Identity Governance
High scrutiny and high blast radius; proof and governance matter.
This interactive experience is the shipped product itself — the same application code customers run in production, mounted read-only in your browser over a real sample journey. Not a video, not a mockup: because the demo and the product are one codebase, it can never drift from the real thing.
Inside this journey
-
Pre-Sales
Qualify and diagnose before investing in a full evaluation cycle.
-
Qualification
Confirm budget, decision authority, timeline, and urgency created by the compliance finding before committing to full discovery.
Qualification Questions
Compliance finding and urgency
- Can you briefly summarize the compliance finding that prompted this engagement and the date it was issued?
- What is the required remediation or evidence date tied to the finding, if any?
- Does the finding involve regulated data or controls that imply conditional contract requirements (for example PHI, PCI, or classified/government data)?
Initial technical scope for evaluation
- Which 2–3 high-risk applications would you want us to validate first so we can assess connector completeness and risk scoring?
Budget and decision authority
- Is there an allocated budget range for remediation or for running an initial evaluation?
- Who is the primary decision-maker for a solution like this and which roles must sign off (title or role)?
Timeline and next-step readiness
- What is your target timeframe to complete the initial evaluation and decide whether to proceed?
- To make the most of a discovery meeting, are you available for a 60-minute discussion within the selected timeframe?
-
Enterprise Discovery
Map stakeholders, in-scope applications, HR data quality, success metrics, and constraints across the buying group.
Discovery Questions
Quick tour of your current access posture
- Give a concise summary of the failed audit finding that initiated this project, including systems implicated and the auditor's core concern.
- How many applications are in your current inventory, and which application categories hold the majority of access risk?
- When did you last run a certification campaign covering both on-prem and cloud systems, and what was the elapsed time to completion?
- Describe the typical process from an auditor finding to the first remediation action, including owners and handoffs.
- Estimate the number of people (reviewers, approvers, integration engineers) who participate during a single certification campaign.
- Is there an executive sponsor who will commit to the pilot within the next 30 days?
If this fails again, what actually breaks
- If the next audit names your team again, which immediate operational change would you expect, budget reallocation, mandated project, or leadership review?
- Provide an estimate of combined costs for remediation hours, external audit work, and potential regulatory penalties from a repeat finding.
- Name the business units or revenue streams that would be most affected by recurring access review failures.
- Who in the executive chain typically reallocates funds after a compliance event?
- Which metric would be decisive for you after a pilot: certification cycle time, risk signal precision, or entitlement completeness?
Where your access visibility actually breaks
- List up to three systems that are most likely to produce incomplete entitlement exports and would expose you in an audit.
- On those systems, indicate the current method of entitlement extraction: API, direct database, scheduled report, or manual spreadsheet.
- Walk me through the last time a connector failed to deliver full entitlement data, what detection lag you saw, and who noticed it.
- Do any of your critical applications require elevated network paths, jump hosts, or privileged service accounts that would block automated extraction?
- Identify any systems without a clear owner who can approve connector access within your pilot timeline.
Who signs and who slows things down
- Who is the single operational owner we should work with for pilot approvals and emergency escalations?
- List the cross-functional roles that must be engaged for a pilot and note their typical availability, for example security, HR, app owners, audit, and legal.
- Explain how priority disputes between security, HR, and application owners are resolved today.
- Name the team responsible for HR data quality and the person we can hold accountable for corrections during the pilot.
- How often do application owners complete certification assignments on schedule under the current process?
Connector reality check
- If one of your top-three risk systems needs a custom connector, how will that affect your timeline and approval process?
- Identify which target systems already expose APIs suitable for entitlement retrieval and which require alternative access methods such as report parsing or DB queries.
- Estimate the number of distinct connector types required for a three-application pilot.
- Do you currently have service accounts and network rules that allow automated entitlement queries, or will new approvals be necessary?
- What's an acceptable minimum percentage of entitlement coverage on day one for the pilot to be considered valid?
- Is there any application in the proposed pilot set that has no feasible connector path within four weeks, and would that single app block the pilot?
Can HR be trusted as the identity source?
- Provide typical rates at which HR onboarding, transfers, and terminations fail to reflect in downstream directories.
- Specify the HR systems that feed identity processes and identify who controls API or export access for each.
- Walk me through a recent joiner or leaver error that resulted in stale or orphaned access, and the steps taken to remediate it.
- What percent of your identities have a consistent employee ID mapped across HR and directory systems today?
- Would you be willing to dedicate an HR data owner for the pilot to sign off on corrections within two weeks?
Technical and compliance gates that stop progress
- Which compliance, legal, or contractual approvals must clear before any connector can query production data?
- Are there vendor agreements or contracts that restrict automated entitlement extraction from any critical system?
- Confirm whether network segmentation, jump hosts, or auditing proxies will require special routing for connectors.
- Report the typical calendar time required to obtain security approvals for integrations, including pen tests and privacy review.
- Point to who would sign risk acceptance if a connector requires elevated privileges for the pilot.
The alternatives you're actually weighing
- Reveal what would have to be true about an internal tool or process for you to avoid procuring an external platform.
- Specify the alternatives you are evaluating or have already considered: incumbent IGA, spreadsheet/process remediation, new cloud governance, custom integrations, or other.
- Has any team proposed solving this entirely in-house, and if so, what resource and timeline estimates were provided?
- Offer a concise assessment of whether any evaluated vendor or internal approach can deliver audit-ready certification evidence within your target window.
- What single capability missing from the alternatives would make you switch to an external platform immediately?
Readiness checklist that must be true before we start
- Select the three prerequisites that must be satisfied before we begin work: HR feed access, directory read, application admin account, network routes.
- Confirm whether APIs, service account credentials, and test environments exist for each pilot system, or whether we will need production access.
- State the available internal headcount for the pilot: technical owner, application owners, and HR data owner.
- Are test environments available for all pilot systems, or will some work need to proceed directly in production?
- Describe any regulatory approvals or audit notifications that must be logged before we begin, and typical lead times.
How you will measure success and make the call
- Assume the pilot reduces certification cycle time by 3x for the three target systems, what would prevent you from approving a purchase that week?
- Report the KPIs you will track during the pilot and the target improvement that would represent a clear win.
- State whether you have a baseline of manual analyst flags to compare against risk scoring and how that baseline will be provided.
- Point to who has final budget authority to move from pilot to production if targets are met.
- What's your target timeline from pilot completion to procurement decision?
Next steps to keep momentum
- Highlight the immediate blocker that, if not resolved within 72 hours, will pause the project.
- Share the primary technical and business contacts you will assign for the pilot, including emails and availability windows.
- Select which artifacts from us would accelerate your internal approvals: architecture diagram, data flow map, privacy impact assessment, sample connector plan.
- Choose your preferred cadence for pilot updates: weekly written summary, twice-weekly sync, or dashboard access only.
- Are there blackout windows or system freeze periods in the next quarter that would prevent connector work?
-
-
Solution Evaluation
Validate connectors, entitlement completeness, and risk-scoring by loading sample systems and running an automated certification campaign against acceptance criteria.
- desired_state
- current_state
- stakeholders
- gaps
- success_criteria
- decision_readiness
- desired_state
- decision_readiness
- current_state
- success_criteria
- gaps
- stakeholders
- desired_state
- success_criteria
- stakeholders
- gaps
- current_state
- decision_readiness
- decision_readiness
- decision_readiness
- decision_readiness
- decision_readiness
-
Solution Scope
Define connector inventory, modules, responsibilities, timelines, and measurable acceptance criteria for the rollout.
Scope Configuration
- Connect to core ERP system
- Connect to on-prem directory services
- Connect to cloud platform entitlements
- Aggregate and normalize entitlement data
- Map entitlement attributes per connector
- Activate default risk-scoring engine
- Execute initial risk-scored certification campaign
- Deploy reviewer UI and certification templates
- Integrate HRIS for joiner-mover-leaver automation
- Implement separation-of-duty enforcement
- Deploy automated remediation and revocation workflows
- Generate audit evidence package and logs
- Provide ongoing connector maintenance and upgrades
Scope Questions
Connect to core ERP system
- Which core ERP application and modules (for example SAP FI, SAP MM, Oracle GL) must be connected for entitlement collection?
- How many distinct ERP modules or tenancy domains (for example production GL, test AP) are in scope for the initial connector run?
- Do you require read-only connector access or service account credentials with delegated rights for the ERP integration?
- Which artifacts can you provide to validate ERP entitlement completeness (for example export of ERP role-to-user assignments, authorization objects for SAP modules)?
- What acceptance criteria will confirm the ERP connector is complete for audit purposes (for example: all users in SAP FI/AP/MM present; entitlement counts match the ERP export within 5%)?
Connect to on-prem directory services
- Identify the on-prem directory service in use and supply domain names (for example corp.example.com) for group and permission enumeration.
- How many domain forests or cross-forest trusts must we inventory to capture group nesting that maps to production access?
- Do you have privileged directory service accounts reserved for integrations and can you provide the service account owner contact for each domain?
- List Active Directory object classes, groups, or naming patterns that directly gate access to production financial systems (for example Finance-Prod-Admins, Finance-Approvers).
- Are there existing scripts or exports (for example LDAP dumps, PowerShell exports) you prefer we reuse for entitlement collection?
- What evidence will validate directory connector completeness for auditors (for example: LDAP export showing all groups mapped to production servers and a reconciliation report with >=98% match)?
Connect to cloud platform entitlements
- List the cloud platforms and account identifiers that hold high-risk workloads to connect (for example the AWS account ID for payments systems).
- Estimate the number of cloud service principals, roles, and identities expected to be inventoried across the accounts (for example 1,200).
- Select whether we should fetch role-level IAM policies, inline policies, and resource-level permissions as part of entitlement collection.
- Identify high-risk cloud resources to prioritize in the initial connector run (for example S3 buckets storing PII, production Kubernetes clusters).
- Provide the principle of least privilege baseline or benchmark you follow (for example CIS profile or internal policy document name) to align mapping.
- How will you supply API credentials or cross-account access to each cloud account (for example cross-account role ARN, temporary assume-role, API key)?
Aggregate and normalize entitlement data
- Confirm whether canonical identifiers exist across systems such as a global employee ID present in HR exports to drive identity matching.
- Provide the HRIS fields available for matching such as employee ID, corporate email, manager id, and cost center.
- Give example title and department normalization rules you expect us to apply (for example map 'Sr. Accountant' and 'Sr Accountant' to 'Senior Accountant').
- Select a data quality threshold for identity merging across ERP, directory, and cloud (for example minimum 90% match on employee ID and email).
- How will you verify that aggregated entitlement data meets audit readiness (for example reconciliation report showing >=95% coverage of accounts in SAP FI/AP and matched HRIS records)?
Map entitlement attributes per connector
- Specify entitlement attributes from the ERP (for example authorization object, role name, TCODE) that must be captured and mapped to platform fields.
- For Active Directory, state which group attributes or nested group behavior must be preserved (for example primary group, tokenGroups, nested membership).
- Specify cloud IAM attributes to map (for example policy ARNs, resource ARNs, role session tags) and how they should translate to risk categories.
- Choose whether custom attribute transformations are required (for example concatenating role+resource into a single entitlement string).
- Who will own decisions on attribute mapping conflicts and who is the technical contact for connector field mapping (name and email)?
- Are there regulatory attributes that must be retained for audit trails (for example job code, supervisor approval flag)?
Activate default risk-scoring engine
- Choose which risk models to prioritize for the pilot (for example segregation-of-duty, privileged access to production financial systems, lateral movement risk).
- Confirm whether you want default risk thresholds applied (for example high risk >=80) or if thresholds must align to your audit policy.
- Describe one prior audit finding we should tune the scoring to detect (for example a single user with approve+execute on wire transfers).
- Who in your compliance team should be included in risk model tuning sessions (name, role, and availability)?
- Should automated risk overrides be allowed during certification campaigns and if enabled, what escalation path do you require?
Execute initial risk-scored certification campaign
- When should we schedule the initial certification campaign against the three pilot applications (ERP module, Active Directory domain, cloud account)?
- Estimate the number of reviewers and reviewer groups participating in the pilot (for example 10 finance managers, 5 application owners).
- State measurable pilot targets you want us to aim for during the initial campaign (for example complete campaign in 7 days, reviewer response rate >80%).
- Pick whether reviewers should see risk-score explanations and entitlement context inline (for example linked transaction IDs, last activity date).
- Enter the contact (name and email) for the reviewer training owner who will approve sample responses for test cases.
Deploy reviewer UI and certification templates
- Will reviewers access the UI via your SAML single sign-on and multi-factor authentication (for example your SAML identity provider)?
- Describe the certification templates you need for Finance and IT applications (for example default reviewer instructions, due dates, escalation rules).
- Enter the desired default reviewer SLA for certification tasks (for example 3 business days per reviewer).
- State whether reviewer roles require read-only, comment-only, or approve-and-revoke permissions within the UI.
- Give sample reviewer groups and their expected membership counts to pre-populate templates (for example Finance Managers: 12).
- Indicate whether certification templates need localization beyond English (for example Spanish for regional teams).
Integrate HRIS for joiner-mover-leaver automation
- Name the authoritative HRIS system and the export artifact that provides hire, termination, and transfer events (for example core HR export file name).
- Enumerate the HR fields available for automation such as employee status, termination date, employee ID and cost center.
- Indicate whether existing HR-to-ID mapping tables exist (for example mapping contractor IDs to corporate IDs) and if they can be shared.
- How often are HR feeds updated and what is the expected latency for new hire and termination events?
- Supply the contact (name and email) for HR data quality ownership and the approver for exceptions across business units.
- Outline the process for handling unmatched HR records during automation runs (for example create ticket and 48-hour SLA for HR review).
Implement separation-of-duty enforcement
- Enumerate the segregation-of-duty policies from prior audits that must be encoded (for example approve vs execute on wire transfers).
- Where can we access your existing control matrix or policy document to import rules and baseline controls?
- Outline the conflict resolution workflow required when a separation-of-duty violation is detected (for example automatic revocation, manager approval within 24 hours).
- Name the approver role for exceptions to separation-of-duty controls and specify the auditor sign-off artifact required.
- Declare the regulatory standards and control identifiers to which these policies must map (for example OCC guidance, HIPAA control identifiers, CMMC control IDs).
Deploy automated remediation and revocation workflows
- Declare the systems that must support automated revocation actions (for example AD account disable, ERP role removal, cloud role detach).
- Pick remediation mode: staged (notify manager then revoke after set days) or immediate automated revocation on high-risk findings.
- Detail the approvals and audit trail metadata that must be recorded when automated revocations occur (for example approver id, ticket ID, timestamp).
- Supply contact details for the playbook owner and the emergency contact for remediation failures (name and phone/email).
- Declare business hours or change windows during which revocations must not occur (for example end-of-day payroll windows).
-
Mutual Commit
Agree commercial and contractual terms, data-access authorizations, and implementation dependencies required to start work.
Agreement Modules
- Master Services Agreement (MSA)
- Statement of Work (SOW)
- Subscription Order Form
- Data Processing Agreement (DPA)
- Data Access Authorization
- Implementation Dependencies & Schedule
- Service Level Agreement (SLA)
- Change Order Agreement
- Payment Schedule Agreement
- Regulatory Compliance Addendum
-
Deployment
Lock readiness facts and configuration values before execution begins.
-
Pre-Deployment Readiness
Confirm environments, owner contacts, HR source alignment, and scheduling windows the deployment depends on before connector work begins.
Pre-Deployment Questions
Environment and access
- List the production and non-production environments we must connect to for the initial deployment, naming each by system category (e.g., "ERP (SAP)", "Active Directory", "Cloud IAM").
- For the environments you listed, is programmatic read-only access available now (so we can validate connector compatibility)?
- Have integration/service accounts with the required read-only entitlements been created for connector work?
- If integration/service accounts are partial or missing, who is responsible for creating them? Provide name and role (so the seller can coordinate provisioning).
Data and configuration
- Which HR system is the authoritative source of joiner/mover/leaver data for the deployment scope? Name by category (e.g., "single global HRIS instance", "multiple HRIS by region", "payroll system as source").
- Has the HR population for the scoped business units been reconciled to a single canonical employee identifier (so joiner/mover/leaver automation can run reliably)?
- Who owns HR data reconciliation and mapping? Provide the contact name, role, and whether they have agreed to validate field mappings (this owner is required for mapping sign-off).
People and ownership
- Please assign a named owner for each workstream: connector integrations, HR data, application owner certification, and security/change approvals (list name and role for each—these map directly into the deployment RACI).
- For the applications in scope, have application owners agreed to participate in certification campaigns and supplied expected reviewer lists?
Timing and constraints
- Are there scheduled blackout windows, compliance freeze periods, or maintenance windows that will block connector activity or certification campaigns in the next 90 days? If yes, indicate whether calendar access will be provided or coordination is pending.
- What is the preferred maintenance window (typical nightly or weekend hours) for connector syncs and automated certification runs so we can align scheduling? Select the closest match.
- Are any organizational approvals required before connector access is granted (change advisory board, data-access authorization, security exceptions)? If yes, indicate whether the approval owner is assigned and whether an expected approval date is known.
- What is the target start date for connector access and the initial certification run? (Provide a date so we can create a draft timeline and resource plan.)
-
Configuration Details
Capture connector credentials, API endpoints, field mappings, risk-threshold settings, and any custom integration parameters.
Configuration Details
Connector & Target Environment
- Select the connector's target system category (choose the single best match)
- Enter the environment name the connector will target (format: short label; Default: production)
- Enter the connector API or endpoint URL the platform should call (format: https://hostname[:port]/path — provide exact base URL used for API calls)
Authentication & Credential Handoffs (identifiers only — secrets exchanged via your vault)
- Select the authentication method the target system supports for this connector
- Provide the non-secret credential identifier for the chosen auth method (e.g., client_id, integration user name, key name) — do NOT paste secrets
Field & Entitlement Mappings (exact source field names)
- Enter the exact source field name that identifies the account/user in the source system (format: exact field/attribute name from source)
- Enter the exact source field name that contains entitlement/role attributes (format: exact attribute name; e.g., memberOf, roleName)
Risk & Operational Parameters (values consumed by certification engine)
- Risk score threshold to flag an entitlement as HIGH RISK (integer 0-100; Default: 70)
- Enter the full name and email of the connector credential owner who will approve secret handoff (format: Full Name <user@domain>)
-
Deployment
Execute integrations, run certification campaigns, remediate data issues, and operationalize reviewer workflows with clear owners and milestones.
-
-
Success
Review certifications completed, reductions in cycle time and risk exposure, and maintain a shared channel for issues and enhancement requests.
Success Reviews
- Go-live Health Check (weeks 1-4)
- First Measurement Review (weeks 4-10)
- Acceptance Gate and Ratification (around day 90)
- Monthly Operational Review (months 4-6 post-acceptance, recurring)
- Quarterly Business Review (recurring quarterly)
Issues & Enhancements
- Run root-cause investigation for any connector above the error-rate threshold and publish findings within 7 days.
- Record the acceptance decision and named signatory in the project record and notify governance stakeholders.
- Execute the archival and read-only retention of legacy spreadsheets and publish the archive location and retention policy.
- Publish remediation tasks for any conditional or failed criteria with owners, verification steps, and firm resolution dates.
- Current metrics and trend analysis
- Reduce the average time to remediate flagged entitlements month over month until the target is met.
- Ensure connector error rate is within acceptable bounds or has a mitigation plan with dates.
- Prioritize enhancement requests that materially affect reviewer throughput and acceptance criteria realization.
- Re-confirm success criteria and owners
- Update the remediation tracker with new target dates and verification checkpoints.
- Add prioritized enhancement requests to the shared backlog with proposed delivery windows.
- Outcome summary vs baseline
- Demonstrate a sustained reduction in risky entitlements versus the pre-deployment baseline.
- Confirm audit evidence is complete and that outstanding evidence gaps have assigned owners and timelines.
- Agree the top operational priorities for the next quarter to protect and extend realized outcomes.
- Publish a quarter-to-date report comparing reduction in risky entitlements and campaign cycle time to the pre-deployment baseline.
- Assign owners and dates for any remaining audit evidence gaps and track to closure.
- Update the quarterly operational plan with the agreed priorities and circulate for acknowledgment.
- Core connectors are returning entitlement sets consistent with expected schemas and no critical errors remain.
- All open high-priority blockers have an assigned owner and target resolution date.
- Your reviewers have access and have begun initial interactions with the certification campaigns.
- Publish the deployment validation checklist including exceptions and remediation target dates.
- Log all open issues to the shared channel and tag each with severity and a proposed owner.
- Schedule a connector re-test window after fixes are applied.
- Present first-campaign results
- Establish whether average certification campaign cycle time and review completion rate are trending toward the targets recorded in the Solution Scope.
- Agree a prioritized remediation plan for the top 3 root causes with target dates to reach acceptance readiness.
- Confirm data quality actions required on HR sources if they are contributing to gaps.
- Publish the remediation plan with task-level dates and link it to the Solution Scope acceptance checklist.
- Run a connector completeness re-check and report the percentage of entitlements successfully reconciled.
- Produce a short diagnostics packet showing root-cause evidence for each metric gap.
- Restate acceptance criteria and numeric targets
- Capture a formal acceptance decision with a named signatory for the enterprise engagement.
- For any failed or conditional criteria, agree a remediation plan with clear dates and verification steps.
- Confirm the incumbent spreadsheet process is archived or locked to read-only and that no active reviews continue outside the platform.
- Open remediation and blocker burn-down
- Audit readiness and evidence
- Present measured outcomes against each criterion
- Gap diagnosis
- Deployment and connector validation
- Enhancement requests and prioritization
- Document pass, conditional pass, or fail per criterion
- Persistent risks and policy adjustments
- Agree corrective actions and timelines
- Early adoption signals and usage patterns
- Quarter roadmap and operational commitments
- Blockers and open issues
- Confirm readiness path to acceptance gate
- Operational adjustments and next steps
- Remediation plan for any failed or conditional criteria
- Agree immediate remediation actions
- Incumbent process wind-down confirmation