EU-native Identity Governance & Administration · built in BelgiumEU-native IGA · built in BelgiumCustomer-first · grounded in the running product

Blog

What accountants already know about access

Serge Kerremans, founder · 7 October 2026 · 5 min read

Ask an accountant what happens to a payment without a receipt. It goes back to whoever booked it. Nobody finds that strange. It is simply how a company keeps its money in order.

Now ask who approved the Salesforce administrator rights of someone who left the company in June. In many organisations nobody can answer that. The access was granted on a ticket, the ticket was closed, and the account is still active.

Four habits that keep the books in order

  1. Every booking has a voucher. A receipt, an invoice or a signed claim. Without one, the booking does not go in.
  2. The books are matched against the bank. Someone puts what the books say next to the bank statement, and every difference gets an explanation.
  3. The person who books does not approve the payment. Nobody can create a supplier and pay it on their own.
  4. At year end there is a file for the auditor. It covers a fixed period, and the auditor can follow every number back to a document.

None of this is new. In finance it is so normal that nobody calls it a control any more.

Identity governance borrowed the words

Reconciliation, segregation of duties and audit all come from accounting. The habits did not always come along. Access goes out on a ticket. Nobody compares what the systems hold with what HR says. And when the auditor asks, someone spends two weeks building a spreadsheet by hand.

We think identity governance should work the way the books do. So RapidValue keeps the same four documents for access. They are views on one identity model, which means they cannot drift apart.

1The statement

A connector reads what each system really holds: accounts, groups, roles, and the fields it can map. It starts read-only. You switch writing on per system, when you trust what you see.

Statement · Entra IDread 06:00

Accounts
412
Groups and roles
96
Fields mapped
14 of 14
Writing
off until enabled
Illustration · fictional demo data

2The reconciliation

HR says who works here and in which job. Your policies say what that job should have. RapidValue puts both next to the statement and lists every difference with its reason: a leaver who is still active, an account without an owner, or access nobody has used for months on a system that reports usage. The comparison runs every day, and again for one person after each HR import.

Reconciliation · HR31 Aug

Jan Peeters
left · still active
svc-backup-02
no owner
Tom Lambert
unused 120 days
398 others
match
Illustration · fictional demo data

3The voucher

Every change gets a reason and an approver who answers for it. Approval rules decide when a second person has to sign, for example for privileged access. The change is then written to the target system and confirmed there.

Voucher · request 22912 Sep

Access
Salesforce · Sales Ops
For
Lotte Claes
Reason
moves to sales

J. WoutersApplication ownerA. MaesIAM team

Confirmed on target · 2 Sep 10:14

Illustration · fictional demo data

4The closing file

An audit pack covers a period you choose and cites the framework it serves, such as ISO 27001, NIS2 or SOX. It is signed and carries its own verifier, so your auditor can check it without us.

Closing file · Q31 Jul – 30 Sep

Decisions
1,190
With reason and approver
1,190
Open differences
4, listed

Signed · verifiable without RapidValue

Illustration · fictional demo data

Where the comparison stops

There is no bank. In accounting the bank statement is the truth. For access every system has its own version, and HR is often late or incomplete. That is why you decide per field which source leads, and why RapidValue says so when a system does not report something.

Access changes faster than money. A finance team closes the month. Access changes every day, so the matching has to run every day too.

A missing approval does not show on a balance. A wrong number in the books eventually shows up somewhere. Too much access usually stays invisible until someone misuses it. So each difference goes to a person with a name as soon as it is found, instead of waiting for the next audit.