Dispatches
Solutions · IT, Security & Identity

Govern every AI tool from one platform in your tenant

Deploy Athena where policy requires, inherit live permissions from source systems, and consolidate AI sprawl under SSO and attribution you already own.

A Fortune 50 retailer collapsed six AI systems onto the platform

Model providersVendor supportYOUR AZURE TENANT · VPC · ON-PREM · AIR-GAPPEDRuntime · Studios· LakehouseComputers · modelgatewayPermission check ·fail-closedUser and agentidentitiesathena-finance-ag…· role: reader ·last active 09:12JIT access gate ·time-bounded ·double-loggedZDR optional to model providers; SSO and SCIM from your IdP
Fig. 01Platform deployed inside your tenant; agents appear in your directory with their own identity
  • SOC 2 Type II
  • HIPAA
  • Zero data retention with every model provider
  • Dozen-plus enterprise security reviews
  • VPC
  • on-prem
  • air-gapped
  • GovCloud
  • Fail-closed permissions
The challenge

Sprawl is the problem. One platform is the answer.

Each with a service account. Each with a copy of your documents somewhere. Each with its own permission model to maintain and its own security review to run. The one that passed review is often the narrowest, so the business keeps buying more.

Sprawl is the problem. One governed platform is the answer.

Vendor sprawlOne platform45 AI toolsMixed approval statusEach: service accountData location45 security reviewsYou are accountable for all of themAthenaDeployed in our tenantApproved · agentsOne governed platform, one permission model
Fig. 02From dozens of vendor-hosted AI tools to one platform deployed in your tenant
How it works

Deploy. Inherit. Enforce. Observe.

  1. Deploy where policy says. Managed cloud, your VPC on GCP, Azure, or AWS, on-prem, air-gapped, GovCloud. Same product in each. Data residency per workspace.

  2. Inherit identity and permissions. SSO through your IdP; SCIM provisioning; tenant-wide consent once. Source-system permissions read per user, live. Files stay where they live; TTL-only cache.

  3. Enforce. Fine-grained authorization per asset. Agents are actors in your directory with their own identity. Fail-closed when the permission service is unreachable. Owner-only computer mode for restricted workspaces.

  4. Observe. Every action attributed and reversible. Cost per user, agent, and project. Hard budgets per run. Every middleware emits a production signal; the build fails if one goes silent.

01Your tenantdeploymentManaged cloud,VPC, on-prem02IdentityinheritedSSO, SCIMprovisioning03Permissioncheck per …Source-systempermissions …04RuntimeexecutesStudios ·Lakehouse05Attributionand budgetsEvery actionloggedEvery action attributed and reversible; hard budgets per run enforced
Fig. 03Deploy in your environment, inherit identity, enforce fail-closed permissions, observe every action
Example workflow

Example workflow: Audit agent permissions and restrict access

SURFACES INWHAT COMES INTHE PLATFORMWHAT GOES OUTDELIVERED BACKMobile · voiceText (SMS)EmailSlack · TeamsChromeOffice add-inMeeting botMeetingsWordPowerPointSheetsFiles · PDFsDataWorkflows (AOPs)AppsLibrarySessionsSpacesStudiosMeetingsSemantic modelsDatabaseDashboardsWordPowerPointSheetsData · APIsApps · portalsWebMobile · voiceText (SMS)EmailSlack · TeamsChromeOffice add-inMeeting botWeb1Lakehouse2Agents3Dashboards41 INIdentity admin opens Entrauser list and seesathena-finance-agent withreader role active at 09:122 CHECKAdmin reviews what the agentaccessed: quarterly financialfolder in SharePoint, threeExcel files3 RUNAdmin restricts agent rolefrom reader to custom roleexcluding the sensitiveexecutive-only folder4 ANSWERPermission check now deniesagent access to restrictedfolder; fail-closed whenservice unreachable; allactions attributed and logged
Fig. 04The route on the system map: Web → Lakehouse → Agents → Dashboards. Connectors: Identity admin → Entra directory → permission check → agent restricted
Use cases

Identity, agents, consolidation, and control

Identity, done once.

SAML/OIDC, Okta, Entra, SCIM. Touchless tenant-wide consent for the productivity suite instead of a click per user. Users outside the platform receive agent outputs by email or portal. Touchless consent was built for a Fortune 500 retailer's identity team.

Athena wants toGrant tenant-wide O365 consent fororganizationSAML/OIDC via EntraSCIM provisioning from OktaTouchless consent replaces per-user clicksWAITING FOR A PERSONNon-licensed users receive outputs by emailBuilt for Fortune 500 retailer identity team
Fig. 05One admin consent replaces per-user clicks; non-licensed users receive agent outputs

Agents as first-class actors.

Each agent has an identity in your directory. See what it did, restrict what it can touch, revoke it like any employee.

Microsoft Entra ID · User and agent identitiesDisplay nameTypeRoleLast activeStatusFinance AnalystUsercontributor14:03activeathena-finance…Servicereader09:12activeOperations LeadUserowneryesterdayactiveathena-triage-a…Servicecontributor11:47activeWHO CHANGED WHATIdentity adminSee what each agent didIdentity adminRestrict what it can touchIdentity adminRevoke it like anyemployee
Fig. 06Each agent has an identity in your directory with role, activity log, and revocation rights

Consolidation without losing the tools people love.

Apps distributed to thousands of employees, included in Athena services. A Fortune 50 retailer collapsed six AI systems onto the platform.

AthenaVendor AVendor BVendor CVendor DVendor EVendor FA Fortune 50 retailer collapsed six AI systems onto the platform
Fig. 07Six separate AI vendor tools consolidated into one governed platform with multiple applications

Just-in-time, audited vendor access.

No standing credentials. Access per incident, approved by you, time-bounded, logged by the platform and by your cluster.

Athena wants toVendor support requests JIT access toruntime for incidentIncident: Production workflow timeoutRequested by: Support Engineer roleDuration: time-boundedWAITING FOR A PERSONApproved · access grantedNo standing credentials · time-bounded · double-logged
Fig. 08Just-in-time vendor access per incident, approved by you, time-bounded, logged twice

Ticket triage that unblocks users first.

First pass on Jira and ServiceNow queues: classification, a proposed resolution, and a reply to the user before a human opens the ticket.

SESSIONPassword reset request · mailboxaccess issueClassified: access · Proposed: checklicense assignment · Reply drafted touserServiceNow ticketFirst-pass · 2 minBefore a human opens the ticket
Fig. 09Jira and ServiceNow queues get classification, proposed fix, and user reply first

Agent-run permission audits and security scans.

Before anything ships to users, an agent scans the application's access model and reports findings. Analogous-issue hunting across the stack: fix one auth issue, ask the agent to find the same pattern everywhere.

Pre-ship security scanTrigger · Before application ships to usersScan application access modelHunt analogous auth issue across stackReport: 3 findings · 2 fixedOne auth pattern awaiting reviewAgent reports findings;fix one issue, find samepattern everywhereAgent-run
Fig. 10Agent scans access model before ship and hunts analogous auth issues across the stack

Cost governance and model control.

Token cost by user, agent, project. Hard budgets per run. Allow-lists and deny-lists of model providers. Bring your own keys and route existing credits through the platform.

Token cost and model controlBy userBy agentBy projectHard budget per runenforcedUserAgentProjRunAllow-list · deny-list · BYOK
Fig. 11Token cost by user, agent, project; hard budgets per run; provider allow and deny lists

Legacy systems without an API.

Entra admin automation through a governed browser; a legacy system over SFTP. Recorded, attributable, never described as bypassing a control.

01Entra admin taskGoverned browsersession02Recording startsActing as identityadmin role03Legacy systemautomationOver SFTP · governed04AttributionloggedRecorded · neverbypassing controlLegacy systems automated without API; attributable, never described as bypass
Fig. 12Entra admin automation through governed browser; Legacy system over SFTP; recorded and attributable
What customers say
“It's good to understand the capability of the platform. That how far, and how quickly you guys can get these things going [...] that has been impressive overall.”
VP-level AI leader · A Fortune 500 retailer
“The performance, say, the kind of speed and latency on those APIs for creating assets, was better in [our private cloud] than it was in managed cloud.”
Audit lead · A global professional services firm
“So we use the SDK, and we write that in Python, and it calls Athena majority by API. The results appear in the interface itself.”
Legal technology team · A global law firm
“I think a good replacement for the BI. Correct? I don't really need a BI help here. I can develop my own dashboards.”
IT lead · A global manufacturer
“Some of the traceability stuff that you guys have within your tool that doesn't exist anywhere else”
IT team · A global manufacturer
“Obviously, you guys have really good security. We trust you guys with your security of what we do.”
Innovation lead · An AmLaw 100 firm
“So it's a full blown running Linux instance with all the bells and whistles that come with that.”
Technology lead · A global professional services firm
“It's a touchless, you know, seamless. Like, it just gives them whatever they have access to.”
Analytics lead · A Fortune 500 retailer
“I can't believe how far you've come in this short period of time. So it's really impressive.”
Assurance Technology Leader · A global professional services firm
“This is where the puck's going and this is where the moat is for an enterprise.”
AI Council lead · A Fortune 50 retailer

Verbatim from customer calls. Customers anonymized.

Three ways to build

IT, Security & Identity on one platform

Agents for the ad hoc: "who has access to this folder and why." Workflows (Agent Operating Procedures) for the recurring: access reviews, ticket first-pass, nightly scans. Applications for the many: the internal portal the whole company uses under your SSO.

Compliance

SOC 2, HIPAA, zero data retention

SOC 2 Type II. HIPAA. Zero data retention with every model provider; no training on customer data. A dozen-plus enterprise security reviews passed. Architecture and data-flow documentation available.

What to plan for

Inherited permissions are only as clean as the source system's. An over-shared SharePoint folder is visible to the agent exactly as it is to its user. We surface what we find; we do not fix your SharePoint.

FAQ

How do we govern AI agents across the company?

From one place: models, connectors, permissions, budgets, and approvals are managed centrally, and every action is logged.

Do agents get more access than people?

No. Agents act with the permissions of the person or service they run for.

Where can it run?

In our cloud, your cloud, on-premises, or air-gapped.

How do we roll it out?

Through your identity provider and directory groups, with single sign-on.

One platform underneath

AGS · Athena Governance System

Records every change by a person or an agent, rolls back one contributor's edits without losing anyone else's, and keeps the model, instructions, and sources behind each agent action.

Palladium · deployment

How the platform is deployed: Athena's managed cloud, your cloud on AWS, GCP, or Azure, on-prem, air-gapped, or GovCloud. Same platform in every option.

How it fits together

Build, Work, and Data on top; 150+ connectors and every surface in and out; one map of the whole platform.

Related

Related products and stories

Send the security questionnaire.

We have answered it before. Then we will show you the platform running inside a boundary like yours.