Provisionierung
Automatisiertes On- & Off-Boarding
Zero-Touch-Provisioning für alle Identitäten, Lizenzen und Apps.

Den Status quo im IAM durchbrechen
9 Stunden
bei manueller Bereitstellung verschwendet
2 Tage
durchschnittliche Wartezeit bei Zugriffsanfragen
30%
savings by downgrading enterprise plans that you only took to access certain APIs.
How does it work?
Corma’s clicker agent is a Chrome-based automation tool designed to interact with web applications in a structured, secure, and reliable way. It operates by leveraging a dedicated Chrome browser environment, which provides the agent with a machine-readable view of the webpage. This includes the full HTML structure, displayed text, clickable elements, form fields, and the visibility or state of each element. Unlike coordinate-based bots, this approach ensures robustness by allowing the agent to interpret the page accurately and make informed decisions about the next steps.
The agent executes tasks through a step-by-step process:
- Interpret the Page: It analyzes the elements on the page and understands their purpose and the actions they correspond to.
- Decide the Next Step: Based on the task (e.g., logging in, navigating to settings, or disabling an account), the agent determines the sequence of actions required.
- Execute Actions: It performs real Chrome actions such as clicking, typing, scrolling, navigating, or waiting for elements to load.
- Validate the Result: After each action, the agent re-reads the updated page structure to confirm success before proceeding to the next step.
Security and compliance are central to the agent’s design. Each automation run takes place in an isolated Chrome session, ensuring that the agent cannot access anything outside its assigned browser instance, including local files, machine data, or external systems. Credentials are securely managed, sourced directly from the client’s vault, and never stored on Corma’s platform.
Transparency is maintained through comprehensive logging and auditability. For every automation run, Corma provides a full video replay of the browser session, step-by-step logs, and success/failure indicators, ensuring complete visibility into the agent’s activity. Currently, the system is cloud-hosted on AWS, with potential future consideration for on-premise deployment based on client needs.
Bereitstellung in einem Klick
Individuell anpassbare Workflows für Bereitstellung und Deprovisionierung ermöglichen eine schnelle Entfernung von Zugriffen und gewährleisten Sicherheit sowie Effizienz während des gesamten Mitarbeiterlebenszyklus.
Connect any app, really
Sure, we integrate with Notion. But what about your weird niche industry tool that literally nobody else uses? Well, our custom agents can be trained on any app as long it has an interface and settings. Train the agents in a few minutes and get going.

Individuell anpassbare Workflows in Slack und Teams
IAM wurde gerade durch die automatisierte Benutzerbereitstellung über Slack einfacher. Verkürzen Sie die Zeit bis zur Problemlösung, indem Sie es Mitarbeitern ermöglichen, Genehmigern und Administratoren innerhalb von Slack-Threads Nachrichten zu senden.
Human in the loop
Vibe coding comes with side effects. Keep the human in the loop if smart admin approval systems with a clear audit trail so you know why something is happening before it happens.

Security Guardrails
Bieten Sie Ihren Mitarbeitern ein Erlebnis wie bei Consumer-Apps, indem Sie den App-Self-Service über den App Store Ihres Unternehmens bewerben.strict security guardrails: it runs in an isolated Chrome browser session, preventing access to external systems, local files, or client data beyond the assigned webpage, with no persistent storage except for approved logs. Credentials are sourced exclusively from the client’s secure vault, never stored on Corma’s platform.





Der neue Standard im Zugangsmanagement
Bereit, Ihre IT-Governance zu revolutionieren?




Wozu brauche ich überhaupt KI-Agenten?
Wenn ein Mitarbeiter eintritt, sollte sein Zugang sofort verfügbar sein. Wenn er ausscheidet, sollte er genauso schnell entzogen werden. Dafür gibt es APIs und Standards (man denke an SCIM und SAML). Und doch sperren viele Anbieter die Lifecycle-Automatisierung hinter Enterprise-Paywalls. Sie verlangen mehr für die Entziehung des Zugangs. Sie vermarkten Sicherheit als Feature. Manchmal aber existieren APIs auch einfach nicht, zum Beispiel für neuere oder Nischen-Branchen-Tools. In diesem Fall ist browserbasierte Agenten-Automatisierung ein effektiver Workaround, um Ihre Apps zu verbinden.
Was ist KI-Agenten-Governance?
KI-Agenten-Governance ist die Gesamtheit der Kontrollen, die steuern, worauf KI-Agenten in Ihrer Umgebung zugreifen und was sie dort tun können. Sie behandelt jeden Agenten als nicht-menschliche Identität und wendet dabei das Prinzip der geringsten Rechte (Least Privilege), Zugriffsüberprüfungen und Audit-Trails an, um Risiken zu mindern.
Was ist KI-Agenten-Automatisierung?
KI-Agenten-Automatisierung ist die Praxis der Verwaltung und Steuerung von KI-Agenten, den autonomen Software-Identitäten, die Aufgaben in Ihren Systemen ausführen. Sie umfasst die Erkennung von Agenten, die Kontrolle ihres Zugriffs und die Durchsetzung derselben Sicherheitsrichtlinien, die auch für menschliche Benutzer gelten.
Wie verwaltet Corma den Zugriff von KI-Agenten?
Um zuverlässig mit Webanwendungen zu interagieren, nutzt der Agent eine sichere, isolierte Chrome-Browserumgebung. Alle Anmeldeinformationen stammen aus dem sicheren Tresor des Kunden (z. B. 1Password, Bitwarden). Wir speichern keine Anmeldeinformationen auf unserer Plattform. Je nach Konfiguration des Kunden ist eine direkte Integration mit dem Secret Manager möglich. Die Zwei-Faktor-Authentifizierung (2FA) wird für verschiedene Integrationen unterstützt. Jeder Automatisierungslauf wird in einer dedizierten, isolierten Chrome-Sitzung.




