Ultra is aligned with and an early contributor to AARM and the Agentic Trust Control Framework.

Products/Identity
Identity

Verify who is calling.

Every MCP client and agent is detected, fingerprinted, and attributed to an identity, with an assurance tier that tells you how confident that attribution is and per-agent scoping for access control.


01 · How it works

Verified before the call is forwarded.

The proxy detects the client type and version on every connection. The Hub's Identities and Clients views roll that up per user and agent with role, assurance, activity, and guardrail and anomaly history, and flag configuration drift across a multi-host fleet.

Detection

Client and agent identity

The proxy detects the client type and version on every connection, attributing each call to an identity instead of an anonymous session.

Assurance

Four-tier assurance model

Every attribution carries a confidence tier, authenticated, gateway-attributed, none, or unattributed, so you know how much to trust who you are looking at.

Membership

Member vs non-member

A non-member badge flags activity from accounts that are not in the org, surfacing offboarded employees and service accounts still making calls.

History

Activity and risk per identity

See tool calls, servers used, guardrail blocks, anomalies, and a peak-hour heatmap for any identity, with deep links into the audit log.


02 · Roster

Every identity, with the receipts.

The Identities roster lists every user and agent with role, assurance, and activity, and the Clients view flags configuration drift across a multi-host fleet, managed, partial, or unmanaged, so a bypassed gateway stands out.



Know exactly who is calling your tools.

Join the waitlist to get early access to Ultra's AI-native security and governance.