Survive the audit

Hand the auditor the campaign instead of a week of screenshots.

Govern, modern IGA

A closed review campaign with its decisions, its sign-off, each revocation result and the CSV the auditor receives
01Where it goes wrong

The auditor wants proof that every privileged account was reviewed. The last campaign lives in a spreadsheet somebody exported in March.

For the GRC lead who owns the evidence.

02What the industry reports

What the industry reports

  • 55%of permissions were classified safe and compliant in 2025, down from 70% the year beforeSonrai, cloud permissions analysis 2025
  • 28%of permissions are now ungoverned, up from 5%Sonrai, cloud permissions analysis 2025
  • 92%of identities holding sensitive permissions did not use them in 90 daysSonrai, enterprise cloud tenants
03What changes

What changes

Every decision carries its evidence

Last sign-in, how often the access is used, and a flag on anything unused for ninety days, on the row being decided. The reviewer is not guessing and neither are you.

A denial reaches the directory

Application access, group membership and directory roles come off per account once the review closes, and a failed revoke is reported per account.

The record is the audit trail

Every decision names who made it and when. Hand that over.

04What it covers

Everything this covers.

The offboarding policy as built: the directory trigger, who it covers, the workflow it runs and its last run
01Identity lifecycle
01

Identity lifecycle

  • The directory change drives joiner, mover and leaver
  • Birthright access by role and department when the account is created
  • Sessions, groups, app assignments, roles and OAuth grants stripped in one run
The offboarding policy as built: the directory trigger, who it covers, the workflow it runs and its last run
02

Access certification

  • Campaigns over tags, groups, applications or directory roles
  • Ordered reviewer stages with a fallback reviewer on each
  • Last sign-in and usage on the row being decided
  • Bulk-approve the obviously fine, spend the time on the rest
  • Recurrence with an end date or an occurrence cap
A review queue with last sign-in and usage beside every decision, and the evidence on the one being denied
03

Policy and role management

  • A policy binds a trigger and a population to one reusable workflow
  • Workflows versioned, with a snapshot of the version that ran
The workflow library, each workflow showing the kinds of step it runs, its task count and version
04

Audit evidence

  • A denial revokes application access, group membership and directory roles
  • A failed revoke reported per account
  • Sign-off recorded against a named person, with the date
  • Evidence exports as a CSV of every decision
Run history with one offboarding run opened step by step, including the step that failed and why
05What does the work

The parts of the product this uses.

Access reviewsReviewers decide with the evidence in front of them
Lifecycle automationAccess arrives on the hire date and ends on the last one
Identity associationsFive accounts across four systems resolve to one person
06On your own tenant

See it on your own tenant.

Book a demo

Connect your directory and see findings the same day.

The graph behind it