Single sign-on, role-based access control, SIEM streaming, and a deployment model your infra team can sign off on — the controls a security questionnaire actually asks for.
Nobody signs in with a shared password, and every role's permissions are enforced on every request — not just hidden in the UI for roles that shouldn't see them.
Single sign-on (OIDC)
Okta, Azure AD, Google Workspace, or any OIDC-compliant IdP. A member signing in with an email at your registered domain is routed through your IdP and joins your org automatically.
Live
Role-based access control
Owner, admin, and viewer roles, enforced on every mutating action — kill switches, policies, approvals, billing, settings.
Live
SAML
Every major IdP this targets — Okta, Azure AD, Google Workspace — already speaks OIDC. SAML is a scoped fast-follow, available on request for enterprise deals that need it.
On request
Self-hosted deployment
Run Navige entirely inside your own environment via Docker Compose — nothing leaves your network, and licensing is a one-time offline check with no phone-home call to Navige at all. Built and verified end to end, for teams whose data residency or network policy means a shared cloud isn't an option at all.
Live
Managed bring-your-own-cloud
A Navige-managed deployment running inside your own cloud account, so you get the managed experience without self-hosted's operational overhead. On our roadmap — talk to us about your timeline.
Roadmap
Observability & Integration
Every decision, streamed into the tools you already run.
Governance data reaches your SIEM and your own risk model in real time — it doesn't live only in Navige's dashboard.
SIEM streaming
An HMAC-signed event for every governance decision — allowed, denied, pending, approved, rejected, expired. Ingested natively by Splunk HEC, Datadog, Microsoft Sentinel, and Elastic.
Live
Blockchain-anchored audit trail
Every batch hashed as a Merkle tree and anchored to Polygon — a single record can be proven without exposing the rest of its batch, and a separate completeness check catches a record deleted before it was ever anchored. Opt-in, free on every plan. Try the public verifier →
Live
Signed decision receipts
A portable, per-action evidence object — decision, the exact policy version that fired, and a Merkle proof when anchored — signed and verifiable completely offline. Hand one to a regulator or a client without them needing a Navige login.
Live
Shadow mode
Run fully connected without ever actually blocking or holding anything — every decision is still computed and recorded, none of it enforced. A report shows exactly what governance would have caught, before you ever let it touch production traffic.
Live
Agent Risk Score
Every agent scored 0–100 from real signals — autonomy level, coverage, ownership, denied or blocked calls, financial or destructive tool access, and access to sensitive systems.
Live
Gateway latency (p50/p95/p99)
Real overhead the governance layer adds to every tool call, computed from your own traffic and shown in your dashboard.
Live
On latency specifically: the number is only as meaningful as the traffic behind it. A brand-new organization sees a "too few samples" note until there's enough real call volume.
Contract & Compliance
Terms your legal and security teams can sign off on.
The paperwork a real procurement process needs.
MSA + DPA
A standard Master Services Agreement and a published Data Processing Agreement covering sub-processors, transfer mechanisms, and breach notification.
Navige's access controls and audit-evidence practices are built with SOC 2's requirements in mind. Formal certification has not yet been started.
Roadmap
Dedicated SLA
A formal uptime and support-response commitment. No uptime SLA exists today — this is on our roadmap as we build the monitoring history to back one, not something we'll write into a contract before we can actually stand behind it.
Roadmap
PII & secret masking
Emails, phone numbers, card numbers, and API keys are masked before they're ever written to storage — on every plan, not an enterprise add-on.