IT Governance
Everything IT needs to manage AI tooling across the organisation: identity provisioning, policy controls, managed deployment, usage analytics, and compliance monitoring.
Identity
Users authenticate through the existing identity provider. Groups and memberships sync automatically via SCIM 2.0. Deprovisioning follows the IdP lifecycle.
Google, Microsoft, SAML 2.0, OpenID Connect. Users authenticate through the identity provider the organisation already uses.
Automated user and group sync. Users and groups create, update, and deprovision automatically. Tested with Okta, Azure AD, and OneLogin.
Policies assign to groups synced from the IdP. No manual user-to-policy mapping required. Policies merge deterministically when a user belongs to multiple groups.
Soft deactivate (preserves data, user can be re-provisioned) or full removal (revokes sessions, deletes memberships, removes from groups). Configurable per organisation.
Users link multiple SSO providers to one identity. Switching identity providers does not create duplicate accounts.
Sessions scoped per device. Revoking one device does not affect others. Brute-force protection on all authentication endpoints.
Managed deployment
A lightweight installer that authenticates via SSO, fetches an encrypted policy, and provisions the complete environment. IT distributes it through their existing MDM.
The installer opens the organisation's SSO provider in the system browser. No credentials stored locally.
After authentication, the installer requests the user's resolved policy from the server. Encrypted and tailored to the user's group membership.
Downloads the client app, plugins, and models specified by the policy. Every artefact is SHA256-verified.
The device exchanges cryptographic keys with the server and registers for ongoing policy management.
The user is productive immediately. The right plugins, the right models, the right settings. No manual setup.
Policy engine
Vendor restrictions, bundle composition, group targeting, phased deployment, compliance monitoring, and MDM enforcement.
Phased rolloutsQ2/Q3 2026
Create a deployment, pick a strategy, and define success criteria. The scheduler rolls out the policy in phases. Each phase waits for enough devices to report success before proceeding.
If error rates exceed the threshold, the deployment pauses automatically. One click rolls back to the previous policy. Every device, every phase, every error is logged for audit.
Works with the existing stack
The device MDM handles the device. Swarmix policies handle the application. The installer is an MSI, PKG, or DEB. Distributed the same way as everything else.
The outcome
Monitoring
Per-vendor and per-model usage breakdown, OpenTelemetry instrumentation on every tool invocation, and a full audit log of agent decisions and knowledge changes.
Compliance
ISO/IEC 42001 is the international standard for AI management systems. These are the clause areas it requires and where Swarmix provides supporting infrastructure.
Drift detectionQ2/Q3 2026
The policy agent on each device continuously compares actual state to desired state. If a user uninstalls a required plugin, changes a locked setting, or installs an unapproved extension, the dashboard shows it within minutes.
Remediation is configurable per restriction: auto-fix silently, warn and fix, report to admin, or block the app until resolved. IT controls the trade-off between user freedom and organisational compliance.
SSO, SCIM, and policy controls are available now. Managed deployment and drift detection are shipping in Q2/Q3 2026.
A walkthrough of unified visibility, governance, and intelligence across every AI vendor and team.