Use Cases

Where a proof is worth more than a log

Use Case 01, AI Agents & Autonomous Systems

The agent's token is valid. That is exactly the problem.

An agent acting on an employee's behalf holds legitimate credentials. Nothing is stolen, nothing malfunctions, and every check passes because every check is supposed to pass. In August 2025 attackers used stolen OAuth tokens from a chat integration to reach more than 700 organisations' Salesforce environments, including major security vendors. No vulnerability was exploited. Multi-factor authentication never applied, because a token is standing authorization: it authenticates a session, not a decision. The agent's token is valid. That is the problem.

Human Authorized Egress
Agents run at full speed on everything internal. Only actions that leave the building, sending outreach, moving funds, exporting data, granting access, require a named human's proof before they execute.
Asynchronous Approval
The consequential action parks rather than blocking the agent. A human clears it when they are available. Autonomy is preserved; accountability arrives.
Attribution After the Fact
Every authorized action carries a signed artifact naming the person who approved it. When an incident review asks who authorized this, there is an answer that does not depend on log inference.

Regulatory Fit: Frameworks governing autonomous systems increasingly ask for demonstrable human oversight rather than documented intent. The EU AI Act's Article 14 requirement is the clearest example. Most current approaches evidence that a step occurred rather than that a specific human decided. Consult qualified counsel for compliance determination.

Use Case 02, MCP & Agent Tooling

A tool call that reads a calendar and one that wires money look identical.

Agent frameworks invoke capabilities through tool interfaces such as the Model Context Protocol. The protocol carries no notion of consequence: a call that lists files and a call that deletes a production database are structurally the same request. Authorization, where it exists, is a scope granted once at connection time and reused indefinitely. CogniKey inserts a per invocation human authorization step in front of the small number of tools whose effects cannot be undone.

Per Invocation, Not Per Connection
A granted scope authorizes a category of action forever. A proof authorizes one invocation, once, and cannot be replayed against a second.
Consequence Aware Gating
Risk is determined server side by the tool being invoked, never by a label supplied in the request. An attacker who controls the client cannot mark a destructive call as harmless.
Framework Agnostic
Sits in front of the tool rather than inside the agent. Applies wherever the invocation is made from.
Use Case 03, Privileged & Enterprise Actions

Your session log proves credentials were used. It does not prove a human was there.

A stolen credential, a hijacked session, or an AI agent acting under a valid token, to every existing system, all three are indistinguishable from the employee who was supposed to be there. Every consequential enterprise action deserves a cryptographic proof that a specific enrolled human consciously authorized it, not just that credentials were presented.

Wire Transfers
Any transfer above your threshold requires a human authorization proof. Action bound: a proof for $10,000 cannot authorize $100,000.
Privileged Access and Admin Operations
Production access, privilege escalation, access grants, and configuration changes. Admin credentials are the most shared and least attributable in any organisation. A proof names the individual, not the role.
Bulk Data Export
Any export above your configured record threshold requires a human authorization proof. The proof is action bound to the export scope, timestamped, and stored in your audit log.

Regulatory Fit: SOX requires documented internal controls over financial and administrative actions. CogniKey strengthens that evidentiary chain with a signed, timestamped proof of conscious human authorization, additive to existing controls. Consult qualified counsel for compliance determination.

Use Case 04, Healthcare

Verified access. Documented consent. Protected records.

Healthcare data is among the most regulated and most breached. A stolen password or shared credential looks identical to a legitimate login, until something goes wrong. CogniKey adds a second factor that proves a specific enrolled clinician was consciously present at the moment of access, not just that valid credentials were used. The result is a signed, timestamped proof artifact for every sensitive action: login, consent capture, and record access.

Second Factor at the Point of Care
Strengthen EHR and portal login with a factor that cannot be stolen, shared, or phished. No hardware token required. The credential exists only in the enrolled clinician's memory and is verified in seconds.
Patient Consent, Cryptographically Bound
Capture patient consent with a signed proof that a named, credentialed clinician was consciously present and authorized the consent event. Timestamped, identity bound, and independently verifiable for audit or legal review.
Medical Record Access, Verified
Every access to a protected health record generates a cryptographic proof identifying exactly which clinician authorized it, for which record, and when. Designed to support HIPAA audit requirements and reduce unauthorized access exposure.

Regulatory Fit: HIPAA requires audit controls for PHI access. Most healthcare organizations satisfy these today with standard access logs and session based authentication. CogniKey is designed to raise that evidentiary bar: a signed, timestamped proof that a specific credentialed clinician consciously authorized a specific action. Consult qualified counsel for compliance determination.

Use Case 05, Fintech & Banking

Regulated financial actions demand more than a valid session token.

Account takeover, authorized push payment fraud, and stolen credentials all produce a clean looking session log. PSD2 Strong Customer Authentication requires two independent factors and dynamic linking of a payment to its amount and payee. None of these frameworks currently distinguish between an authenticated session and a conscious human decision, which is precisely the gap that becomes material when an AI agent or a compromised session executes a transaction with valid credentials.

Step Up for High Value Actions
Wire transfers, beneficiary changes, and account recovery above your configurable threshold require a human authorization proof before execution. Action bound: a proof for one transfer cannot authorize another.
Deepfake Fraud Prevention
No biometric signal exists to synthesize. Where an attacker impersonates an executive by voice or video, the authorization still has to come from a specific enrolled human reproducing something no recording contains.
Automated and AI Driven Transactions
When agents or automated systems execute trades, rebalance portfolios, or move funds above policy thresholds, they must produce a human authorization proof first. Signed, timestamped, and stored in your audit log.

Regulatory Fit: PSD2 SCA requires two independent authentication factors and dynamic linking of a payment to its amount and payee. CogniKey produces a signed, action bound proof that a specific identified human consciously authorized the transaction. Consult qualified legal counsel for compliance determination.

Use Case 06, Legal & Compliance

A signature proves a credential was used. A CogniKey proof proves who authorized it.

eIDAS, the ESIGN Act, and legal evidentiary standards increasingly require proof that a specific identified human consciously authorized a legal act, not just that an authenticated session executed it. CogniKey provides a cryptographic proof that a named enrolled human was consciously present and authorized the specific legal action.

Contract Execution
Signing a contract, approving a purchase order, or committing to a vendor agreement each generates a signed proof artifact identifying the specific human who authorized it, bound to the exact document action.
Regulatory Filings
Submissions that are drafted and routed automatically require a human authorization proof before filing. Timestamped, identity bound, and non repudiable. Suitable for legal and regulatory review.
Board Resolutions and Attestations
Corporate governance actions, board approvals, officer attestations, and compliance certifications produce a cryptographic proof of conscious human authorization that satisfies audit and legal discovery requirements.

Regulatory Fit: eIDAS and the ESIGN Act recognize electronic signatures and authorizations where identity and intent can be demonstrated. CogniKey adds a stronger evidentiary layer for the signatory presence question: a signed, action bound proof that a named human was consciously present at the moment of authorization. Consult qualified counsel for compliance determination.

Use Case 07, EU AI Act Article 14

A Slack button click is not documented proof of oversight.

EU AI Act Article 14 requires high-risk AI systems to be designed so that natural persons can effectively oversee them. High-risk obligations under the Digital Omnibus package are deferred to December 2027 for standalone systems and August 2028 for AI embedded in regulated products. A session log proves credentials were used. A CogniKey proof provides evidence that a specific enrolled human consciously authorized the specific action.

Cryptographic Proof Artifact
Each authorized action produces a signed, action bound, timestamped proof artifact. Ed25519 signed. Independently verifiable. Stored in your audit log.
Extraterritorial Scope
Any AI system whose output touches EU users is in scope, regardless of where you are headquartered. The same logic that made GDPR apply to US companies applies here.
Regulator Ready
The proof answers the question a regulator will ask: which specific enrolled human authorized this, when, for what exact action, and can you prove they were consciously present?

Regulatory Fit: EU AI Act Article 14 requires documented human oversight of high risk AI actions. CogniKey produces stronger evidence: a signed, timestamped proof of conscious human authorization, intended to be more defensible under adversarial enforcement review than a conventional approval log. Consult qualified counsel for compliance determination.