$ every product image on this site is an unretouched screenshot of the running platform — demo tenant, fictional people, captured live

Identity Governance & Administration · EU-native · Built in Belgium

Connect in the morning.See everything by lunch.Govern by Friday.

RapidValue is an Identity Governance & Administration (IGA) platform for the EU mid-market: who has access to what, whether they should, and the evidence to prove it — without the twelve-month implementation project. This page is the actual product, in the order you'll experience it.

No infrastructure to provision Credentials stay local with the tier-3 agent Walk-away clean if you don't convert
rapidvalue — day one

        
the day-one sequence · timings from the POC playbook · demo-tenant numbers

Three proofs

Demonstrated, not promised.

1 day
From first call to working POC — on your own HR feed and systems
15 min
SCIM, LDAP or AD connector live via the wizard
0
Connector secrets leaving your network in agent mode

$ watch the wizard do it, click by click → · why the classical playbook fails the mid-market → · where the incumbents are still ahead →

The shape of it

Access governance is a cycle, not a project.

Connect once. Everything after that keeps running on its own — until it genuinely needs a person to decide. The full mechanism is three loops and a gate; this is the shape of it in one picture.

CONNECT · ONCE Understand Model Decide Confirm RapidValue The loop runs on its own. You only see what needs you.

🔍 Understand

See what is really there — accounts, entitlements, owners, and the gaps nobody flagged. The Platform Advisor reads it continuously, no workshop required.

📚 Model

Mine roles, account rules, and applications from raw access — onboarded on purpose, never by accident.

📥 Decide

Every request, approval, certification, and SoD check — routed to one inbox, not fifteen tools.

🔁 Confirm

Act on the decision, then check it still holds — expected versus actual, with the reason stored.

See how the loop actually works →

The journey

What actually happens, day by day.

No sandbox, no slideware. This is the sequence we run in every POC — on your HR feed and your systems.

Connect a system.

Pick your vendor from the catalog — Entra ID, Workday, SuccessFactors, Salesforce, ServiceNow — or connect anything else over generic REST, SCIM 2.0 or LDAP. Drop in a token; the wizard auto-discovers the schema, suggests the field mappings and tests them as you go.

  • First sync in minutes — ≤ 15 for a typical system
  • Training wheels on by default: every write queues for your batch approval until you remove the gate, per system
  • Attribute selection decides, per field, what gets imported at all
all onboarding screens — catalog, mappings, account rules →

See your whole access reality.

The first sync already answers the question most organisations can't: who has access to what — and is that what you expected? Quick Scan runs every relevant detector against the fresh data and turns it into concrete actions.

  • Risk score per identity, with a readable breakdown — not a black box
  • Orphan accounts, dormant grants, unowned service accounts, SoD conflicts, peer outliers
  • Everything lands in one advisor inbox, prioritized
all posture screens — quick scan, identities, risk profiles →

Turn patterns into governance.

Role mining reads your actual access patterns and proposes roles in plain language — "12 people in Finance share this access" — not cluster IDs. App mining does the same on the application axis: it spots the App-… group families hiding in your directory and proposes each one as a real application. One click formalizes either into something governed.

  • 8 mining algorithms, deduplicated, output as business stories
  • App mining opens the app-onboarding wizard pre-filled — you review, you don't retype
  • Change a policy and the preview names the people: who starts matching, who stops, and what they’d actually get — before you save. Take enough away and it says so out loud, because reconciliation will pull it back on a clock without asking again
  • Requests route through approval chains you design visually — and show which account each right lands on before you submit
all governance screens — policy builder, requests, approvals →

Prove it, continuously.

Governance you can't evidence is governance you don't have. Every reconciliation run compares expected against actual access and records a per-grant reason. Reviews run continuously, as campaigns, or fire on an event — a transfer or a new grant spawns one now, not next quarter — and audit packs generate from live data instead of a quarterly evidence-gathering scramble.

  • Expected vs actual per grant: "expected via policy X" / "not expected — flagged"
  • Drift is decided per item — Keep it (certified, no write) or Remove it — never a blanket approve-all. And where forty items really are the same decision, bulk is one call with one authority path, not forty clicks
  • Audit trail is hash-chained and database-immutable — tampering is detectable
  • SOX · ISO 27001 · HIPAA · GDPR packs, one click, from live data
  • A report opens as a view, not as a file you order — the same saved filter drives the list you look at and the file you export, and the masking holds in both
  • An approver — and a reviewer: a certification round announces itself, and an overdue decision gets its nudge from a scheduled job. The person who asked hears the outcome too, including "your access is live" — sent when provisioning lands, not when a form was filled. And one standing lens says what has been waiting longest, on whom, across every kind of decision at once
all compliance screens — reconciliation, SoD, audit packs →
Connector wizard — the target's data model, verified on a live record
live tenant · connector wizard · model adopted, verified on a live record

Where your data lives

EU-hosted. EU-owned. Your choice where it runs.

The managed SaaS control plane runs in AWS Ireland (eu-west-1) — RapidValue is a Belgian company with no US parent. For on-premises systems or strict credential custody, the tier-3 agent runs in your VPC: connector credentials never cross the wire to our control plane. By architecture, not policy — and not a roadmap slide: this is the architecture running today.

YOUR NETWORK ⬢ tier-3 agent one Python file, readable 🔑 local vault secrets — encrypted, local only AD · LDAP · internal apps reached only from inside EU CONTROL PLANE AWS eu-west-1 · Belgian company governance model & policies dashboards · reviews · packs ⛓ immutable audit chain results tasks & config 🔑✕ secrets never cross outbound HTTPS :443 only — the agent dials out, nothing dials in

☁️ Managed EU SaaS

Fully managed in our EU AWS account — tenant-scoped isolation, automated backups, same-day POC. EU-sovereign operators (OVH / Scaleway), private cloud and on-premises on request.

🛡️ Tier-3 agent in your VPC

Outbound HTTPS only, no inbound ports, no VPN tunnel. Credentials encrypted at rest with a local master key. The agent is one readable Python file, plus the connector code the control plane serves it — signed, and code only, never secrets. Updates are pushed and signature-verified; if a host dies you re-point its connectors to a replacement agent.

🗝️ Bring your own vault

HashiCorp Vault, Azure Key Vault or AWS Secrets Manager as the secret backend — RapidValue stores references, your vault keeps the values. Or keep them agent-local: the tier-3 agent resolves the secret inside your network and it never leaves it.

The full trust & security page →

Start your POC

See your own access patterns this afternoon.

30-minute kickoff call. We bootstrap a POC tenant, you install the agent, we connect your first system together. By end of day you have real role-mining proposals and a risk-score baseline from your own environment.

What you get on the first call

POC tenant provisioned (~2 min, in front of you)
Tier-3 agent one-line install in your VPC
Your HR source connected — required; it's what makes the data meaningful
A first target system live (your AD or a SaaS app)
Risk-score baseline + Quick Scan output
Role-mining proposals from your data
Sample audit pack (SOX / ISO / HIPAA / GDPR)

The HR source is the must-have — without it the access data is meaningless. No NDA, no sales-engineer second call, no procurement form: just bring your HR feed plus one system you trust us to read.

We don't touch your systems — you install the agent on your side. Walk-away clean: kill the process, no decommissioning. Reach us at hello@rapidvalue.eu.