Skip to content
Solutions IT

One query, not eleven exports. With an approver on every row.

The access review spreadsheet has no approval column because nothing ever recorded one. Make each grant an Action and it does.

Explore the platform

The systems you already run, the objects your product declares, and the work your team gets back.

Okta
ServiceNow
Microsoft 365
Jira
Slack
Bijection
Person
Device
Access grant
Service
Licence
Ticket
Access review
Leaver revocation
Shadow SaaS
Incident context

These marks name the kinds of system a source declaration reaches — a picture of the ecosystem, not a fixed menu, and nothing here implies a partnership.

Less exporting. Reviews you can cite.

The eleven exports collapse

Identity, device and licence systems become linked objects, so the join happens once instead of in a sheet.

Grants carry their approver

Access changes through an Action, so who approved it and when is a field, not a mailbox search.

A record that outlives admins

Every grant and revocation is appended with its author and effects, so the answer outlives whoever left.

What teams build. On day one.

Four places this work turns into declared objects, governed reads, and reviewed changes.

Access review

The eleven CSVs become one Function. Every row names the system that reported the grant and the pull that captured it.

Leaver revocation

Offboarding becomes a Workflow: it revokes through declared Actions, waits, then rereads the sources to prove the licence and the token are gone.

Shadow SaaS

Set the identity provider against the expense feed in one Function. Apps nobody registered appear as a gap between sources, not a rumour.

Incident context

When a service degrades, one Function returns its owner, dependencies, recent changes and open tickets, instead of a scramble to find who owns it.

How it runs. End to end.

The same path every product takes: connect what exists, declare what it means, then publish the reads and the changes.

  1. 01

    Connect the systems you already run

    Identity provider, device management, ticketing and cloud inventory stay put, and nothing here writes into them. Each is pulled on a cadence you set, and every answer names its pull.

  2. 02

    Declare the things you manage

    Person, account, device, service and entitlement, with the links between them, modelled once in reviewed source instead of once per spreadsheet.

  3. 03

    Make every change an Action

    Grant, revoke, reassign and decommission become named Actions with declared effects. The consequential ones park until a second person approves exactly what they will do.

  4. 04

    Hand the review to an agent

    An agent can run the review and propose revocations, then send them through the same Actions you use. Its authority is never wider than the admin who delegated it.

Common questions.

Only where you declare an Action that does, and only through that Action. There is no general write path: if no reviewed Action revokes a seat, nothing in the platform can revoke one.

No, and it should not pretend to be. Each system is read on a cadence you set, so a Function reports the estate as of a named pull and tells you when that pull ran. For a quarterly review that is the better trade, because the answer can be reproduced and cited months later. When a seat has to be gone this minute, the Action that revokes it is the path, not the report describing it.

It gives you evidence, not a verdict. A review names its sources, the pull that captured them, the approver behind each grant and every Action taken since. Whether that satisfies your auditor, and whether the control itself is designed correctly, stays your judgement and your obligation.

Bring us a process.
We'll build it with you.

A business process, the systems it touches, and the rules it needs to follow.