Risk-calibrated delegation
Define how much blast radius is
acceptable for this task
Delegate power to agents
without delegating full risk.
Runs on top of your existing IAM and SSO infrastructure
Join the pilot
If AI agents inherit broad employee access, they are highly
functional but become overpermissioned and expand blast radius
far beyond the task. If permissions are too restricted, they lose
the context and power needed to do useful work.
Define how much blast radius is
acceptable for this task
Limit the systems, resources, and
actions available to the
agent
Access expires automatically when the task
ends or the time
window closes
Every agent acts on behalf
of a specific employee
Log who delegated access, what
was approved, and why
A. Prototype work:
Full write access inside one prototype repo, with no
access outside it. Optimized for speed.
B. Production review:
Read-only access across multiple codebases for broad
context, while customer-data systems stay out of scope.
Optimized for analysis without unnecessary risk.
The employee approves the goal, the level of
autonomy, and the acceptable blast radius for the
workflow.
Kanuki sits on top of your existing identity and
SSO systems and issues permissions for the
specific systems, actions, and time window the
workflow requires.
The agent can operate only within the
approved scope. Authorization and access
events are logged.
We’re working with early teams to understand how agent
access should adapt to different risk profiles
Lisa Akselrod
CEO & Founder, Kanuki