Tachikoma tachikoma
Book a demo
Lineage-based access control · open source

Access control for AI agent outputs.

Tachikoma lets AI agents work across all your systems, so everything they produce inherits the access rules of the data it came from. A report built from restricted data only opens for people who could already read that data.

Sits on top of what you already have — no migration.

Book a demo See how it works
Drop-in compatible

Works with any of your existing AI solutions — no need to rebuild what already runs.

Keep your agents, your models, your tools — and your vendors' agents. One registry for all of them; Tachikoma sits underneath and governs what their outputs are allowed to reveal.

FIG.02 — Paradigm shift

Stop reviewing outputs. Start inheriting permissions.

Data-driven firms need agents to work across scattered sources. Tachikoma reads the access rules of every source and carries them into whatever the agent produces — answers, reports, summaries, files.

Reads your existing ACLs — warehouses, object storage, wikis, ticketing, drives.
Applies the strictest rule — an answer built on five sources inherits the tightest of the five.
Resolves per recipient — the same question returns different answers to different people.
Before — permissions lost at the output
agent reads restricted source
output → plain text, no rules
recipient → sees what they shouldn't
After — permissions inherited
agent reads restricted source
output → inherits source rules
recipient → checked, then served
FIG.03 — How it works

One registry. One live map. One trace.

A Monday-morning scenario: two vendor copilots and one internal agent build the board pack. Watch your access rules — not the vendors' — travel with the file, all the way to who can open it. Click a step to trace it.

FIG.04 — Omnirepo

Your scattered sources, mapped at the granularity of your access rules.

Every team, agent, and system becomes a node in one permission-aware graph. Agents get real accounts, scoped networks, and borrowed secrets — so what they read is always attributable to a source and a rule.

tachikoma · context graph
● lumo
│ venv: lumo (galaxy)
│ network: lumo.*.tachikoma.sh (127.0.1.14)
│ manager: claude-lumo-a827b9 [claude]
│ ● agent
│ │ secrets: ZAI_API_KEY borrow
│ │ network: lumo.agent.*.tachikoma.sh (127.0.1.17)
│ │ manager: manager-agent-9e0029 [claude]
│ │ ● rag-agent
│ │ │ secrets: ZAI_API_KEY borrow
│ │ │ network: …rag-agent.*.tachikoma.sh (127.0.1.18)
│ │ └ profiles: tachikoma-agent-snhx
└ ● new channel → propagated in sync
Kernel-level enforcement

Agents get Unix accounts and scoped addresses — access is decided in the OS, not in a prompt.

Source-attributed reads

Secrets are borrowed, never read. Every retrieval is tagged with the rule that allowed it.

Inheritance by default

New agents and new outputs inherit the strictest rule of everything they touched.

FIG.05 — Governance

Every output is checked before it reaches a person.

Agents don't get API keys — they get job descriptions. Reads are scoped, outputs carry their sources' rules, sensitive deliveries route to a human, and every decision lands on an immutable trail.

audit.loglive
agent:reconciler → post.ledger.entryallow
agent:analyst → read.pii.customerborrow
agent:payer → wire.transfer > $50k→ human
agent:crawler → delete.recorddeny
human:cfo → approve.wire.transfersigned
FIG.06 — Enterprise

Built for data-driven firms under real scrutiny.

Deploy where your data already lives, and answer the auditor's real question: for this output, which sources went into it — and was every recipient allowed to see them?

Currently in partnership conversations with major banking groups in Asia, on regulated production-grade use cases.

Open source, self-hosted

Runs entirely inside your infrastructure, next to the data it governs. No vendor lock-in.

One trace

On incident day: who read what, produced what, and for whom — replayable end to end.

Compliant with SOC 2 GDPR HIPAA ISO 27001
FIG.07 — Use cases

One rule set, every scattered source.

Banking
Reconciliation & reporting

Drafts inherit deal-room walls — no client data crosses into the wrong desk.

Government
Clearance-aware answers

Every answer is bounded by the recipient's clearance level, inside your perimeter.

Healthcare
PHI-safe workflows

Summaries built on patient data stay bounded to that patient's care team.

Insurance
Claims & underwriting

Adjusters see summaries scoped to their own book — never another policyholder's file.

In focus — Lumen

A team of agents that investigates — and shows its work.

Lumen runs multi-agent investigations on Tachikoma. Planner, retrieval, and legal agents work across scattered sources, cite their evidence, and return a recommendation that carries the access rules of every document it read.

Multi-agent — many specialists, one shared rule set.
Evidence-cited — every claim linked to a source, with a confidence score.
Access-bounded — each reader sees only the findings they're cleared for.
Telecom X — Leverage Covenant Breach INV-0048 Trace
14:31:02Planner— Creating investigation plan✓
14:31:05Retrieval— Searching Credit Agreement✓
14:31:09Legal— Reading EBITDA definition✓
14:31:14Analyst— Computing leverage ratio✓
14:31:18Reviewer— Routing high-value finding→ human
Recommendation
Covenant breached in Q4 2024
confidence
0.86

Let agents work everywhere. Leak nothing.

A report built from restricted data only opens for people who could already read that data. Open source, self-hosted, no migration.

Book a demo
Lumen — Investigation dashboard