Passport Enterprise

Give teams real AI access without giving up control.

People keep Claude, ChatGPT, Cursor, Codex, VS Code, and terminal agents, while IT gets one place to manage which MCPs each person reaches and how access is revoked.

Enterprise plan $30 / member / month

Managed catalog rollout, team access, identity lifecycle, and activity streaming. Annual invoicing is available.

Discuss your rollout
Nothing new to installMembers connect once with the clients they already run. No per-vendor setup, no mcp.json edits.
One cross-client control planeManage access, credentials, and policy in one place instead of rebuilding them in every AI vendor.
Governed calls stay attributableKnow who used which client, MCP, and tool, plus the outcome.
Controlled self-service

Give people a paved road, not another ticket queue.

Start open for approved MCPs, require review, or route access through rules that match your organization.

01

Choose how the catalog rolls out

Let people connect supported MCPs themselves, require admin review, or apply rules by MCP, category, publisher, and team.

02

Match access to the job

Set full, read-only, or no access by workspace, team, and person, then narrow individual governed tools when needed.

03

Connect identity to offboarding

Use OIDC SSO and SCIM provisioning and group mapping. Deprovisioning cuts Passport sessions, clients, and account grants.

04

Give auditors the access records they ask for

Review member activity and privileged admin changes, export CSV or JSONL, or stream governed activity to SIEM / OTLP.

From pilot to rollout

Keep the clients. Centralize the hard parts.

Passport sits between the AI experience and the work app, so adoption does not depend on standardizing everyone on one AI vendor.

1 · ConnectEmployees use supported desktop, hosted, editor, and terminal clients with a Passport identity.
2 · GovernAccess, approvals, guardrails, and client selection run at the gateway on governed calls.
3 · RevokeEnd access centrally when a person, client, account, or automation should stop.
Why this matters

Most teams cannot see what their AI already touches.

Recent research on AI adoption and oversight.

21% of enterprises can see what their AI agents and MCP tools actually do. Akto, 2025
82% of data pasted into AI tools goes through personal accounts security teams can't govern. LayerX, 2025
83% / 13% 83% of companies use AI. Only 13% can see how it touches their data. Cyera, 2025
Security and procurement

Give reviewers evidence they can inspect.

Security posture, Trust summary, DPA and SCCs, subprocessors, privacy terms, and live service status are public. Current assurance gaps stay explicit.

Deployment choice

Use hosted Passport or keep it in your VPC.

The hosted service runs in the United States. Self-hosting uses one application container plus your Postgres and encryption keys, with the same gateway, catalog, and controls.

Early-access assurance boundary

Passport does not yet publish a SOC 2 report, independent third-party penetration-test report, independent uptime history, or contractual SLA/RTO/RPO. Review the Trust summary before procurement.

Plan a rollout your developers will actually use.

Tell us which clients, identity provider, controls, and deployment model your team needs.