
Reva.AI is well positioned for this emerging market, with its IBAC (Intent and Behavior Based Access Control) offering a particularly innovative combination of intent drift detection, traceability, runtime enforcement, and gradual monitor-to-control adoption.
Summary
AI agents now call tools, APIs, MCP servers and other agents on their own. Static roles can't tell whether an action still serves what the user asked for. In its Rising Star report, KuppingerCole looks at how Reva.AI closes that gap with Intent & Behavior-Based Access Control (IBAC). IBAC checks every agent action against the agent's identity, the original request, expected behavior and policy at the moment the action runs. The report covers the market shift, Reva.AI's platform, its strengths and challenges, and where AI agent authorization is heading.
Key Highlights
- Innovation: 5/5, Market Fit: 4/5
- Every agent action is evaluated at runtime, including calls to tools, APIs, models, data sources, or other agents.
- Each action is allowed, denied, conditionally allowed, or escalated to a human using intent-drift detection alongside RBAC, ABAC, and ReBAC.
- Teams can start in monitor mode and transition to enforcement when ready.
- Agent decisions are fully traceable for investigation and auditing.
- Covers autonomous agents, enterprise copilots, and coding agents.


