What accountants already know about access
Ask an accountant what happens to a payment without a receipt. It goes back to whoever booked it. Nobody finds that strange. It is simply how a company keeps its money in order.
Now ask who approved the Salesforce administrator rights of someone who left the company in June. In many organisations nobody can answer that. The access was granted on a ticket, the ticket was closed, and the account is still active.
Four habits that keep the books in order
- Every booking has a voucher. A receipt, an invoice or a signed claim. Without one, the booking does not go in.
- The books are matched against the bank. Someone puts what the books say next to the bank statement, and every difference gets an explanation.
- The person who books does not approve the payment. Nobody can create a supplier and pay it on their own.
- At year end there is a file for the auditor. It covers a fixed period, and the auditor can follow every number back to a document.
None of this is new. In finance it is so normal that nobody calls it a control any more.
Identity governance borrowed the words
Reconciliation, segregation of duties and audit all come from accounting. The habits did not always come along. Access goes out on a ticket. Nobody compares what the systems hold with what HR says. And when the auditor asks, someone spends two weeks building a spreadsheet by hand.
We think identity governance should work the way the books do. So RapidValue keeps the same four documents for access. They are views on one identity model, which means they cannot drift apart.
1The statement
A connector reads what each system really holds: accounts, groups, roles, and the fields it can map. It starts read-only. You switch writing on per system, when you trust what you see.
Statement · Entra IDread 06:00
- Accounts
- 412
- Groups and roles
- 96
- Fields mapped
- 14 of 14
- Writing
- off until enabled
2The reconciliation
HR says who works here and in which job. Your policies say what that job should have. RapidValue puts both next to the statement and lists every difference with its reason: a leaver who is still active, an account without an owner, or access nobody has used for months on a system that reports usage. The comparison runs every day, and again for one person after each HR import.
Reconciliation · HR31 Aug
- Jan Peeters
- left · still active
- svc-backup-02
- no owner
- Tom Lambert
- unused 120 days
- 398 others
- match
3The voucher
Every change gets a reason and an approver who answers for it. Approval rules decide when a second person has to sign, for example for privileged access. The change is then written to the target system and confirmed there.
Voucher · request 22912 Sep
- Access
- Salesforce · Sales Ops
- For
- Lotte Claes
- Reason
- moves to sales
J. WoutersApplication ownerA. MaesIAM team
Confirmed on target · 2 Sep 10:14
4The closing file
An audit pack covers a period you choose and cites the framework it serves, such as ISO 27001, NIS2 or SOX. It is signed and carries its own verifier, so your auditor can check it without us.
Closing file · Q31 Jul – 30 Sep
- Decisions
- 1,190
- With reason and approver
- 1,190
- Open differences
- 4, listed
Signed · verifiable without RapidValue
Where the comparison stops
There is no bank. In accounting the bank statement is the truth. For access every system has its own version, and HR is often late or incomplete. That is why you decide per field which source leads, and why RapidValue says so when a system does not report something.
Access changes faster than money. A finance team closes the month. Access changes every day, so the matching has to run every day too.
A missing approval does not show on a balance. A wrong number in the books eventually shows up somewhere. Too much access usually stays invisible until someone misuses it. So each difference goes to a person with a name as soon as it is found, instead of waiting for the next audit.