# Anthembasis

*/Startups/Anthembasis*

## Startup Overview

This access governance engine maps cross-platform entitlements into unified policies. It connects disparate directories, applications, and cloud environments to build a strict, continuous record of user permissions. Security and IT teams use this capability to identify over-provisioned accounts and enforce least-privilege access rules across the entire enterprise stack.

Managing user access across fragmented software environments traditionally relies on manual spreadsheet audits or fragile point-to-point integrations. When employees change roles, siloed identity data leaves ghost accounts and unauthorized access paths exposed. Translating raw, system-specific entitlement data into standardized policies removes these blind spots and exposes hidden vulnerabilities.

Legacy governance platforms like SailPoint and ecosystem-locked tools like Okta Identity Governance restrict operations to supported vendor networks. This architecture rejects those constraints by remaining completely infrastructure-agnostic, securing permissions across any mix of bespoke or commercial software. Because it is fully autonomous in execution, it applies policy updates and revokes unauthorized privileges immediately, eliminating the reliance on scheduled compliance checks.

## Startup Founding Hypothesis

**Approach**: that maps cross-platform access entitlements into unified policies
**Competitors**:
- [Okta Identity Governance](/Competitors/Okta_Identity_Governance)
- [SailPoint](/Competitors/SailPoint)
- [manual spreadsheet audits](/Competitors/manual_spreadsheet_audits)
**Differentiator2x2**: fully autonomous in execution and completely infrastructure-agnostic

## Startup Solution Coordinate

**Solution**: [Autonomous Access Mapper](/Software/Autonomous_Access_Mapper)

## Startup Position2x2

```mermaid
quadrantChart
    x-axis Infrastructure-Coupled --> Completely Infrastructure-Agnostic
    y-axis Manual / Assisted Execution --> Fully Autonomous Execution
    quadrant-1 Autonomous & Agnostic
    quadrant-2 Autonomous & Coupled
    quadrant-3 Manual & Coupled
    quadrant-4 Manual & Agnostic
    manual spreadsheet audits: [0.85, 0.15]
    Okta Identity Governance: [0.15, 0.85]
    SailPoint: [0.60, 0.70]
    Anthembasis: [0.90, 0.90]
```

## Startup Offer

**Proof**:
- Targeting high-growth startups to reduce quarterly access compliance audit durations from weeks to hours
- Aiming to help distributed engineering teams automatically revoke 100% of orphaned credentials upon offboarding
- Designed to give IT directors complete visibility into shadow IT access permissions within 48 hours
**Tiers**:
- Name: Audit Mapping · Price: ~$400–$800/mo base + ~$1.00 per active identity · Inclusions: Read-only access mapping for up to 5 standard platforms (e.g., Google Workspace, Slack, GitHub) and daily entitlement reconciliation reports for security teams.
- Name: Autonomous Governance · Price: ~$1,200–$2,000/mo base + ~$2.50 per active identity · Inclusions: Automated access remediation, unlimited standard platform connectors, cross-platform anomaly alerts, and continuous policy enforcement for IT and compliance departments.
- Name: Agnostic Enterprise · Price: ~$4,000–$6,500/mo base + ~$4.00 per active identity · Inclusions: Support for custom and legacy infrastructure connectors, dedicated single-tenant hosting, real-time enforcement, and API access for enterprise identity engineering teams.
**Guarantee**: If Anthembasis does not successfully map and categorize at least 95% of your cross-platform access entitlements within the first 30 days of deployment, we will refund your first month's fees and provide our integration engineering team to complete the mapping manually at no cost.
**Business Function**: ProvideService
**Objection Handlers**:
- Objection: We already use Okta for identity management. Rebuttal: Okta governs federated apps well, but Anthembasis maps entitlements across Okta, standalone SaaS tools, and un-federated legacy systems autonomously.
- Objection: Our custom internal tools do not have standard APIs for access mapping. Rebuttal: Anthembasis is designed infrastructure-agnostic, interpreting database roles and flat-file permissions where standard APIs do not exist.
- Objection: Automated remediation might accidentally revoke critical developer access. Rebuttal: You configure the enforcement mode; autonomous actions can be set to 'alert only' or routed to a Slack approval workflow before execution.
- Objection: Extracting this data violates our compliance policies. Rebuttal: Anthembasis processes access metadata only, never reading user data payloads, and the enterprise tier offers dedicated single-tenant hosting.
**Pricing Architecture**: UsageMeter
**Agent Checkout Support**:
- agentic-commerce-protocol

## Startup Brand

**Voice**: Clinical engineering register anchored by absolute infrastructural neutrality.
**Tagline**: Map and enforce cross-platform access entitlements autonomously.
**Icon Concept**: keycard
**Palette Intent**: institutional-cool
**Visual Identity**: Deep slate and crisp white backgrounds are accented by sharp cobalt blue lines that resemble policy trees mapping access pathways.
**Archetype Reference**: the-ruler

## Startup Buyer Chain

**Chain**: Anthembasis → IAM Architects → Enterprise Workforce
**Gtm Motion**: Acquires mid-market IT security teams by offering a free initial entitlement audit on a single cloud platform, then expands contract value by charging per additional integrated infrastructure environment and connected SaaS application.
**Agent Channel**: Designed to list its OpenAPI entitlement-query schema in the LangChain tool registry and autonomous SecOps agent catalogs, allowing security AI agents to query user permissions across platforms without human intervention.
**Primary Channel**: Searches on the AWS Marketplace and Azure Commercial Marketplace for automated access governance and cross-platform entitlement mapping.

## Startup Customer Journey

```mermaid
flowchart LR; A[AWS Marketplace Search] --> B[OpenAPI Schema Registration]; B --> C[Free Entitlement Audit]; C --> D[Active Identity Meter]; D --> E[Autonomous Governance Upgrade]; E --> F[Compliance Audit Report];
```

## Startup Proof Points

_Illustrative — target and order-of-magnitude estimate figures, not an achieved track record (this Thing is concept-stage)._

**Pilot Goals**:
- 30-day read-only mapping pilot across 5 standard platforms to prove Anthembasis maps and categorizes at least 95 percent of active identity entitlements without manual intervention.
- 60-day remediation pilot with a specific engineering pod to test the transition from 'alert only' access anomaly detection to automated Slack-approval revocation workflows.
**Target Metrics**:
- Target: 95 percent cross-platform access entitlement mapping within the first 30 days of deployment.
- Aim: 100 percent automated revocation rate for orphaned credentials across non-federated systems.
- Target: Reduction of quarterly compliance audit duration from 3 weeks to under 4 hours.
- Aim: 48-hour detection time for undocumented shadow IT access permissions.
**Target Case Studies**:
- Mid-sized distributed engineering team: Automatically revoke orphaned credentials across standard repositories and internal un-federated tools immediately upon contractor offboarding.
- Series C SaaS company preparing for compliance audits: Reduce quarterly access audit duration from weeks of manual spreadsheet reconciliation to hours via daily automated entitlement mapping.
- Enterprise IT department managing legacy infrastructure: Map database roles and flat-file permissions without standard APIs to achieve complete visibility into shadow IT access within 48 hours.
**Testimonial Targets**:
- VP of Engineering: Validates that Anthembasis catches the un-federated database roles and custom tool access that standard identity providers miss.
- IT Director: Confirms the Slack approval workflow for remediation cleans up permissions without accidentally revoking critical developer access.
- Head of Security: Highlights how metadata-only daily entitlement reports make compliance audits painless without risking user data payload exposure.

## Startup Top Risks

**Risks**:
- Severity: existential · Description: Major SaaS platforms restrict the IAM APIs required for autonomous execution, breaking the core product functionality. · Mitigation Status: unmitigated
- Severity: high · Description: An autonomous execution error inadvertently revokes admin access across a client's core infrastructure causing a catastrophic lockout. · Mitigation Status: in-progress
- Severity: high · Description: Incumbent competitors like SailPoint bundle autonomous remediation features into their existing enterprise contracts to block new deployments. · Mitigation Status: unmitigated
- Severity: moderate · Description: Onboarding obscure legacy infrastructure platforms requires extensive custom mapping that extends enterprise deployment timelines. · Mitigation Status: in-progress

## Startup Competitors

- [Okta Identity Governance](/Competitors/Okta_Identity_Governance) — Incumbent
- [SailPoint](/Competitors/SailPoint) — Legacy Platform
- [Manual Spreadsheet Audits](/Competitors/Manual_Spreadsheet_Audits) — Status Quo
- [Opal Security](/Competitors/Opal_Security) — Challenger Startup
- [Varonis Systems](/Competitors/Varonis_Systems) — Incumbent

## Startup Solution Stack

- [Access Policy Mapping Service](/Services/Access_Policy_Mapping_Service) — Service-as-Software
- [Entitlement Discovery Agent](/Agents/Entitlement_Discovery_Agent) — Agent
- [Policy Translation Worker](/Agents/Policy_Translation_Worker) — Agent
- [Cross-Platform Access SDK](/Software/Cross-Platform_Access_SDK) — Software
- [Entitlement Resolution Engine](/Software/Entitlement_Resolution_Engine) — Software

## Startup Story Brand

**Hero**:
- **Need**: to be the architecture's architect, not the manual cleanup crew for orphaned credentials
- **Want**: to achieve absolute visibility and control over cross-platform access entitlements
- **Identity**: the IT director managing a scaling, distributed workforce
**Plan**:
- Step: Identify Platforms · Detail: Index your standard SaaS tools and legacy databases to visualize current access pathways.
- Step: Approve Policies · Detail: Set enforcement rules for cross-platform remediation or route alerts to a Slack workflow.
- Step: Enforce Governance · Detail: Let the system autonomously revoke orphaned credentials and maintain continuous compliance audits.
**Guide**:
- **Empathy**: You shouldn't still be manually chasing shadow IT. Okta Identity Governance wasn't built to map entitlements across un-federated legacy systems autonomously.
**Problem**:
- **Villain**: spreadsheet sprawl
- **External**: Reconciling access across Okta, GitHub, and Slack takes weeks of manual export-and-compare audits in Excel.
- **Internal**: You feel like a glorified data-entry clerk chasing shadows instead of securing the company.
- **Philosophical**: Why should IT directors accept permission fragmentation when a unified policy layer is possible?
**Success**: Access governance is fully autonomous, allowing you to revoke credentials instantly across all platforms and close audits in hours.
**One Liner**: What if your access audits were autonomous? Anthembasis maps cross-platform entitlements into unified policies, revoking 100% of orphaned credentials automatically.
**Positioning**:
- **So That**: revoke orphaned credentials across all platforms instantly
- **Unlike**: manual spreadsheet audits
- **For Whom**: IT directors at high-growth startups
- **Category**: Autonomous Identity Governance
**Call To Action**:
- **Direct**: Map your identities
- **Transitional**: Review sample audit report
**Failure Stakes**:
- Compromised credentials lead to preventable breaches
- Quarterly audits consume hundreds of engineering hours
- Failed compliance certifications stall enterprise deals
**Transformation**:
- **To**: the domain's infrastructure architect
- **From**: the admin buried in Slack and GitHub settings
**Controlling Idea**: Access governance should be infrastructure-agnostic and fully autonomous.

## Startup Token Hero

**Genre**: founding-hypothesis
**Rendered**: What if your access audits were autonomous? Anthembasis maps cross-platform entitlements into unified policies, revoking 100% of orphaned credentials automatically.
**Mechanism**: spine-derived-v1
**Template Id**: spine-founding-hypothesis
**Vocab Fingerprint**: 46fc7cb066ca06b7

## Startup Token Positioning

**Genre**: moore-positioning
**Rendered**: Autonomous Identity Governance for IT directors at high-growth startups. Unlike manual spreadsheet audits — revoke orphaned credentials across all platforms instantly.
**Mechanism**: spine-derived-v1
**Template Id**: spine-moore-positioning
**Vocab Fingerprint**: 3684e8e3a66b0561

## Startup Token Pitch Deck

**Genre**: pitch-deck
**Rendered**: Problem: Reconciling access across Okta, GitHub, and Slack takes weeks of manual export-and-compare audits in Excel.
Solution: What if your access audits were autonomous? Anthembasis maps cross-platform entitlements into unified policies, revoking 100% of orphaned credentials automatically.
Customer: IT directors at high-growth startups
Unlike: manual spreadsheet audits
**Mechanism**: spine-derived-v1
**Template Id**: spine-pitch-deck
**Vocab Fingerprint**: f205af4f949c28d1

## Startup Token M E D D P I C C

**Pain**: Reconciling access across Okta, GitHub, and Slack takes weeks of manual export-and-compare audits in Excel.
**Metrics**: Target: Access governance is fully autonomous, allowing you to revoke credentials instantly across all platforms and close audits in hours.
**Rendered**: Pain: Reconciling access across Okta, GitHub, and Slack takes weeks of manual export-and-compare audits in Excel.
Economic buyer: IAM Architects
Metrics: Target: Access governance is fully autonomous, allowing you to revoke credentials instantly across all platforms and close audits in hours.
Competition: manual spreadsheet audits
**Mechanism**: spine-derived-v1
**Competition**: manual spreadsheet audits
**Economic Buyer**: IAM Architects
**Vocab Fingerprint**: 482516d1ec71af9c

## Startup Token Cold Email

**Genre**: cold-email
**Rendered**: Subject: Autonomous Identity Governance for IT directors at high-growth startups

IT directors at high-growth startups — Reconciling access across Okta, GitHub, and Slack takes weeks of manual export-and-compare audits in Excel. What if your access audits were autonomous? Anthembasis maps cross-platform entitlements into unified policies, revoking 100% of orphaned credentials automatically.
**Mechanism**: spine-derived-v1
**Template Id**: spine-cold-email
**Vocab Fingerprint**: 9675d5119647aa32

## Startup Token Agent Spec

**Genre**: ai-agent-spec
**Rendered**: Autonomous Identity Governance. What if your access audits were autonomous? Anthembasis maps cross-platform entitlements into unified policies, revoking 100% of orphaned credentials automatically. Serves IT directors at high-growth startups.
**Mechanism**: spine-derived-v1
**Template Id**: spine-ai-agent-spec
**Vocab Fingerprint**: cc7c4ea125c7403d

## Neighborhood

### Candidate solutions

- [Calculate Grower Liquidations](/Problems/Calculate_Grower_Liquidations) — candidate solution for · Problems

### What it offers

- [Autonomous Access Mapper](/Software/Autonomous_Access_Mapper) — offers · Software

### Composed of

- [Access Policy Mapping Service](/Services/Access_Policy_Mapping_Service) — composes · Services
- [Entitlement Discovery Agent](/Agents/Entitlement_Discovery_Agent) — composes · Agents
- [Policy Translation Worker](/Agents/Policy_Translation_Worker) — composes · Agents
- [Cross-Platform Access SDK](/Software/Cross-Platform_Access_SDK) — composes · Software
- [Entitlement Resolution Engine](/Software/Entitlement_Resolution_Engine) — composes · Software

### Competitors

- [Varonis Systems](/Competitors/Varonis_Systems) — competes with · Competitors
- [Okta Identity Governance](/Competitors/Okta_Identity_Governance) — competes with · Competitors
- [Manual Spreadsheet Audits](/Competitors/Manual_Spreadsheet_Audits) — competes with · Competitors
- [Opal Security](/Competitors/Opal_Security) — competes with · Competitors
- [SailPoint](/Competitors/SailPoint) — competes with · Competitors

### Embodies

- [Software](/Theses/Software) — embodies · Theses

### Similar Startups

- [Direridian](/Startups/Direridian) — similar · Startups
- [Octity](/Startups/Octity) — similar · Startups
- [Accibe](/Startups/Accibe) — similar · Startups
- [Accaze](/Startups/Accaze) — similar · Startups
- [Accepository](/Startups/Accepository) — similar · Startups
- [Hegen](/Startups/Hegen) — similar · Startups
- [Consolidatesphere](/Startups/Consolidatesphere) — similar · Startups
- [Deltaridge](/Startups/Deltaridge) — similar · Startups
- [Rigavanna](/Startups/Rigavanna) — similar · Startups
- [Accault](/Startups/Accault) — similar · Startups
- [Coordinatorfield](/Startups/Coordinatorfield) — similar · Startups
- [Staborus](/Startups/Staborus) — similar · Startups
- [Verow](/Startups/Verow) — similar · Startups
- [Florix](/Startups/Florix) — similar · Startups
- [Corelamp](/Startups/Corelamp) — similar · Startups
- [Datapalace](/Startups/Datapalace) — similar · Startups
- [Latticeforge](/Startups/Latticeforge) — similar · Startups
- [Accocess](/Startups/Accocess) — similar · Startups
- [Capabilityhaven](/Startups/Capabilityhaven) — similar · Startups
- [Frontierhaven](/Startups/Frontierhaven) — similar · Startups
