Secure AI Agent · Identity and Access

AI applied to controlling who accesses what

A specialist configured to prepare access reviews, track joiners and leavers, and gather the evidence auditors ask for, within your company's rules.

Companies that trust UPX

  • Bradesco
  • Nubank
  • BTG Pactual
  • Totvs
  • Ascenty
  • Live!
  • G4 Educação
  • EVEO

Capabilities

What the Identity and Access Agent can do

Main areas of work for the Identity and Access AI Agent in your operation.

Access reviews

Organizes who has access to what and prepares the periodic review campaign.

Joiners and leavers

Tracks the onboarding and offboarding cycle and flags provisioning gaps.

Orphaned accounts

Flags accounts without an owner or without recent use for the team to assess.

Excessive privilege

Compares granted access with the recorded role and flags divergences.

MFA coverage

Identifies accounts and systems without a second factor under the current policy.

Audit evidence

Gathers review and approval records in the format auditors request.

Skills

Capabilities that compose the specialist

Skills add specific capabilities to the Secure AI Agent according to the processes it needs to execute.

Access review campaign
Builds the review list by manager, system, and privilege level.
Identity reconciliation
Cross-references the people directory with active accounts in the systems.
Compliance evidence
Organizes approval and review records for auditing.
How it works

From the access inventory to the evidence, with review at every step

Connect your identity provider, define what the agent can do, and let review and documentation happen within your company's limits.

01

Connect identity and the people directory
The agent works where access is already managed.Connect the identity provider, the HR system, and the ticket tracker so the Secure AI Agent has access only to what it needs to prepare each review.

02

Ask for the work
Talk to the agent in natural language.Request the review campaign, the status of an offboarding, or the audit evidence through the available channels. The agent understands the context, applies the configured skills, and follows your company's policy.

03

The agent prepares. The manager decides.
From review to evidence, with control.The agent compares, flags divergences, and organizes the evidence within the defined permissions. Granting, changing, and revoking access stay with the system owner.

Integrations

Connected to the systems where access is granted

The Identity and Access AI Agent can query your identity provider and run tasks in the systems your team already uses.

  • Okta
  • Microsoft Entra ID
  • Microsoft Intune
  • BambooHR
  • Jira

Flow

What goes in, what the agent does, and what comes out

From the raw inventory to the review campaign, following your company's rules and permissions.

Inputs

  • Active accountsCSV
  • People directoryList
  • Access policyDOC

Processing

Secure AI Agent

Processing the task

  • Read
  • Reconcile
  • Comparerunning
  • Prepare
Skill appliedPolicy verified

Output

Completed

Review prepared

  • Divergences flagged
  • Orphaned accounts listed
  • Evidence ready for auditing

Control

You define how far the Agent can act

Different actions can operate with different autonomy levels, always within your company's rules.

  1. 1

    Query

    Reads accounts and directories and answers with the reference.

  2. 2

    Prepare

    Builds the review campaign and flags divergences.

  3. 3

    Request review

    Waits for validation from the responsible manager.

  4. 4

    Execute

    Performs the action within the defined limits.

Levels are configured per type of action, according to each company's policy. Granting, changing, and revoking access always stay under human approval.

Get started

Put a Secure AI Agent to work.

Start on the platform or choose the plan that fits the pace of your operation.

Security and compliance

Security that can be verified.

Certifications and attestations

  • SOC 2 Type II
  • ISO 27001

UPX maintains SOC 2 Type II and ISO 27001, with independent audit over its information security controls.

Privacy and regulation

LGPD
Operations follow Brazil's Law 13.709/2018. In AI Agent contracts, UPX acts as data processor; the legal basis remains with your company.
Zero Data Retention
A product policy, not a certification: with compatible providers and configurations, processed content is not retained after execution.
Retention and deletion
The retention policy is defined by contract. Once the contract ends, data is deleted within the agreed period.

Frequently asked questions

Common questions about the Identity and Access Agent

What teams usually ask before putting an agent to support access management.

  • Does the agent grant or revoke access on its own?

    Not by default. Granting, changing, or revoking access are high-impact actions and stay under human approval. The agent prepares the review and flags what needs to change; execution depends on the system owner.
  • Does it store passwords or credentials?

    No. The agent operates with the permissions granted during setup and queries systems through integrations. Secrets stay in the vaults and identity providers where they already live, without being copied into the agent's context.
  • Does it disable access for people who left?

    The agent identifies gaps in the offboarding cycle and flags accounts that are still active. The revocation itself follows the approval flow your company defines.
  • Is the evidence usable for auditing?

    Yes. The agent organizes review, approval, and exception records in the requested format. Formal validation and the conversation with the auditor stay with the responsible team.
  • Is identity data used to train models?

    No. Content processed by Secure AI Agents is not used to train UPX models or third-party models.
  • Can we audit what the agent did?

    Yes. Every action is logged: what was queried, what was proposed, when, in which system, and under which permission. The history stays available for review and auditing.
  • How long does it take to go live?

    It depends on the systems involved and your company's access policy. The starting point is connecting the identity provider and the people directory, then expanding the scope as results come in.

Secure AI Agent

Bring a Secure AI Agent to your access management

Talk to our specialists and see how to adapt this AI Agent to your processes, systems, and needs.