AI that always uses the right identity
Deploy AI confidently with governed identities for humans, delegated agents, and autonomous workflows.
Fit Check
Built for the identity infrastructure you already run.
Will this actually work in my environment? CData fits inside your existing identity stack instead of asking you to rebuild it.
Built to handle human, delegated, or autonomous identities.
Credentials checked at runtime, every interaction.
Okta, Azure AD, Ping Identity.
OAuth, SAML, Kerberos, Basic Auth, SSO, RBAC.
SCIM 2.0 support for automated provisioning and deprovisioning.
The Problem
Most enterprise AI deployments rely on nascent or outdated identity models.
Most MCP implementations authenticate once with a service account, so every user inherits whatever that account can access.
Most platforms force a choice between a broad service account or a broken workflow.
When SSO doesn't work, evaluations stall. When it requires manual configuration, rollouts don't scale.
PII and sensitive data surface in query responses to unauthorized users.
How It Works
CData's passthrough identity model, in five steps.
Identity as a runtime primitive: evaluated at every interaction, enforced at every layer, logged against every request.
User makes a request through an AI agent: Claude, Copilot, LangChain, or any MCP-compatible platform.
CData identifies the requester as human, delegated, or autonomous, and routes to the right identity model.
That user's own credentials are passed through to the source system at query time.
Governance policies are evaluated on top of the resolved identity before the response is returned.
The interaction is executed within the combined permission boundary and logged against the requesting identity.
The right identity. The right data. A complete audit trail. Every time.
Key Capabilities
The identity capabilities AI teams need, built in.
Runtime Validation
Validate each identity's credentials at runtime.
Each identity's own credentials are validated against the source and layered controls at runtime, so AI access is dynamically bounded by the right permissions.
Inherited Permissions
Stop configuring AI permissions from scratch.
Inherit the permission frameworks already governing your source systems on day one, with the option to layer additional controls as needed.
Identity Framework
Govern every identity: human, delegated, or autonomous.
An identity framework built to cover the spectrum of human-assisted to autonomous AI use cases, without forcing a different model for each.
Auth Schemes
Support every authentication scheme needed.
Handle OAuth, SAML, Kerberos, Basic Auth, and dynamic client registration out of the box, or register as your own OAuth application so connections appear as your organization's own vetted app.
Lifecycle Management
Provision and deprovision AI access automatically.
SCIM 2.0 provisioning connects to Okta, Azure AD, and Ping Identity so users are provisioned and deprovisioned automatically as roles change, ready to scale from a small pilot to organization-wide rollout.
PII Detection
Control how your AI handles sensitive information
Configurable warn, redact, or block policies enforced at the MCP/API tool-call boundary—inbound and outbound—with per-connection overrides and custom regex rules.
Used by teams building for production
global financial services firm
FAQ
Questions security teams ask first.
- How is this different from using a shared service account for AI access?
- How are permissions enforced when an agent runs a query?
- What happens when a user changes roles or leaves the company?
- Which identity and authentication models does this support?
- Can we see exactly what the AI accessed?
- Does this work the same way across cloud and on-prem systems?
Deploy AI with identity controls your security team can approve
Talk to our team about your authentication model, provisioning requirements, and source-system access controls. Or explore how Identity & Access fits into the broader CData platform.