Self-service requests with multi-step approval chains. Role mining that proposes opportunities โ "12 people in Finance share this access, formalize it" โ instead of algorithm metrics. Visual policy authoring with live preview.
What's inside
Everything that decides who-gets-what lives here. From the employee requesting access to the manager approving it, the security gate catching an SoD conflict, and the role mining engine proposing the pattern they all share โ same data model, same audit chain.
Approvers see only what they're responsible for. Each request shows the full chain โ who already approved, who's next, why the SoD check passed or flagged. Decision metadata is captured for the audit chain.
Operators see every in-flight request with its current step, quorum status, time-to-deadline, and routing rationale. Filter by approver role, target system, or rule that matched. Re-route stuck requests without breaking the audit trail.
Manager โ Security team (any-1-of) โ Resource owner. Quorum types: all, any, n-of-m. Conditions evaluated server-side with the shared filter DSL. Stop-on-first-match priority ordering so rules don't cascade unpredictably.
Access-grant policies that say "everyone in Finance gets app X, role Y". They evaluate continuously โ when someone joins Finance, their access updates automatically. When they leave Finance, the policy revokes it. No manual maintenance.
Visual builder walks admins through condition selection, target resources, and approval routing. Live preview shows who'd be affected before you save. The shared filter DSL underneath is audit-friendly and version-controlled.
Mining surfaces proposals in plain language: "40 people in 'RapidValue NV' share this access. Formalize as a role โ reduces 16 ungoverned grants." Confidence + impact + cohort size displayed up front. One-click formalize.
One taxonomy for all role types. Business roles bundle entitlements for a function ("Finance analyst"). Application roles wrap target-side groups. Each role has its own re-cert cadence, membership model, and ownership.
SoD checks run before grants are submitted (preflight) and on a schedule across existing access (continuous). Toxic combinations are blocked or routed to compensating control. The conflict surface shows you who has what conflicting pairs and why.
When someone changes department or job title, transfer rules govern what stays, what gets revoked, what gets granted, and what fires a smart-cert review. The new manager confirms; the old access doesn't silently linger.
Entitlements imported from target systems become first-class objects with owner, description, risk rating, and review cadence. Group them into business-meaningful roles or expose them in the self-service catalog for direct requests.
Why governance matters
Average mid-market company over-licenses by 18% because nobody owns the question "does this person still need this?". Role mining + continuous certs reclaim those seats automatically.
Approving "Bank approver" + "Payment requester" on the same identity is a finding waiting to happen. SoD preflight blocks it at request time โ not in next quarter's audit.
Self-service catalog + auto-grant policies cover the common cases. Helpdesk only sees exceptions. Approvers spend less time stamping predictable requests and more time on real decisions.
"12 people in Finance share this access" beats "coverage 87%". Mining output is something a director understands without a training course โ and acts on with a single click.
Connect a target. Run mining. See real opportunities surfaced in business language โ typically 8โ15 high-confidence proposals in the first hour.
Book a POC demo โ