NDGM/ identity-graph/ live
lat 51.509°Nlon 0.118°W● UK
Closed-loop identity governance
estate 400nhi:human 7:1evidence 100%

Identity governance that fixes what it finds.

NDGM discovers every human, service account and AI agent on your estate — then rotates the credential, vaults the secret, and hands your auditor the evidence. A closed loop, not another report.

Meet Reeve
Customer zero — governs its own 400-identity estateNow recruiting UK design partnersBuilt & hosted in the UK
/ 01The problem
legacy_iga.finds_not_fixes

Legacy IGA finds. It doesn't fix.

Most identity governance ends at a finding: a stale key flagged, a review completed, a PDF filed. The risk itself is still live.

57%
Identities are invisible

Over half of enterprise identities are invisible to the systems meant to govern them. You can't review what you can't see.

45:1
Machines outnumber people

Service accounts, keys and AI agents outnumber humans roughly 45 to one — and legacy IGA was built for the one.

#1
Credentials still win breaches

Stolen credentials remain among the most common ways in. The stale key gets a ticket; the ticket gets a backlog; next year's audit finds the same key.

1. Orchid Security, 2026 Identity Gap report · 2. CyberArk, Identity Security Landscape · 3. Verizon, Data Breach Investigations Report
/ 02The loop
discover → enforce → prove → repeat

Five steps. One closed loop.

Identities change constantly, so governance can't be an annual event. NDGM runs the loop continuously — and step four is the one nobody else has.

step 01
Discover

Connect your estate. Humans, service accounts, keys and agents land in one live identity graph.

step 02
Classify

Every identity typed, owned and risk-scored — graphed against its actual access.

step 03
Govern

Blueprint-driven reviews with AI-recommended decisions. Certifications without spreadsheets.

the difference
step 04
Enforce

Rotate the credential. Vault the secret. Revoke what shouldn't be there. The loop closes.

step 05
Prove

Checksummed, auditor-ready evidence packs from every run. Immutable by design.

/ 03The product
recorded in the live platform

The actual product. No slideware.

Real walkthroughs recorded in the live platform — reviews, blueprint runs and evidence packs as your team would see them.

ndgm.app /reviews
● REC
/ 04The agent
local models · human gates

Meet Reeve. Governance that doesn't wait for tickets.

Reeve watches your identity graph continuously. It detects the orphaned account or ageing credential, triages it with AI running on local models, opens a job with its reasoning attached — and once you approve, it acts: assigns the owner, rotates the secret, closes the loop.

Runs on local models — your data never leaves your estate
Human-approval gates on every destructive action
Every job carries its reasoning and a confidence score
reeve (n.) — the English official who kept order long before “sheriff” was a word.
reeve · jobs queue● 3 active
orphaned_nhirecommended
Service account svc-data-sync has no owner
→ Assign owner j.whitfieldconf 0.91
secret_hygieneawaiting approval
App credential entra-prod-02 is 84 days old
→ Rotate & vault credentialconf 0.88
orphaned_nhirecommended
API key ci-deploy-key unused for 60 days
→ Open reviewconf 0.79
local model · no egress
/ 05The edge
metadata only · outbound-only

Govern what your cloud APIs can't see.

Most identity tools stop at the SaaS API. NDGM's lightweight edge agent runs inside your environment — a VM, a container, or a laptop — and surfaces the identity risk that never reaches a cloud console. Findings are reported as metadata only; raw secrets never leave your environment, and each one is handed to Reeve to govern.

/ secrets sprawl
Unmanaged secrets

An AWS key in a .env, a private key on disk, a token in a config file. The agent finds them — and Reeve queues each one to vault and rotate.

/ shadow ai
Shadow AI & MCP

Every AI agent and MCP server is a non-human identity with real credentials and scope. NDGM discovers them and governs them like any other identity — owner, least privilege, kill-switch.

Metadata onlyOutbound-onlyDocker or bare VPSReads only what you scope it to
/ 06The platform
four_pillars.no_gaps

Four pillars. No gaps.

Govern

Blueprint-driven access reviews with AI-recommended decisions, for humans and machines alike.

Enforce

Rotate credentials and vault secrets automatically — Keeper Secrets Manager integration live today.

Prove

Every decision paired with a checksummed evidence item. One-click auditor-ready packs.

Sovereign

Self-host in your estate. AI on local models. Built and hosted in the UK.

/ 07From our live deployment
customer_zero.metrics
7:1

Non-human to human identities found in our live deployment's first sync — 350 NHIs against 48 people.

90d

Fully-automated credential rotation cadence — minted, verified, vaulted, no human in the loop.

Mins

From connecting a source to first governance findings.

100%

Of review decisions evidence-backed with SHA-256 checksums.

/ 08Who it's for
teams + msps

Built for teams — and the MSPs who serve them.

for security & IT teams
Own your audit. Govern everything.

One live graph for every human, service account and AI agent. Blueprint reviews your auditors accept, enforcement your board expects, deployed in your estate — not someone else's cloud.

for MSPs
Deliver governed identity as a service.

Multi-tenant by design. Bundle governance, PAM and vaulting into one managed offering with margin you own.

Talk to us about the MSP programme →
Trusted patterns for regulated work: financial services · healthcare · AI platforms · public sector
/ 09Integrations
70+ connectors · 13 categories

Connect anywhere. Govern everywhere.

Microsoft Entra ID, GitHub and CSV import are live today — 70+ connectors across 13 categories are shipping through 2026.

Microsoft Entra ID LIVEGitHub LIVECSV import LIVE
Identity providersCloud IAMDevOpsHR / HRISSaaSSecurityMonitoringSecrets / PAMInfrastructureITSMCI / CDFinanceMDM
/ 10Security & trust
designed like the systems it governs

Designed like the systems it governs.

Tenant isolation

Row-level security at the database layer — every query scoped to one tenant.

Immutable audit

Every decision creates a SHA-256-checksummed evidence item. Tamper-evident by default.

Self-host option

Run NDGM entirely inside your own estate, including the AI.

UK GDPR

UK-built, UK-hosted, processor terms published. No third-party AI providers.

/ engage

See NDGM on your estate.

A 30-minute tailored walkthrough. Bring a real cloud account — we'll map it live. No slideware.

NDGM

Closed-loop identity governance. Built & hosted in the United Kingdom.

© 2026 NDGM · United Kingdom[email protected]

NDGM is a trading name of Agile Tech Global Solutions Limited, registered in England and Wales (company no. 14654678). Registered office: 27 Old Gloucester Street, London, WC1N 3AX. VAT registration no. GB 486 3793 36.