Zac Gibson / IAM Change Proof Gate
When AI proposes an access change, every allow or deny is hashed against live Okta/SailPoint state — cite-or-abstain, same-run proof, nothing becomes standing entitlement without a receipt.
We never assumed the AI was right. Visibility ≠ enforcement. Provenance before rubber-stamping: what was proposed, under whose authority, with what audit trail — not agent-identity cosplay against Okta.
- Cite or abstain Answers against a bounded corpus / IdP-adjacent state; unsupported claims abstain instead of inventing policy.
-
Hashed allow/deny + deny receipts
Every check writes a receipt with reason codes like
sod_conflict_denied. -
Same-run proof
learnrefuses empty or failed proof — exceptions do not silently become standing entitlement.
● What it is
A SLUICE wedge beside your IdP/IGA: proof-gated receipts when AI influences access decisions.
The local package keeps its legacy command: python -m brainos.cli iam demo.
Demo narrative: Northbridge as sandbox only.
● What it is not
- Not a replacement for Okta or SailPoint
- Not IdP enforcement — callable ≠ enforced
- Not agent-identity SKUs or measured model-lift claims
30-day pilot — $2,000–$5,000
Wire proof receipts to your access-change path and Okta/SailPoint-adjacent state. Prefer a fit check first? Book a 30-minute discovery call.