DISCOVER · REVIEW · REMEDIATE
Agents & non-human identities

Certify the authority, whatever the actor.

Service accounts, workload identities and AI agents outnumber people many times over, and most organisations cannot say who owns them. The market fights over what an agent can access. REVIEWIT answers a different question: who authorised it, did a human decide, and can you prove it afterwards.

Ownership attestationReason to existHuman authoritySealed proof
Four questions

Everyone is on the first. Nobody is on the fourth.

01

1. What can it access?

The permission graph. Crowded, well funded, and not where certification lives.

02

2. Who authorised it?

A named owner, accountable, with a reason for the identity to exist at all.

03

3. Did a human decide?

Not a policy, not an automation. A person, on a date, with a comment.

04

4. Can you prove it?

Six months later, to a regulator. Sealed, chained, exportable. This is REVIEWIT's question.

The regulation already changed the object

The obligation is periodic. The motion is the same.

Human oversight with the capacity to intervene, automatic logs retained, demonstrability on request. The AI Act asks of agents what DORA and NIS2 already ask of people: show, periodically, that a human authority supervises. The certification campaign does not change. Its subject does.

  • The question changes. For a person: should this access continue? For a non-human identity: who owns this, and why does it still exist?
  • The policy exists. Ownership and orphan policies already carry minimum owners, acceptance, designation strategies and deadlines. They apply to a service account as they apply to a site.
  • The proof exists. A named human's decision, signed off, sealed into the audit trail. Whatever the actor being certified.
Campaign Ownership attestation · non-human identities
svc-payroll-exportWorkload identity · last used 3 days ago
Owner: HR systems leadReason: monthly exportAttested
agent-support-triageAI agent · 1 204 actions this month
Owner: none acceptedReason: missingOrphan
ci-deploy-runnerService account · privileged
Owner: platform teamExpires: 31 Dec 2026Review due
Same policy, same sign-off, same seal
Agents, with a precedent

We govern our own agent first.

RITA's ledger records, for every turn, what the assistant actually did and with which tools, under whose session. That is the primitive an agent governance needs: not what it was allowed to do, but what it did, and under whose authority. REVIEWIT applies to its own AI what it will apply to yours.

The guard-rail. This is not a second thesis. REVIEWIT does not do machine identity security, secrets management or permission graphs. It certifies authority and proves it, for a person, a service account or an agent, with the same campaign, the same sign-off and the same seal.

Start with the ownership attestation.

Name an owner, justify the existence, set a deadline. It is the campaign every non-human identity programme starts with, and REVIEWIT runs it today.