Three loops.
One place it asks you.
The menu above is ordered by when you get value — connect, see, govern, prove. This page is the other question: how it all hangs together. It is not fifteen modules. It is three loops that answer three different questions, a gate between two of them, and exactly one surface where any of them asks a human for something.
The model
Three loops, and they are not the same kind of thing.
Two of them run on machine time — sweeps and reconciliation runs. The middle one runs at human pace: a role is proposed, argued over, and lives for years. That difference in kind is why folding it into either of the others fails.
🔍 The data loop
Is what we know good enough to act on?
Read what is actually there. Work out whose an account is and what kind of thing it is. Resolve who answers for it. Then name what is still too thin to act on — and fixing that changes what is observed, so the loop turns again.
📚 The model loop
What exists to be governed — and does it still deserve to?
The catalogue the access loop reasons in: applications, entitlements and roles. Something is proposed, shaped, formalised — and eventually retired on a date, with its holders migrated rather than stranded.
🔐 The access loop
Who should have what — and does it still hold?
What access should be, compared against what the systems actually show, with the reason stored at the moment it was computed. Then the approvals, reviews and changes that close the difference — and access is written because the two diverged, never because an event fired.
The gate
The data loop decides what the rest may claim.
Most of this category treats data quality as an onboarding chore you finish before governance starts. Here it is a governed loop of its own that never stops — and it holds a veto. Three refusals, each one a real code path rather than a principle.
A system we cannot read activity from produces no dormancy findings. An empty last-used date there means untracked — it is not evidence of anything.
A review that reaches nobody is reported as a gap, not as a review that was scheduled and therefore counted. Covered requires a reviewer who exists.
A compliance control with nothing to measure says so and is left out of the score, instead of being rounded to 0% because nothing was found, or 100% because nothing was found wrong.
Each of these was a live defect here before it was an invariant, and each one now has a test holding it in place. That is the honest version of the claim: not that we designed it perfectly — that when it drifted, we noticed, fixed it, and pinned it.
One inbox
Deciding happens in one place.
Every decision either loop needs from a person converges on one surface: approvals, certifications, reconciliation drift, detector findings. Each item says which loop asked and why, and a decision re-enters the loop it came from.
The workbenches around it are for oversight — they show you what is happening, they do not ask. And the badge in the navigation, the posture pill and the approvals chip all read the same number, so the three of them cannot tell you different things about how much is waiting — and once a week a bot walks every screen as six different people to check the ones we cannot count.
And a question that has already been answered closes itself. When the thing a decision was about stops existing — the owner changed, the drift healed, the proposal was settled elsewhere — the item is superseded with the reason on the trail, instead of waiting for someone to notice it is stale.
⚡ The deliberate exception
Just-in-time elevation and break-glass do not queue. They are imperative, immediate and time-boxed, and they go straight to the target without waiting on a loop — which is also where evidence matters most, so a session carries a snapshot that survives the objects it referenced being deleted.
And who may skip the queue is written down in advance: a person or a group, for which right, for how long, until when. Inside that row there is no chain to walk. Outside it, a refusal that names which of the three limits you hit. And the person named in that row can see the door: eligibility is shown to whoever holds a live row, and to nobody else.
The same model, in time
What the first week actually looks like.
“From nothing to governance in a day” is not a second model. It is a path through the three loops — which is why nothing you do in the first hour has to be unlearned later.
Colour follows the loop: data model access all three
The source of people first, then a system holding accounts — that order matters, because correlation needs somebody to attach an account to. Then the estate is visible, and nothing has been changed.
Accounts have owners and kinds, entitlements have classifications, and the first gaps surface as work rather than as a report nobody acts on. The first afternoon of governance ships as starter packs — birthright, JML, access review, SoD. They install inert: everything is there to read and edit, nothing grants or spawns until you switch it on.
Mining proposes roles from the access people actually hold — not from an org chart. The first is shaped, owned and formalised.
The access loop turns on data the gate now allows. Policies say what should be true; reconciliation says where reality differs, and why.
Provisioning is gated behind manual batch approval by default, per system. The gate comes off when the model has earned it.
All three loops run, and all three ask in one place. It is the same map, still turning.