Non-human identity
Scoped tools and department tenancy — not shared API keys — so agents can act without becoming unaccountable.
Build · Steer · Compound
AI agents as mission-critical systems: scoped tools, department tenancy, policy gates, and continuous evidence — not blanket certifications or shared API keys.
We maintain institutional context within firm boundaries while giving agents the governed access they need to be useful. SOC 2 and HIPAA are readiness programs here — not blanket certifications until your agreement says so.
Substrate:· Methodology: Build · Steer · Compound
This page is the living controls brief — export or screenshot the checklist and compliance path for security questionnaires.
We maintain institutional context within firm boundaries while giving agents the governed access they need to be useful. Enterprises treat AI agents as mission-critical, yet most identity stacks still assume human-only principals. OWASP’s LLM and Agentic Top 10 put prompt injection, memory poisoning, excessive agency, and tool misuse at the top of the risk list — I/O Mesh answers with a governed operational context plane, not another chat sandbox.
Scoped tools and department tenancy — not shared API keys — so agents can act without becoming unaccountable.
Optional long-term recall stays department-bound — never a cross-firm vector dump.
SOC 2 / HIPAA readiness mappings and continuous gates — attestation only when your agreement says so.
Agent context that compounds across real-time pulses, short-term stream history, and longer analytical or institutional patterns only works when tenancy, policy-gated MCP, and audit lineage sit on the same fabric. I/O Mesh is the governed operational context plane behind the homepage full organizational heartbeat—security is how multi-horizon BI stays usable without claiming blanket certifications.
Full organizational heartbeat: live operations, knowledge memory, and analytics patterns — department-scoped, policy-gated. Security and trust mean department-scoped products agents can use under policy across those horizons, not a checkbox pack that pretends SOC 2 or HIPAA are already signed unless your agreement says so.
The full organizational heartbeat—live ops pulses, knowledge memory of past heartbeats, and analytics patterns—feeds a shared context plane. Agents then work across real-time rates, short-term stream history, and longer analytical or institutional patterns.
Live pulse rates and ordered stream state from operational heartbeats agents subscribe to under MCP policy. Incidents, tickets, deploys, pipeline stages, scoped by tenant and department.
Hours to days of stream history and rolling operational context. Lineage agents can cite. Do not invent 1h/24h/7d product windows.
Analytical history and institutional patterns under tenancy and audit controls.
One fabric, three signals: live operations, knowledge, and analytics — department-scoped, policy-gated.
Tickets, incidents, deploys, and customer updates, organized by team. The primary heartbeat a reviewer can see after a source, a stream, and a signed event.
Docs, runbooks, and memory of past heartbeats. What previous activity meant. Reviewers can open this layer in the product; do not chip it as a readiness label.
Patterns and trends across heartbeats so agents see beyond the moment. Same rule: describe the layer, do not chip a status.
No SOC 2 Type II claim on this page. HIPAA is a readiness mapping, not a certification. A BAA is required before PHI.
Secure payment · Immediate full access · 15% off annual
Product surfaces platform teams can staff and measure — mapped to Build · Steer · Compound Build (tools + gates), Steer (portal context + memory), and Compound (usage proof + private evals).
Prevent context bleed while enabling multi-dept agents — org → workspace → tenant with dept.* namespaces, not a shared agent memory bucket.
Treat human and non-human principals differently — sessions, SSO/SCIM, and audited privilege elevation so support is powerful without being unaccountable.
Stop free-form agent tools from becoming production risk — policy-gated, rate-limited, department-scoped MCP with preflight and audit.
Protect operational facts as token capital — in transit, at rest, and under customer-controlled key policy when required (enterprise BYOK path).
Give evaluators request-level truth — who published, who invoked, what enriched, and what support did — so GRC reviews are evidence-backed.
Inherit continuous gates instead of a one-time PDF — SAST, dependency, container SBOM, and optional DAST on the release path.
How common 2026 agentic risk classes land on I/O Mesh controls — for security questionnaires, not as a certification claim.
| Risk class | I/O Mesh control | Surface |
|---|---|---|
| Prompt injection / tool hijack | Policy-gated MCP invoke + subject ACLs at ingress | MCP tools · mesh policy preview |
| Memory poisoning / context bleed | Department-scoped memory chambers; no cross-tenant indexes | Department-scoped memory chambers. No cross-tenant indexes. |
| Excessive agency | Plan entitlements, rate limits, dry-run validation on automation paths | Entitlements · automation studio |
| Shadow tools / sprawl | Cataloged dept.* products + governed connectors with OAuth/HMAC | Integrations · data products |
| Privileged support abuse | Role-gated impersonation with paired audit events | Admin console audit |
| Vulnerable components | govulncheck, Trivy, SBOM/Grype, pnpm audit in release gates | CI security-scan |
Readiness mappings and commercial packs for regulated evaluators. We do not claim SOC 2 Type II or a signed BAA on this page.
Mapped to AICPA Trust Services Criteria with readiness artifacts (access, tenancy, monitoring, change gates). Control mapping is a readiness artifact — not an auditor report until Type II is issued under your commercial path.
Administrative and technical safeguards mapped for care-adjacent B2B workloads. BAA required for PHI handling — marketing packs do not replace a signed BAA.
SSO/SCIM automation, IdP scope sync, dedicated compliance reviewer path, and evidence-pack packaging for enterprise evaluators.
Visual Rego editor, field-level ABAC, traffic analytics, and federation audit exports for regulated mesh operators.
Continuous gates (SAST, dependency scans, container SBOM/Grype, optional OWASP ZAP DAST) and chaos isolation tests so you inherit production-grade controls — not a one-time PDF.
A dedicated public status page is the next polish for platform teams who want subscribe-to-incident feeds without a sales ticket. Production edge and self-serve Base plan are live today — start in the console, or email hello@iome.sh for availability questions.
We solve the agent security problem the same way platform teams solved service security: clear boundaries, policy enforcement, and evidence over promises.
Tenancy, identity, encryption, audit, and compliance readiness are built into the fabric — so your AI agents can be powerful without becoming a liability.
Controls are built into the product fabric — giving you audit-friendly evidence paths from day one without waiting on a separate security product.
Get started in the console, or review Governance and Compliance packs on Pricing. Use the buyer checklist as the questionnaire map.
Policy gates · audit trails · continuous security-scan gates