# IdentiQube > IdentiQube puts identity administration, access governance and privileged > access on one graph, so every access decision carries the evidence of why it > was made. Early access is open. ## What it is Identity administration (IAM), access governance (IGA) and privileged access (PAM) grew up as three product categories with three data models and three audit trails. IdentiQube treats them as one problem over one typed graph, evaluated by one decision runtime. The question it exists to answer: **why does anyone have the access they do?** Today that is an investigation across several systems. Here it is a lookup. ## What is different - **Credentials are not authority.** Proof of who you are never becomes permission to act. Capabilities declare what a principal may do, separately. - **Evidence at decision time.** The reason for a decision (which rule, whose approval, which facts and how fresh they were) is recorded as the decision is made, not reconstructed later from logs. - **Drift is an alarm.** The gap between what the governance model believes and what downstream systems enforce is surfaced when it appears, not at quarter end. - **AI can propose, never grant.** AI actors are modelled as principals with declared bounds. They may read, summarise and suggest; there is no path through the system by which one can originate authority. - **Roles are computed, not stored.** Role membership is a query over the graph, so there is no role explosion to prune. - **Observe before enforce.** Adoption starts read-only: the runtime computes decisions against existing state and records them without changing anything. Enforcement is enabled per scope, on the customer's schedule. ## What it will not do - Be an identity provider. No SSO, no MFA, no passwords. It governs what authenticated principals may do, and integrates with the customer's IdP. - Fail open. Without a basis for a decision, the answer is no. - Gate correctness behind a tier. Security, audit and export are identical across tiers; tiers differ in capacity. - Hold data hostage. Tenants can export canonical state as a signed bundle, verifiable offline, including after they stop being a customer. ## Also from IdentiQube - [Provenant](https://provenant.identiqube.com): a control plane and tamper-evident audit ledger for AI agents. Checks every agent action against mandate, budget and policy before it runs. Commercially available today. A narrower problem than IdentiQube, built on the same principles. ## Pages - [Home](https://www.identiqube.com/): the product argument and early access. - [Impressum / Legal Notice](https://www.identiqube.com/legal): operator and EU representative. - [Privacy Notice](https://www.identiqube.com/privacy): what the early-access form collects and how to have it deleted. ## Contact Early access and general enquiries: iq@identiqube.com