Trust and Identity squad

AI identity management across every customer channel

Cian Gatekeeper, Lead AI Customer Identity Director, an AI agent by FluxForceCian Gatekeeper — Lead AI Customer Identity Director

Cian Gatekeeper is an AI agent that keeps one identity record per customer across your app, web, branch and API. He watches for credential stuffing and account takeover signals, recommends when to step up authentication, and tracks what each customer has consented to. Anything risky reaches your team with the evidence attached.

Cian Gatekeeper
Cian Gatekeeper, Lead AI Customer Identity Director, an AI agent by FluxForce
Login spike on retail app
IllustrativeFlagged for review
Credential stuffing risk · high
Flag explained
“Many accounts tried from a few networks, high failed-password rate.”
NIST SP 800-207PSD2 SCA
REPORTS TO
Your CISO or Head of Fraud
Shadow mode first
How Cian works with your team
Shadow mode
first: nothing acts until you say so
3 bands
of autonomy you configure
Every decision
has a replayable record
1 per agent
kill switch
SaaS · on-prem · hybrid
deployment
Product controls, not performance claims. Performance is measured on your data, in shadow mode.
The problem

The identity problem behind account takeover

Your customer has a mobile login, a web login, a branch record and maybe an API consent. Each system keeps its own version of that person. Attackers test stolen passwords across all of them, and nobody sees the pattern in one place.

IDENTITY RECORDS
Many

versions of the same customer

Each channel keeps its own.

Fragmented identity

Four records, one person

The app, website, branch and API each hold a different view of the customer. A change in one channel doesn't reach the others.

Credential stuffing

Stolen passwords, tested at scale

Attackers run leaked username and password lists against your login pages. Spread across channels, the failed attempts look like noise.

Consent gap

Who agreed to what, and when

Data protection law asks you to show consent and its scope. When consent lives in four systems, answering one customer request turns into a search.

Job description

What Cian Gatekeeper does Job description

Cian Gatekeeper is a Lead AI Customer Identity Director. He sits beside your identity provider and channel systems, links each customer's records into one identity, and watches how that identity is used.

AI AGENT · TRUST AND IDENTITY SQUAD
Cian Gatekeeper, Lead AI Customer Identity Director, an AI agent by FluxForce
CIAN GATEKEEPER
Lead AI Customer Identity Director
REPORTS TO
Your CISO or Head of Fraud
WORKS WITH
Your identity provider, mobile and web apps, branch systems and APIs
DEPLOYED
Shadow mode first, then the autonomy you set
KEY RESPONSIBILITIES
01Link each customer's records across app, web, branch and API into one identity record
02Detect credential stuffing, password spraying and account takeover patterns across channels
03Recommend adaptive authentication steps based on the risk of each login and request
04Track consent and its scope for every customer, with a dated record of each change
05Send suspected takeovers and identity conflicts to an analyst with the evidence attached
AUTONOMY MODEL
Low risk
Can let routine logins continue, if you allow it
LOW
Medium risk
Goes to an analyst by default
MEDIUM
High risk
Always goes to an analyst
HIGH
You set the threshold per rule.
Kill switch: Turn Cian off at any time
Shadow mode

What to measure in shadow mode on your own data

We don't publish detection numbers from our own tests. Run Cian Gatekeeper beside your current identity controls and measure what he finds on your data before he acts on anything.

01
Records linked
How many channel records Cian links to one customer, and how many links your team confirms.
02
Identity conflicts
Customers whose details disagree across channels, such as two different phone numbers.
03
Stuffing campaigns found
Credential stuffing patterns Cian groups together that your current tools logged separately.
04
Missed-takeover review
Every confirmed takeover Cian scored low. Read this number first.
05
Step-up friction
How often good customers would face extra authentication under your proposed rules.
06
Analyst agreement
How often your analyst's decision matches Cian's recommendation, by risk band.
07
Consent completeness
Share of customers with a dated consent record covering each use of their data.
08
Decisions with evidence
Share of decisions with a replayable record. The target is all of them.
Shadow mode results belong to you. We agree the metrics, the time window and who reviews the closures before the trial starts.
How it works

How AI identity management works with Cian Gatekeeper

Cian Gatekeeper connects to your identity and channel systems through APIs. Your login flows stay where they are.

01

Connect

Login events, customer profiles, consent records and API access logs arrive from your apps, branch systems and identity provider.

02

Link

Cian matches records that belong to the same customer and flags conflicts, such as different contact details in different channels. Your team confirms any link he isn't sure of.

03

Watch

He looks for credential stuffing, password spraying and takeover patterns across all channels at once, and scores each login and sensitive request. Session trust from Nova Sentinel feeds the same view.

04

Route and record

Your autonomy settings decide what happens next. Routine logins can continue if you allow it. Medium risk goes to an analyst by default, and high risk always does. Every decision and consent change goes into tamper-evident evidence storage.

Want to see this on your data?

Run Cian Gatekeeper in shadow mode beside your current identity controls. He links records, scores logins and records why, and no customer is challenged or locked out. Compare his findings with your team's before you switch anything on.

Request a shadow mode trial
Compliance and regulatory mapping

Regulatory frameworks Cian Gatekeeper supports

Cian doesn't make you compliant. He produces the identity and consent evidence these frameworks expect you to keep.

NIST SP 800-207
Zero trust architecture verifies each access request. Cian applies that to customer logins and requests in every channel.
PSD2 strong customer authentication
EU payment providers apply SCA under RTS 2018/389. Cian records when step-up was recommended and why.
GDPR and UK GDPR
Consent is one lawful basis under Art. 6, and Art. 15 gives customers access to their data. Cian keeps one consent history per customer.
India DPDP Act 2023
India's data protection law sets rules for processing personal data with consent. Cian keeps the consent history your team reviews.
NYDFS Part 500
New York's cybersecurity regulation applies to covered financial firms. Cian adds customer access evidence to your controls review.
FATF Recommendation 10
Ongoing due diligence relies on current customer information. Cian flags conflicting details across channels for your KYC team.
Analyst view

What your identity and fraud teams see

One view of each customer, and takeover signals in one place.

BEFORE CIAN GATEKEEPER
A separate customer record in every channel
Failed logins scattered across systems
One authentication rule for every login
Consent spread across several systems
Takeovers found when the customer complains
AFTER CIAN GATEKEEPER
One linked identity record per customer
Credential stuffing grouped into a single campaign
Step-up recommended by the risk of each login
One dated consent history per customer
Suspected takeovers sent to an analyst with evidence
Options

How the options compare

CRITERIA Separate channel loginsStandard CIAM platform Cian Gatekeeper, Lead AI Customer Identity Director, an AI agent by FluxForceCian Gatekeeper
Time to first results Already in placePlatform migration project Shadow mode on your live login data
Who decides Fixed rules per channelPlatform policy, then your team Analyst, inside risk bands you set
One view of the customer NoYes, once migrated Linked across the systems you already run
Cross-channel attack view NoPartial Yes, with patterns grouped into campaigns
Why a login was challenged Rule IDPolicy name Plain-English reason with the signals behind it
Where it's weaker Attackers work the gaps between channelsA large migration before you see value Only as good as your source records, and uncertain links need human review
Trust Builders

Built for Regulated Financial Institutions

01

Configurable autonomy

Low risk can run on its own if you allow it. Medium risk goes to a person by default. High risk always goes to a person. You set the bands per rule, channel and transaction type.

02

Kill switch

Turn Cian off without touching the other agents or your core systems. The switch, and who used it, is stamped on the record.

03

Shadow mode

Run Cian on live data with nothing blocked or closed. Compare the calls with your team's before anything changes.

04

Explainability

Every decision answers why, in plain English, with the signals and the rule or policy behind it.

05

Audit trail

Each decision is stored with its inputs, its reasoning and the person who approved it, in tamper-evident evidence storage.

06

No migration

Agents connect beside your systems through APIs. Your core banking, screening and case tools stay where they are.

Questions? We Have Answers

Frequently Asked Questions

FluxForce

Still have questions?

Talk to the people who build the agents. We'll answer per capability, yes or no.

It keeps one identity record per customer across channels, watches how that identity is used and tracks consent. Cian Gatekeeper links records, detects credential stuffing and takeover patterns, and recommends when to step up authentication. Your team sets the rules and makes the call on anything risky.

No. Cian scores and recommends. Medium-risk activity goes to an analyst by default and high risk always does. Routine logins continue without review only where you allow it. A kill switch turns Cian off without touching your login flows.

No. Cian reads from the identity provider and channel systems you already run and links what they hold. Your authentication stays where it is.

He looks at failed and successful logins across every channel together: many accounts tried from a small set of networks, high failure rates and logins that match leaked credential patterns. He groups those attempts into one campaign for your team.

Cian links records and scores your live logins, but no customer is challenged or locked out. Your current controls keep working, and you compare his findings with your team's. You decide whether, and where, to switch on any autonomy afterwards.

He keeps a dated record of what each customer agreed to, through which channel, and every change since. That record supports access requests and consent reviews under the data protection law that applies to you.

FluxForce runs as SaaS, on-premise or hybrid, built on Microsoft Azure. We agree data residency and which components run inside your environment during deployment design, before any data moves.

Shadow mode trial

See Cian on your data before anything changes

Run Cian Gatekeeper beside your current process. He works on your live data and records every call, and nothing is blocked, closed or sent until you decide.

  • Runs in shadow mode on your own data, next to your team
  • You agree the metrics, the time window and who reviews the results
  • Kill switch and a replayable record of every decision from day one
  • SaaS, on-premise or hybrid, with data residency agreed up front

Shadow mode results belong to you.

Take the first step

AI agents that prepare the case. Your team makes the call.

Start with one workflow in shadow mode, then decide how much each agent does on its own.

How we start
Discovery and scoping
Integration beside your systems
Shadow mode
Controlled autonomy
Govern and improve