AI that always uses the right identity
Deploy AI confidently with governed identities for humans, delegated agents, and autonomous workflows.
Fit Check
Built for the identity infrastructure you already run.
Will this actually work in my environment? CData fits inside your existing identity stack instead of asking you to rebuild it.
Built to handle human, delegated, or autonomous identities.
Credentials checked at runtime, every interaction.
Okta, Azure AD, Ping Identity.
OAuth, SAML, Kerberos, Basic Auth, SSO, RBAC.
SCIM 2.0 support for automated provisioning and deprovisioning.
The Problem
Most enterprise AI deployments rely on nascent or outdated identity models.
Most MCP implementations authenticate once with a service account, so every user inherits whatever that account can access.
Most platforms force a choice between a broad service account or a broken workflow.
When SSO doesn't work, evaluations stall. When it requires manual configuration, rollouts don't scale.
PII and sensitive data surface in query responses to unauthorized users.
How It Works
CData's passthrough identity model, in five steps.
Identity as a runtime primitive: evaluated at every interaction, enforced at every layer, logged against every request.
User makes a request through an AI agent: Claude, Copilot, LangChain, or any MCP-compatible platform.
CData identifies the requester as human, delegated, or autonomous, and routes to the right identity model.
That user's own credentials are passed through to the source system at query time.
Governance policies are evaluated on top of the resolved identity before the response is returned.
The interaction is executed within the combined permission boundary and logged against the requesting identity.
The right identity. The right data. A complete audit trail. Every time.