ProductsHow It WorksThe StudioThe Orchestrator
EnterpriseOverviewIntelligenceWho It's ForSecurityIT Governance
Pricing
ResourcesBlogFAQ
Get in touch

IT Governance

AI tooling under IT governance.

Everything IT needs to manage AI tooling across the organisation: identity provisioning, policy controls, managed deployment, usage analytics, and compliance monitoring.

IdentitySSO, SCIM provisioning, group-based access
DeploymentMDM distribution, managed installer, enrolment
Policy EngineVendor restrictions, bundles, phased rollout
MonitoringUsage analytics, audit trail, compliance
1

Single Sign-On

Google, Microsoft, SAML 2.0, OpenID Connect. Users authenticate through the identity provider the organisation already uses.

2

SCIM 2.0 provisioning

Automated user and group sync. Users and groups create, update, and deprovision automatically. Tested with Okta, Azure AD, and OneLogin.

3

Group-based policy targeting

Policies assign to groups synced from the IdP. No manual user-to-policy mapping required. Policies merge deterministically when a user belongs to multiple groups.

4

Configurable deprovisioning

Soft deactivate (preserves data, user can be re-provisioned) or full removal (revokes sessions, deletes memberships, removes from groups). Configurable per organisation.

5

Linked accounts

Users link multiple SSO providers to one identity. Switching identity providers does not create duplicate accounts.

6

Session isolation

Sessions scoped per device. Revoking one device does not affect others. Brute-force protection on all authentication endpoints.

SSOGoogle, Microsoft, SAML, OIDC
SCIM 2.0Okta, Azure AD, OneLogin
Multi-orgUsers switch between organisations
The existing MDM distributes the installer
Microsoft IntuneJamf ProSCCM / Ansible
Pushes installer
LIGHT INSTALLER
Authenticate · Fetch Policy · Download · Verify · Configure · Enrol

Provisions
What lands on the user's machine
Client app
pinned version
Plugins
configured per policy
AI Models
embeddings, rankers
Settings
locked or defaults
01

Authenticate

The installer opens the organisation's SSO provider in the system browser. No credentials stored locally.

02

Fetch policy

After authentication, the installer requests the user's resolved policy from the server. Encrypted and tailored to the user's group membership.

03

Provision

Downloads the client app, plugins, and models specified by the policy. Every artefact is SHA256-verified.

04

Enrol

The device exchanges cryptographic keys with the server and registers for ongoing policy management.

05

Launch

The user is productive immediately. The right plugins, the right models, the right settings. No manual setup.

Access Control

Vendor and model restrictionsDeclare which AI vendors and models each team can access. Everything outside the allowlist is blocked at the application level.
MDM enforcementWhen the organisation requires managed installation, the server blocks unenrolled clients. Three enforcement modes: audit, partial, then full.

Configuration

Bundle compositionEach policy resolves to a concrete bundle: client version, plugins at pinned versions, configuration overrides, and post-install steps. All SHA256-verified.
Group-based targetingAssign policies to groups, roles, or individual users. When a user belongs to multiple groups, policies merge deterministically. Most-restrictive-wins.

Deployment

Phased deploymentRoll out in phases: canary to 5%, then engineering, then everyone. Success criteria gate each phase. Auto-pause on error rate spikes.
Compliance monitoringEvery enrolled device reports its state on a configurable interval. Dashboard shows compliance %, drift events, stale devices, and deployment progress.

Phased rolloutsQ2/Q3 2026

Progressive deployment with automatic rollback

Create a deployment, pick a strategy, and define success criteria. The scheduler rolls out the policy in phases. Each phase waits for enough devices to report success before proceeding.

If error rates exceed the threshold, the deployment pauses automatically. One click rolls back to the previous policy. Every device, every phase, every error is logged for audit.

Canarycomplete
5% of engineering
8/8 devices
Engineeringactive
All engineers
41/79 devices
Everyonepending
All groups
0/162 devices
Intune / Entra IDPush the installer via Intune. Groups sync from Entra ID via SCIM. SSO for authentication.
Jamf / Apple MDMDistribute via Jamf policies. Keychain integration for at-rest policy encryption.
Ansible / SCCMAutomate with DEB/RPM packages. Silent mode for headless deployment.
SCIM syncGroups and users sync from the identity provider. Policy targeting mirrors the AD structure.
< 5 minUser onboarding
100%Compliance visibility
1-clickRollback capability
ZeroUnmanaged installations
LLM
Usage analytics
Per-vendor, per-model breakdown
OTLP
OpenTelemetry
Grafana, Jaeger, Datadog export
SOC 2
Audit trail
Decisions, votes, knowledge changes
380
Flow coverage
23 domains, event routing
AI governance
Clause 5
Structured proposals, consensus voting, role-based agent identity, and remit enforcement.
Risk management
Clause 6.1
Plan gates, milestone verification, dependency tracking, and health monitoring.
Data management
Annex A.7
On-device content detection, vendor restrictions, encrypted policy state, and training opt-in.
Monitoring
Clause 9
LLM usage analytics, OpenTelemetry instrumentation, per-vendor breakdowns.
Audit
Clause 9.2
Full audit trail of agent decisions, knowledge changes, ticket transitions, and governance actions.
Continual improvement
Clause 10
Versioned knowledge base with review workflows, drift detection, and policy simulation.

Drift detectionQ2/Q3 2026

Continuous state comparison against policy

The policy agent on each device continuously compares actual state to desired state. If a user uninstalls a required plugin, changes a locked setting, or installs an unapproved extension, the dashboard shows it within minutes.

Remediation is configurable per restriction: auto-fix silently, warn and fix, report to admin, or block the app until resolved. IT controls the trade-off between user freedom and organisational compliance.

Compliant
Settings match policy, plugins present and verified
Drift
Locked setting changed or required plugin removed
Error
Policy application failed, needs IT attention
Stale
Device has not checked in within the expected window

Talk to us about IT administration.

SSO, SCIM, and policy controls are available now. Managed deployment and drift detection are shipping in Q2/Q3 2026.

Book a Call

See how Swarmix works

A walkthrough of unified visibility, governance, and intelligence across every AI vendor and team.

  • Deploy in weeks
  • Works with any existing AI stack
  • SOC 2 compliant, GDPR ready