Product
Independent authority between AI intent and enterprise execution.
Before an AI agent performs a consequential action, ValarIQ verifies identity, delegated authority, policy, current business evidence and required approval — then allows, conditions, delays, escalates, quarantines or denies execution.
From logs to defensible evidence.
Discover → Promote
See what is acting before you authorise it.
Live HubSpot CRM and Microsoft Graph scanners when credentials are configured, plus a 100-system catalogue of Ready-to-Connect targets. Promote into Agent Identity — discovered is never authorised by default.
- ✓Credentialed HubSpot / M365 discovery (env secret refs)
- ✓SYNTHETIC fixtures for safe rehearsal
- ✓Promote to Agent Identity with explicit human action
- ✓Authority, Policy and Keys only after promote
Agent Identity Registry
Know every non-human actor with financial authority.
Register agents with cryptographic identity, version tracking, and explicit scopes. Every financial action is attributable to a known autonomous actor — not an anonymous API call.
- ✓Cryptographic agent certificates
- ✓Version and scope tracking
- ✓Revocation and kill switch
- ✓Owner accountability mapping
Policy Engine
WHEN conditions THEN ALLOW / DENY / ESCALATE.
Transaction policy evaluates every financial action against your rules. Low-risk actions proceed automatically. Exceptions escalate. Prohibited actions are blocked.
Routine refund — auto-approve
WHEN action = "refund" AND amount <= 100 AND destination IN authority.allowed_destinations AND within_working_hours(agent) THEN ALLOW
High-value refund — escalate
WHEN action = "refund" AND amount > 100 AND amount <= 500 THEN ESCALATE approver = authority.owner
Out-of-policy transfer — deny
WHEN action = "transfer" AND destination NOT IN authority.allowed_destinations THEN DENY reason = "destination_not_permitted"
Decision Engine
Every request evaluated at the execution boundary.
→
Agent request
✓
Identity
✓
Authority
→
Policy
→
Risk
→
ALLOW / ESCALATE / DENY
Identity and authority are verified first. Policy and risk scoring determine the outcome: straight-through execution, human escalation, or denial.
Approval Orchestration
Human-in-the-loop when policy requires it.
Single approval
One named Approver for exceptions above policy threshold. Shipped.
Timeout handling
Pending approvals expire (default 30 minutes) and block execution until resolved or expired.
Dual approval
Two independent Approvers for escalate ≥ £250 (and dual_control action classes). First vote parks; second distinct Approver settles. Self-approval blocked. Expanding with Design Partners.
Risk-based routing
Escalation path by amount band and action type today; richer routing on the roadmap.
Evidence & lifecycle
Defensible proof, then honest currency.
Every control decision produces a signed evidence pack: who acted, under what authority, which rules applied, and what ValarIQ decided. That historical record is not rewritten when the world changes.
Evidence Lifecycle then asks a separate question: for a given claim today, does that evidence still hold, or must the action be re-verified? Authority reductions, policy changes and related shifts surface as re-verification, not silent edits.
What auditors can see
- Who acted: agent identity and owner
- What was requested: action and amount context
- Under what authority: limits and permitted actions
- Which controls applied: policy outcome and risk class
- Decision: allow, escalate, or deny
- Human involvement: approver when escalated
- Integrity: signed proof of the sealed record
- Lifecycle: historical truth vs current applicability
Capability status stays honest on /capabilities. ValarIQ authorises; your stack executes.
From logs to defensible evidence.
Request a sandbox and wire your first refund path.