โš–๏ธ Governance

Access decisions in business language.

Self-service requests with multi-step approval chains. Role mining that proposes opportunities โ€” "12 people in Finance share this access, formalize it" โ€” instead of algorithm metrics. Visual policy authoring with live preview.

What's inside

Approvals, role mining, SoD โ€” one unified flow.

Everything that decides who-gets-what lives here. From the employee requesting access to the manager approving it, the security gate catching an SoD conflict, and the role mining engine proposing the pattern they all share โ€” same data model, same audit chain.

Self-service access requests
Approvals queue

My requests, requests for me, all-tenant โ€” one queue

Approvers see only what they're responsible for. Each request shows the full chain โ€” who already approved, who's next, why the SoD check passed or flagged. Decision metadata is captured for the audit chain.

Access requests
Active approvals

Visual approval-chain tracking

Operators see every in-flight request with its current step, quorum status, time-to-deadline, and routing rationale. Filter by approver role, target system, or rule that matched. Re-route stuck requests without breaking the audit trail.

Active approvals
Approval rules & policies
Approval rules

Multi-step chains with quorum semantics

Manager โ†’ Security team (any-1-of) โ†’ Resource owner. Quorum types: all, any, n-of-m. Conditions evaluated server-side with the shared filter DSL. Stop-on-first-match priority ordering so rules don't cascade unpredictably.

Approval rules
Policies

Auto-grant policies + birthright access

Access-grant policies that say "everyone in Finance gets app X, role Y". They evaluate continuously โ€” when someone joins Finance, their access updates automatically. When they leave Finance, the policy revokes it. No manual maintenance.

Policies
Policy wizard

Guided policy authoring โ€” no DSL knowledge required

Visual builder walks admins through condition selection, target resources, and approval routing. Live preview shows who'd be affected before you save. The shared filter DSL underneath is audit-friendly and version-controlled.

Policy wizard
Business role mining
Role mining proposals

Opportunities, not algorithm metrics

Mining surfaces proposals in plain language: "40 people in 'RapidValue NV' share this access. Formalize as a role โ€” reduces 16 ungoverned grants." Confidence + impact + cohort size displayed up front. One-click formalize.

Role mining
Roles catalog

Business roles + application roles + birthright

One taxonomy for all role types. Business roles bundle entitlements for a function ("Finance analyst"). Application roles wrap target-side groups. Each role has its own re-cert cadence, membership model, and ownership.

Roles
SoD & transfer rules
SoD rules

Separation of duties โ€” preflight + continuous

SoD checks run before grants are submitted (preflight) and on a schedule across existing access (continuous). Toxic combinations are blocked or routed to compensating control. The conflict surface shows you who has what conflicting pairs and why.

SoD rules
Transfer rules

Department change โ†’ access recalculated

When someone changes department or job title, transfer rules govern what stays, what gets revoked, what gets granted, and what fires a smart-cert review. The new manager confirms; the old access doesn't silently linger.

Transfer rules
Entitlement catalog
Entitlements

Every permission, every system, owner-attributed

Entitlements imported from target systems become first-class objects with owner, description, risk rating, and review cadence. Group them into business-meaningful roles or expose them in the self-service catalog for direct requests.

Entitlements

Why governance matters

The cost of access drift.

๐Ÿ’ธ โ‚ฌ40K/yr in unused SaaS seats

Average mid-market company over-licenses by 18% because nobody owns the question "does this person still need this?". Role mining + continuous certs reclaim those seats automatically.

โš–๏ธ SoD violations caught preflight

Approving "Bank approver" + "Payment requester" on the same identity is a finding waiting to happen. SoD preflight blocks it at request time โ€” not in next quarter's audit.

๐ŸŽฏ 70% fewer access tickets

Self-service catalog + auto-grant policies cover the common cases. Helpdesk only sees exceptions. Approvers spend less time stamping predictable requests and more time on real decisions.

๐Ÿ“Š Business-readable mining

"12 people in Finance share this access" beats "coverage 87%". Mining output is something a director understands without a training course โ€” and acts on with a single click.

Run mining against your own access patterns.

Connect a target. Run mining. See real opportunities surfaced in business language โ€” typically 8โ€“15 high-confidence proposals in the first hour.

Book a POC demo โ†’
EU-hosted ยท No installation footprint ยท Walks away cleanly if you don't convert