Expected vs actual.
Per grant, with a reason.
The engine at the heart of the platform: every run compares what access should exist against what actually exists in your systems — and explains every difference.
Drift, explained
Every difference carries its explanation.
"Expected via policy X" — "found in target without an expected source" — "expected but no account to put it on". An identity is recomputed the moment a sync or a grant changes it, with a full tenant-wide run every day and whenever you press the button. Each grant's verdict is recorded as evidence, not just counted. A leaver's account gets disabled by the next reconciliation run: there is no event to miss and no ticket to chase — the run pulls the world toward the model, so a missed message costs you a run, not a gap.
- Per-grant reasons on every run — auditors get answers, not exports
- Eight drift kinds: unapproved, missing, attribute drift, orphan and disabled accounts, shadow access, cardinality conflicts, blocked provisioning
- Keep or remove, per item — Keep certifies the drift and writes nothing, Remove revokes. The planned writes, the risk delta and the evidence being recorded are listed before you click
- Per-connector drift policy: auto-fix, review, or keep
The control room
Writes you can watch, gate, and trust.
Provisioning runs in batches you can approve manually until you release the gate. Failures never disappear into a void — they land in a triage queue, grouped by cause and counted. One finding per system per failure class — timeout, auth, not-found-in-target, other — because the next move differs per class: a retry fixes a timeout and re-fails a not-found identically. The finding carries the size, whether it is growing, and a drill into exactly the rows it counted. The row tells you what is actually possible next: a config failure stays blocked until the config really changed, a target-side failure retries straight away, a policy-blocked write says so instead of pretending a retry would help.
- Batch approval per system (training wheels)
- Failed-jobs queue grouped by failure cause, with a fix-config deep-link
- Mass-revoke breaker: a run about to revoke more than a quarter of a system's access is aborted whole, before the first revoke — the fail-safe is keep, never remove. On by default
- Sync safety limits pause a connector when an import's change, deletion or creation share crosses its threshold — the bad import stops at us, not at your AD
- Releasing one is a decision with a name on it: you see every change it would make — searchable, all of them, not a 200-row sample — and it refuses to proceed without a written reason
See reconciliation running on your own data.
A 30-minute kickoff connects your HR feed and one system — working POC the same day.
Bring your HR feed plus one system you trust us to read — that is all the kickoff needs. No NDA, no second call with a sales engineer, no procurement form.