Early accessMesh is in development. You can request early access and help shape it — the capabilities below describe what it is being built to do.
Niello/Products/Mesh
Mesh · enterprise control plane

You approved four agents.

You're running three hundred.

Mesh inventories every agent and non-human identity in your estate, maps what each one could reach, and holds the control line before reach turns into an incident.

0
Agents & identities discovered
0
Shadow-AI findings
0
Blast-radius criticals

From "we think it's fine" to evidence

Five surfaces that take an estate nobody has mapped and turn it into something you can answer for.

DiscoverInventoryBlast radiusPolicyEvidence
01 / DISCOVER

Find what nobody registered

Connect your SaaS, cloud and endpoints and Mesh sweeps for agents, service accounts, API keys and AI tools — including every one that never went through a review.

Connectors — estate scanScanning
Okta — identity312 found
AWS — roles & keys148 found
Google Workspace61 found
Endpoints — 1,240 devicesin progress
◆ 27 unsanctioned AI tools◆ 4 orphaned credentials
02 / INVENTORY

One register for every non-human identity

Agents, service accounts, bots and integrations in a single list — with an owner, a purpose and a last-seen date against each one.

Inventory
svc-ingest-07
No owner · 14mo old
Critical
agent-triage-prod
Platform team
Review
notion-ai-connector
Unsanctioned
Shadow AI
ci-deploy-bot
Engineering
Healthy
03 / BLAST RADIUS

See how far one identity could actually reach

The graph walks every permission, trust and token relationship — so you can see that a forgotten ingest account is three hops from a regulated store.

svc-ingest-07
3 hops → regulated store
svc-ingest-07WarehouseCRMAgent · triageStorageRegulated storeAnalytics
04 / POLICY

The rule runs before the request does

Policy as code, evaluated at the boundary. Not a review queue somebody gets to on Thursday — a gate that already ran, on every call.

Policies
# evaluated on every request
policy contract_data_stays_local {
  when classification contains "supplier_terms"
  allow models where residency == "on_device"
  deny egress; log evidence
}
Evaluated today48,201
Denied312
05 / EVIDENCE

Evidence your auditor can read

Every decision the boundary made, mapped to the frameworks you already report against — generated from what actually happened, not from a questionnaire.

Evidence
EU AI Act — Art. 12 record-keepingEvidence mapped
ISO 42001 — 8.3 AI system operationEvidence mapped
SOC 2 — CC6.1 logical accessEvidence mapped
NIST AI RMF — MAP 3.4Evidence mapped
◆ Export as an auditor-ready pack
Every capability, in full

Open anything up

Each surface breaks apart into what it actually does. Click to dive in.

Mesh reads from the systems you already run. No sidecar on every host, no change to how teams ship.

  • Identity providersOkta, Entra and Google Workspace — service accounts and OAuth grants included.
  • Cloud & SaaSAWS, Azure and GCP roles, keys and workload identities, plus the SaaS estate.
  • Endpoint signalWhich AI tools are actually installed and talking, per device.
  • Continuous, not annualScans run on a schedule; drift shows up the week it happens.
Connectors
OktaConnected
AWS — 4 accountsConnected
Google WorkspaceConnected
EndpointsScanning

The register most organisations assume exists and don't have. Every agent, bot, service account and integration in one place, each one attributable to a human.

  • Ownership resolutionInfers the owning team from commit, deploy and grant history.
  • Orphan detectionCredentials whose owner left the company months ago.
  • Staleness & over-permissionWhat hasn't been used in ninety days, and what holds far more than it needs.
  • Lifecycle actionsRotate, scope down or revoke straight from the record.
Inventory
svc-ingest-07
Owner left · Mar 2025
Orphan
legacy-etl-key
Unused 214 days
Stale
agent-triage-prod
Platform team
Healthy

Permissions rarely stop where the org chart says. The graph follows trust relationships, assumed roles and token exchanges to their real end point.

  • Transitive reachFollows role chaining and token exchange, not just direct grants.
  • Boundary crossingsFlags any path that ends inside regulated or restricted data.
  • What-if simulationModel a revocation before you make it and see what breaks.
  • Shortest-path fixThe single grant to remove that cuts the most reach.
svc-ingest-07WarehouseCRMAgentStorageRegulated store

People adopt AI tools faster than any review process moves. Mesh finds them, works out what data they see, and gives you something better than a blanket ban.

  • Tool discoveryBrowser extensions, desktop apps and OAuth grants nobody approved.
  • Data-class exposureWhat each tool can actually see — not just that it exists.
  • Evidence attachedThe grant, the scope and the timestamp, ready for the conversation.
  • Sanction or replaceApprove it under policy, or route those users to Lumen instead.
Findings — shadow AI
notion-ai-connector
41 users · reads customer records
High
meeting-notes-ext
12 users · records calls
High
grammar-assist
88 users · drafts only
Medium

Controls live in your repo, get reviewed like any other change, and run at the boundary on every request rather than sitting in a policy document.

  • In version controlReviewed, diffed and rolled back like the rest of your infrastructure.
  • Dry-run firstSee exactly what a new rule would have blocked last month before enforcing it.
  • Inline enforcementEvaluated before the model call, not reconciled afterwards.
  • Reaches LumenThe same rules decide which models Lumen even offers on the device.
Policy — dry run
policy no_regulated_to_hosted {
  when data.class in ["pii", "phi"]
  deny model.residency != "on_device"
}
Would have blocked (30d)1,847
Would have broken0 workflows

The part that usually costs a quarter of someone's year. Mesh keeps the record continuously and maps it to the frameworks you report against.

  • Continuous recordEvery decision the boundary made, immutable and timestamped.
  • Framework mappingEU AI Act, ISO 42001, SOC 2 and NIST AI RMF out of the box.
  • Gap viewWhat isn't covered yet, stated plainly rather than glossed.
  • Export packsHand the auditor a pack instead of a fortnight of screenshots.
Evidence
EU AI Act — Art. 12Evidence mapped
ISO 42001 — 8.3Evidence mapped
SOC 2 — CC6.1Evidence mapped
ISO 42001 — 9.2 internal auditPartial

Find out what you're actually running.

Most estates surface three hundred identities in the first scan. We'll show you yours.