$ every product image on this site is an unretouched screenshot of the running platform — demo tenant, fictional people, captured live
🧭 How it works

Three loops.
One place it asks you.

The menu above is ordered by when you get value — connect, see, govern, prove. This page is the other question: how it all hangs together. It is not fifteen modules. It is three loops that answer three different questions, a gate between two of them, and exactly one surface where any of them asks a human for something.

The model

Three loops, and they are not the same kind of thing.

Two of them run on machine time — sweeps and reconciliation runs. The middle one runs at human pace: a role is proposed, argued over, and lives for years. That difference in kind is why folding it into either of the others fails.

what the rest may claim data loop good enough to act on? turns continuously the gate model loop what exists to be governed? runs at human pace access loop who should have what? turns continuously one inbox every loop asks here — and only here
Turns continuously

🔍 The data loop

Is what we know good enough to act on?

Read what is actually there. Work out whose an account is and what kind of thing it is. Resolve who answers for it. Then name what is still too thin to act on — and fixing that changes what is observed, so the loop turns again.

Runs at human pace

📚 The model loop

What exists to be governed — and does it still deserve to?

The catalogue the access loop reasons in: applications, entitlements and roles. Something is proposed, shaped, formalised — and eventually retired on a date, with its holders migrated rather than stranded.

Turns continuously

🔐 The access loop

Who should have what — and does it still hold?

What access should be, compared against what the systems actually show, with the reason stored at the moment it was computed. Then the approvals, reviews and changes that close the difference — and access is written because the two diverged, never because an event fired.

The gate

The data loop decides what the rest may claim.

Most of this category treats data quality as an onboarding chore you finish before governance starts. Here it is a governed loop of its own that never stops — and it holds a veto. Three refusals, each one a real code path rather than a principle.

what we observed the gate a finding · covered · measured untracked · a gap · not measurable rounded to 0% or 100% never
Not observed
is not a finding.

A system we cannot read activity from produces no dormancy findings. An empty last-used date there means untracked — it is not evidence of anything.

No owner
is not covered.

A review that reaches nobody is reported as a gap, not as a review that was scheduled and therefore counted. Covered requires a reviewer who exists.

No denominator
is not measurable.

A compliance control with nothing to measure says so and is left out of the score, instead of being rounded to 0% because nothing was found, or 100% because nothing was found wrong.

Each of these was a live defect here before it was an invariant, and each one now has a test holding it in place. That is the honest version of the claim: not that we designed it perfectly — that when it drifted, we noticed, fixed it, and pinned it.

One inbox

Deciding happens in one place.

Every decision either loop needs from a person converges on one surface: approvals, certifications, reconciliation drift, detector findings. Each item says which loop asked and why, and a decision re-enters the loop it came from.

The workbenches around it are for oversight — they show you what is happening, they do not ask. And the badge in the navigation, the posture pill and the approvals chip all read the same number, so the three of them cannot tell you different things about how much is waiting — and once a week a bot walks every screen as six different people to check the ones we cannot count.

And a question that has already been answered closes itself. When the thing a decision was about stops existing — the owner changed, the drift healed, the proposal was settled elsewhere — the item is superseded with the reason on the trail, instead of waiting for someone to notice it is stale.

data model access one inbox says which loop asked the decision re-enters its own loop

The deliberate exception

Just-in-time elevation and break-glass do not queue. They are imperative, immediate and time-boxed, and they go straight to the target without waiting on a loop — which is also where evidence matters most, so a session carries a snapshot that survives the objects it referenced being deleted.

And who may skip the queue is written down in advance: a person or a group, for which right, for how long, until when. Inside that row there is no chain to walk. Outside it, a refusal that names which of the three limits you hit. And the person named in that row can see the door: eligibility is shown to whoever holds a live row, and to nobody else.

Privileged & emergency access →

The same model, in time

What the first week actually looks like.

“From nothing to governance in a day” is not a second model. It is a path through the three loops — which is why nothing you do in the first hour has to be unlearned later.

Colour follows the loop: data   model   access   all three

Hour one

The source of people first, then a system holding accounts — that order matters, because correlation needs somebody to attach an account to. Then the estate is visible, and nothing has been changed.

Day one

Accounts have owners and kinds, entitlements have classifications, and the first gaps surface as work rather than as a report nobody acts on. The first afternoon of governance ships as starter packs — birthright, JML, access review, SoD. They install inert: everything is there to read and edit, nothing grants or spawns until you switch it on.

The same week

Mining proposes roles from the access people actually hold — not from an org chart. The first is shaped, owned and formalised.

Week one

The access loop turns on data the gate now allows. Policies say what should be true; reconciliation says where reality differs, and why.

When you are ready

Provisioning is gated behind manual batch approval by default, per system. The gate comes off when the model has earned it.

Continuously

All three loops run, and all three ask in one place. It is the same map, still turning.