Six chapters.
Zero concept art.
Every image below is an unretouched capture from a running tenant with fictional demo people — click any thumbnail to put that screen on stage, click the screen to zoom. What you see here is what you log into on day one.
Chapter 1 · Onboard
Connected and syncing before the coffee's cold.
Every connector starts in a guided wizard: pick the vendor, drop in credentials, watch the schema auto-discover, confirm the suggested mappings against live records from your own system.
- 17 connectors: vendor templates from Entra ID and Google Workspace to AFAS and TOPdesk + generic REST, SCIM 2.0, LDAP, SQL and SFTP-CSV for everything else
- Live endpoint test at every step — you never configure blind
- Writes stay batch-gated for your approval until you take the training wheels off
Chapter 2 · See
Finally answer "who has access to what — and should they?"
One sync in, the platform scores every identity, flags what's wrong, and puts the findings in a single advisor inbox — prioritized, with the fix one click away.
- Risk score per identity with a readable breakdown — not a black box
- Orphans, dormant grants, unowned service accounts, SoD conflicts, peer outliers
- Executive numbers and per-person drill-down from the same live model
Chapter 3 · Govern
Governance in business language, not consultant dialect.
Role mining turns access patterns into plain-language proposals you can formalize in one click. Policies are built visually, with the blast radius simulated live before you save. The consulting workshop is the product.
- "12 people in Finance share this access" — not cluster IDs and coverage %
- Live simulation: exactly who a policy touches, named, before it goes live
- Self-service requests routed through approval chains you design visually
Halfway. Rather see this on your own data?
A 30-minute kickoff gets your HR feed and one system connected — today.
Chapter 4 · Prove
Audit-ready every day — not the week before.
Reconciliation compares expected against actual access on every run and records a per-grant reason. Reviews run continuously or as campaigns, and audit packs generate from live data on an immutable, hash-chained trail.
- Every difference explained: "expected via policy X" / "not expected — flagged"
- Reviews grouped per account — where shared and privileged risk actually lives
- SOX · ISO 27001 · HIPAA · GDPR packs, one click, from the live model
Chapter 5 · Operate
Joiners, movers, leavers — handled, with receipts.
Your HR source drives the lifecycle: joiners get birthright access, movers get reviewed, leavers get cleaned up. Every write is visible, batchable, and capped by safety limits; failures land in a triage queue instead of a void.
- Transfers show the actual field changes — and the review they triggered
- Managers act on their team's access in business terms: keep, flag, revoke
- Blast-radius caps: a runaway policy stops at the threshold, not at your AD
Where the work converges
One inbox does the work. One advisor does the thinking.
Every review, approval, exception and fix lands in a single inbox — and a platform-wide advisor watches the whole model, turning what it detects into decisions you can take on the spot.
The inbox is the spine
Certifications, approvals, failed provisioning jobs, lifecycle exceptions, advisor findings — governance sources collapse into one queue, split into three lanes: decide, do and review. Each person sees only their own — reviewers get reviews, the helpdesk gets the do-queue, auditors read-only. High-volume findings roll up by area, so you triage a handful of cards instead of thousands of rows.
The advisor is the brain
Detectors continuously scan for what's wrong or improvable — toxic combinations, dormant access, unowned service accounts, config gaps. Each finding arrives explained and routed to the named people who own it — notified in-app and by email, not dumped on one admin. It lives in your posture view, ranked so the signal surfaces first, with the fix one click away.
Chapter 6 · Non-human identities
Service accounts and AI agents — finally owned.
Non-human identities get the same governance as people: a typed identity, a named owner, a risk score, dormancy detection tuned to machine behaviour, and a yearly ownership attestation seeded out of the box.
- Every service account, bot and AI agent with owner, risk and last-used signal
- Unowned NHIs are a finding, not a fact of life
- Dormancy thresholds tuned for machines — cron jobs aren't leavers
Everything in the box
One platform, the full IGA discipline.
One platform, everything included — every capability below ships in the product, is shown in the chapters above, and links to its own platform page.