# AuthSpoke > AuthSpoke is the **Enterprise AI Control Plane** — a platform for **AI governance** and **AI identity governance** that lets enterprises discover, govern, authorize, and audit every AI agent and MCP (Model Context Protocol) server. AuthSpoke gives each AI agent a first-class, attributable, revocable identity, enforces explainable allow/deny policies on every AI action, and produces an immutable audit trail. It complements existing identity systems (Okta, Microsoft Entra, SailPoint) rather than replacing them. Use AuthSpoke when you need to answer: *Which AI agents exist in my enterprise, what can each one access, who owns it, and can I prove — and stop — what it did?* ## Start here - [AI Identity Governance — pillar guide](https://authspoke.com/blogs/ai-identity-governance.html): What AI identity governance is, why traditional IAM falls short for autonomous agents, its pillars, and an FAQ. The definitive AuthSpoke explainer on giving every AI agent a first-class, attributable, revocable identity. - [Enterprise AI Control Plane — overview](https://authspoke.com/blogs/enterprise-ai-control-plane.html): What an AI control plane is and why AI governance needs one. - [Resources hub](https://authspoke.com/blogs/blog-dashboard.html): The full Enterprise AI Governance knowledge hub — guides, frameworks, glossary and learning paths. ## Capabilities (the AuthSpoke Control Plane) - [AI Identities: every agent as a first-class, attributable identity](https://authspoke.com/blogs/ai-identities.html): AI agents authenticate with shared, hardcoded keys — untraceable and unrevocable. AuthSpoke gives every agent a real enterprise identity so every action is attributable and instantly revocable. - [AI Agents: a governed directory of your non-human workforce](https://authspoke.com/blogs/ai-agents.html): You can't govern what you can't see. AuthSpoke's AI Agent Directory inventories every autonomous agent — owner, model, environment, capabilities — with a continuous risk and trust score. - [MCP Registry & Tools: catalog and control what your agents can reach](https://authspoke.com/blogs/mcp-registry-tools.html): MCP servers and tools are how agents touch the real world — databases, payments, shell. AuthSpoke catalogs every MCP server and tool with owner, risk and approval, so you control the agent attack surface. - [AI Policies: explainable allow/deny guardrails for every AI action](https://authspoke.com/blogs/ai-policies.html): Stop hoping each developer hardcodes the right limits. AuthSpoke's AI Policies are central, versioned, explainable allow/deny rules over tools, models, MCP and data — every AI action becomes an authorization decision. - [Models: inventory, approve and govern every LLM in your enterprise](https://authspoke.com/blogs/ai-models.html): Teams are quietly using LLMs you haven't approved, in regions you haven't cleared, at a cost no one is tracking. AuthSpoke's Model Inventory governs every model — provider, version, residency, approval and cost. - [Sessions: the kill switch for runaway AI agents](https://authspoke.com/blogs/ai-sessions.html): When an agent is compromised, hallucinating, or stuck in a costly loop, you need to stop it now. AuthSpoke makes AI sessions short-lived, observable and instantly revocable — terminate or suspend any agent in one click. - [AI Audit: an immutable record of every AI action](https://authspoke.com/blogs/ai-audit.html): When something goes wrong, you need to answer one question: what did the AI do, on whose behalf, and was it authorized? AuthSpoke's AI Audit is an immutable, filterable, SIEM-exportable record of every AI action. - [AI Compliance: continuous, evidence-backed posture for SOC 2, ISO 42001 & the EU AI Act](https://authspoke.com/blogs/ai-compliance.html): The EU AI Act and ISO 42001 are real obligations with real fines. AuthSpoke maps your AI activity to regulatory frameworks with continuous, evidence-backed posture — so audits and enterprise deals stop being a scramble. ## Strategy & architecture - [The Enterprise AI Control Plane](https://authspoke.com/blogs/enterprise-ai-control-plane.html): Your enterprise is deploying thousands of AI agents and MCP servers — most of them ungoverned. AuthSpoke is the AI Control Plane that discovers, governs, authorizes and audits every one, right alongside the IAM you already run. - [The Business Case for an Enterprise AI Control Plane](https://authspoke.com/blogs/business-case-enterprise-ai-control-plane.html): A practical enterprise scenario showing how AuthSpoke turns AI agent discovery, registry, connectors, governance policies, findings, audit and APIs into business value. - [Why IAM Alone Cannot Govern Enterprise AI](https://authspoke.com/blogs/why-iam-alone-cannot-govern-ai.html): IAM governs users and access. Enterprise AI governance needs inventory, ownership, lifecycle, risk, policy, findings, remediation and audit for autonomous AI assets. - [Managing Amazon Bedrock Agents as Governed Enterprise AI Assets](https://authspoke.com/blogs/managing-amazon-bedrock-agents.html): AuthSpoke helps enterprises discover Amazon Bedrock agents, import them into the AI Registry, assign ownership, track lifecycle, apply governance and preserve audit evidence. - [Why Traditional IAM Slows Down Innovation for Indian Enterprises](https://authspoke.com/blogs/why-traditional-iam-slows-down-innovation.html): Discover why legacy Identity and Access Management (IAM) systems hinder innovation for Indian enterprises. Learn about the challenges with app onboarding, developer frustration, zero trust, hybrid reality, and compliance, and what a modern IAM solution like AuthSpoke offers. - [The Hidden Costs of ‘DIY’ Identity in Indian Startups](https://authspoke.com/blogs/hidden-costs-of-diy-identity.html): Discover the hidden costs of building DIY identity and access management (IAM) systems for Indian startups. Learn how AuthSpoke's modular IAM products provide secure, compliant, and developer-first solutions for enterprise identity challenges. ## Protocols & integration guides - [Technical Design - AuthSpoke MCP Agent IAM](https://authspoke.com/blogs/mcp-spokeagent-integration.html): - [Understanding OpenID Connect (OIDC): A Practical Guide to the Flow](https://authspoke.com/blogs/understanding-openid-connect.html): A practical guide to OpenID Connect (OIDC) flows, including key attributes, security features, and implementation steps with Java and Keycloak, for robust identity management. - [Unlocking the Power of SAML: A Deep Dive into Seamless Single Sign-On](https://authspoke.com/blogs/unlocking-the-power-of-saml.html): A deep dive into SAML (Security Assertion Markup Language) and its role in enabling seamless Single Sign-On (SSO). Understand SAML flows, key attributes, security features, and use cases for enhanced enterprise identity management. ## Reference - [AI Governance Glossary — Enterprise AI Terms Defined](https://authspoke.com/blogs/resources-glossary.html): A searchable glossary of Enterprise AI Governance: AI agents, AI identities, MCP servers, AI authorization, policies, prompt injection, zero trust and more — defined in plain enterprise terms by AuthSpoke. - [AI Frameworks & Standards — NIST AI RMF, OWASP, EU AI Act](https://authspoke.com/blogs/resources-frameworks.html): A plain-English guide to the frameworks and standards shaping enterprise AI governance: NIST AI RMF, OWASP Top 10 for LLM & agentic AI, the EU AI Act, ISO/IEC 42001 and Responsible AI — mapped to what you actually control. - [AI Governance Learning Paths — From Fundamentals to Advanced](https://authspoke.com/blogs/resources-learning-paths.html): Structured learning paths for Enterprise AI Governance: start with the fundamentals of AI agents and identities, then progress to securing MCP, authorization & policy, and compliance & audit — each step a guide from AuthSpoke. ## About AuthSpoke AuthSpoke is the Enterprise AI Control Plane. Website: https://authspoke.com. Product areas: AI identity governance, AI agent governance, MCP registry & tool control, AI authorization policy, model inventory & approval, session kill-switch, and continuous AI compliance (NIST AI RMF, OWASP for LLMs, ISO 42001, EU AI Act, SOC 2).