IAM and access reviews: who can access what, why, and the gap to close
An entitlement review happens in a spreadsheet, once a year, on the applications there is time to look at. Your agent works on the extracts you deposit: it links accounts to people, exposes the inheritance path of every right, names the gaps with the rule behind them and drafts the change order. Hosted in France: your entitlement graph, which says where your keys are, does not leave the company. Removing an access stays a human decision, taken by the resource owner and recorded.
Updated on
Gaps are ranked by reach, with the rule, its version and the values observed.
An account the data cannot settle is marked undetermined, never compliant.
🔗 Sourced · deposited extracts, each with its date and age
Removing an access can interrupt an activity or erase a trace an investigation needs: the decision belongs to the resource owner, and the effect is only declared obtained after the next extract has been read back.
✎ Framework · order prepared, decision and execution human
A Blue Lemon Agent access-review agent, working on the extracts you deposit: it links accounts to people, exposes the inheritance path of every right and its owner, names the gaps with the rule and its version, and drafts the change order for your operator. No access is removed by the agent; no direct connection to a directory or an identity provider is sold here. It runs on local inference or is hosted in France: your entitlement graph stays with you, architecture designed to reduce exposure to extraterritorial legislation, location alone not guaranteeing immunity.
Reference points describing our offer, not results measured at a client. How much is gained on your number of accounts, applications and owners is confirmed by a pilot.
What does an AI agent bring to your entitlement review?
A right whose inheritance path and owner are visible is settled in a minute; a spreadsheet of raw accounts is copied out for weeks.
! The challenge
The French data protection authority recommends a regular review of entitlements, at least once a year, and the removal of permissions as soon as a person is no longer entitled (CNIL, “Sécurité : gérer les habilitations”, published 13/03/2024). What jams is not the decision: it is linking thousands of accounts to people, finding who is accountable for each application and reconstructing where a right comes from. That work is systematic, and it can be prepared.
✓ Our answer
Your resource owners receive batches already worked through: the account, the person, the path of the right, the rule questioning it and the values observed. They decide, and their reasoned decision is kept with its date and its author. Silence never amounts to certification, and an account the data cannot settle is marked undetermined. Local inference or an isolated resource hosted in France: the graph describing your accesses, and therefore your entry points, does not leave the company.
Your entitlement graph: sovereignty & confidentiality
The list of your privileged accounts says where your keys are. Its confidentiality is a security matter in itself; here is how it is held.
Local inference
The agent can run on a machine of your own organisation: no directory extract and no entitlement graph leaves the network.
Hosting in France
Otherwise, a dedicated and isolated resource hosted in France, under French law — your extracts and your review decisions: processing and access operated in the European Union targeted by the architecture.
Reduced extraterritorial exposure
For your entitlement graph and your privileged accounts, the architecture aims to reduce exposure to the Cloud Act and FISA 702; location in France or in the European Union alone does not guarantee immunity.
Entities kept apart
Each subsidiary, entity or site has its own space: a review batch never shows another entity's accounts, and roles follow that separation.
Decisions preserved
Every decision keeps its author, its date, its reason and the version of the rule applied; encryption, role-based access (RBAC) and logging usable in a control.
AI Act: governed deployment
The agent is strictly in support; no account disabled, no right removed and no campaign closed automatically; traceability and human oversight throughout.
What depends on the architecture chosen These points are not general guarantees: they are settled deployment by deployment, in the quotation.
- The applicable location is that of the architecture set out in the quotation and verified before commissioning.
- Local execution is announced only for the configuration explicitly described and accepted in the quotation.
- The applicable isolation depends on the deployment mode set out in the quotation; no dedicated isolation is presumed.
- Roles and permissions are configured and accepted for the identities and systems actually connected.
- The events logged, their content, their retention period and who may access them are defined for the deployment chosen.
See the agent at work
5 real situations, taken from those that come up most often. Pick one: the exchange unfolds as it would in your organisation.
A scripted demonstration. These exchanges show how the agent behaves — its sources, its refusals, what it leaves to your teams. Nothing is sent from this page, no model is queried here, and the matters named are fictional. That is precisely what we promise your data.
The behaviours shown here — monitoring, automation rules, routing and reminders — are configured with you during deployment, from your tools, your rules and your thresholds.
The architecture points named in these exchanges — location, local execution, isolation, encryption, role-based access, logging — are not a guarantee attached to the demonstration: they are those of the architecture set out in your quotation, and verified before commissioning.
The company in this demonstration
Fictional companyVallonis Participations — an active holding company, six holdings and one semi-public company
- Sector
- Activities of holding companies (NAF 64.2) — ownership, steering, shared finance and IT management
- Headcount
- 41 staff at head office, 3 of them in shared IT; 2,340 people across the consolidated scope, no CISO role anywhere
- Holdings served
- 6 subsidiaries and 1 semi-public company: digital services, industry, energy, a clinic held as a stake, two portfolio companies
- Order of magnitude
- 3,180 active accounts, 74 applications listed, 214 accounts with no named owner; one review a year, required by the statutory auditor
- Tools in place
- A corporate directory and a ticketing tool at head office, one shared finance ERP, four separate application estates in the subsidiaries — the agent reads the EXTRACTS deposited, it connects to none of these tools
- Who decides
- The group chief financial officer arbitrates removals; the head of internal control runs the instruction and keeps the evidence; each subsidiary director owns their applications; the outsourced operator executes signed orders
- Room for improvement
- The 2025 review covered 11 applications out of 74 and stopped in April for want of identified owners; 214 accounts have nobody accountable, and 38 leavers' accounts were still active at extraction time
Vallonis Participations has to prove to its statutory auditor every year that access across its consolidated scope is reviewed. The difficulty is not the decision: it is that the holding owns none of these accounts, that its six holdings share neither a directory nor a vocabulary, and that no security role decides in their place. The agent runs on local inference on a machine at head office and reads the extracts each subsidiary deposits, with their date. It links, explains, names the gaps and drafts the orders; the chief financial officer decides, each subsidiary director answers for their applications, and the outsourced operator executes. The five tabs are the five perimeters of the 2026 campaign, from the first triage to the file handed to the auditor.
This company, its figures and the exchanges that follow were invented for the demonstration. They illustrate a common situation; they describe no real client.
Linking an account means establishing who answers for it: a person on the personnel file, or a technical service with a named bearer. A match on a name alone is not enough — two namesakes exist across your consolidated scope.
What the 2 September extract carries, and its age: subsidiary directory — 6 hours; head office personnel file — 31 hours; last sign-in log — 6 hours. All below the 72-hour threshold you set.
The batch's input document is attached: the extract exactly as I received it, untouched, with the fingerprint of the deposited file. Everything below is derived from it, and you can replay any figure against it.
The four open cases all come from the same cycle — joiners, movers and leavers —, and that is where the gaps appear, never anywhere else:
· PME-01 — an application account still active sixteen days after a departure. Contract ended on 17 August on the personnel file, account open and used on 29 August. Change requested, priority 1.
· PME-04 — an administration account shared between three people. Three separate workstations sign in over thirty days. No action taken from that account is attributable to anyone: I cannot certify it, so I open a dated exception, priority 1.
· PME-02 — a guest account inactive for 190 days, owner identified: the project director who requested it. Eligible for review, priority 2.
· PME-03 — a joiner on 1 September. I propose the baseline rights of her population, and nothing else: the eight rights shared by the eleven people in the same job, never those of a colleague taken as a template. Review assigned, priority 4.
What I suggest next: open case PME-01, see where the right comes from, and judge whether the order I drafted is the one you would have written. deposited-extract_sillage-numerique.csvInput document · 412 rows received, untouched review-batch_sillage-numerique.pdf412 accounts, 4 cases opened, 3 undetermined
⛓ Sourced · extracts deposited 02/09 (directory 6 h, personnel file 31 h, sign-ins 6 h)
Why I do not take it in your place, and this is not a formality: that account still carries the scheduling of two nightly billing jobs and owns eleven shared files. Cutting it tonight stops tomorrow morning's billing. This is exactly the kind of effect an automatic revocation does not see.
What I prepared so the cut has no consequence, and it is the work nobody has time for:
· the two jobs rescheduled under the service account svc-factu-nuit, named bearer, with the switch-over window;
· the eleven files transferred to the project director, list attached;
· the removal order, to be handed to your operator, with the effective date you choose. That is what controlled remediation means: a replayable order, a chosen date, and the effect checked on the source before it is declared obtained.
The framework: the French data protection authority recommends removing permissions as soon as a person is no longer entitled (“Sécurité : gérer les habilitations”, published 13/03/2024). It recommends doing it, it does not say to do it blind: sixteen days of delay are caught up with one signature, a stopped billing run takes a week.
What I do after you sign: I wait for the next extract and read the account back. Until the source shows it closed, the effect is not declared obtained — an order sent is not an order applied. change-order_PME-01.pdfRemoval prepared, dependencies handled, effect to be confirmed
✎ Framework · order drafted, decision with the owner, effect confirmed on the source
The method, and it guesses nothing: for each application without an accountable person, I look at who requested the access in your tickets, who approved it, and which department the sign-ins come from. When the three agree, I propose; when they diverge, I say so.
· 34 applications: all three indications agree. Proposal made, to be confirmed with one click by the subsidiary director.
· 13 applications: two indications out of three. Proposal made, with the disagreement shown — management control approves, but the sign-ins come from operations.
· 14 applications: nothing agrees. I propose nobody. One of those fourteen has had no sign-in for 400 days: the real question is not who answers for it, but whether it should still exist.
The figure that does not flatter me, and I publish it: of the 47 proposals, your internal control rejected 6 in the dry run — all of them applications taken over in a 2023 acquisition, where the original tickets belong to a company that no longer exists. 13 % of my proposals were wrong on that subset, and none anywhere else. So I added a rule: an application inherited from an acquisition predating its takeover no longer gets an automatic proposal, it goes straight to the subsidiary director.
What I suggest next: move to the industrial perimeter, where the subject is no longer the owner but the combination of rights. proposed-owners_61-applications.pdf47 proposals, 14 abstentions, 6 rejected in the dry run
⛓ Sourced · 3,400 access tickets, 12 months of sign-in logs, approval history
· ETI-01 — one person holds both supplier creation and payment release. Holding both rights is enough, on its own, to create a supplier and pay its invoice without anyone else stepping in. Rule SoD-04 of your matrix, version 3, adopted on 12 January 2026. The two rights do not come from the same place: creation is direct, set by hand in 2021; payment release is inherited from the Compta-Sites group, itself a member of Finance-Étendue. No compensating control is declared. Exception opened, priority 1.
· ETI-02 — an ERP administration account with no sign-in for 120 days. Standing privilege, measured inactivity. Change requested, priority 1.
· ETI-03 — a project access whose end date was 31 August 2026, still open on 2 September. Change requested, priority 2.
· ETI-04 — an application with no owner. No certification by default: nobody can certify what nobody answers for. Exception opened, priority 3.
What I suggest: for ETI-01, three costed ways out rather than a flag — you pick the one that holds in your organisation. segregation-of-duties-conflict_ETI-01.pdfRule SoD-04 v3, two inheritance paths, three costed ways out
⛓ Sourced · ERP extract of 02/09 (8 h), SoD matrix v3 of 12/01/2026, entitlement log
· Split the two rights. Supplier creation moves to the site's management assistant. Real cost: 4 files a month to reroute, measured over your last twelve months. The conflict disappears.
· Keep the combination, and add a compensating control. Any invoice from a supplier created less than 30 days ago goes to management control for sign-off. Over twelve months that would have covered 11 invoices — slightly under one a month. The conflict becomes a documented, dated exception with its control alongside.
· Keep the combination with nothing alongside. That is possible, and it is your call — but I write it as it stands in the file: exception accepted by the chief financial officer on 6 September 2026, without a compensating control, to be reviewed in six months. Your statutory auditor will read that line, and it will be accurate.
What I recommend, costed: the second. It costs eleven sign-offs a year against forty-eight reroutings for the first, and it leaves the circuit where it works.
What is yours, and nobody else's: declaring that this combination is acceptable. It is a risk judgement, it carries your name, and an unsigned exception is not an exception — it is a hole. costed-ways-out_ETI-01.pdf3 ways out, cost measured over 12 months, reasoned recommendation
✎ Framework · three ways out measured over twelve months, judgement with the CFO
What the data says: named account, production manager of the northern site, ERP administration privilege set in 2019, last sign-in 120 days ago, person still present on the personnel file — he changed jobs in May.
Why the privilege goes and the account stays: deleting the account breaks the link between his identifier and the 1,340 entries he posted in the ERP since 2019. Those entries would become orphaned in your audit trail, and your statutory auditor will ask about them. The account stays, without the privilege, with its deactivation date.
What I prepared: the privilege removal order, the check that no scheduled task runs under that account — there is none, I looked — and the offer of a four-hour time-bound access if his successor needs him during the handover.
The sector reference, given as indicative: Commission Delegated Regulation (EU) 2024/1774 of 13 March 2024, which applies to the financial entities covered by DORA, prescribes granting rights on a need-to-know, need-to-use and least-privilege basis, and granting administrator and emergency access only on a need-to-use basis or case by case. Orion Industrie is not a financial entity: that text does not bind you. It gives the state of the art, and that is why I cite it. privilege-removal_ETI-02.pdfPrivilege removed, account kept, audit trail preserved
⛓ Sourced · ERP extract, personnel file, scheduled tasks, Delegated Regulation (EU) 2024/1774 of 13/03/2024
· SAN-01 — the account of a carer who left on 21 August, whose access rights to the patient record are still open. Dual approval required: the patient record application owner and the director of care. Priority 1.
· SAN-02 — an emergency access was used on 27 August at 03:12, on one record, for 9 minutes. An emergency access — “break glass” — opens everything, immediately, and it must exist: at night a life does not depend on an authorisation circuit. What must also exist is the justification afterwards. Eligible for review, priority 1.
· SAN-03 — a contractor whose contract says “support” and whose account says “administration”. The right observed exceeds the right contracted: the gap sits between two documents you hold. Exception opened, priority 1.
· SAN-04 — a nurse's right that is compliant: role and ward agree, seniority is consistent. Eligible for review, priority 4 — it still goes to the owner, because a compliant right is certified, not skipped.
What I suggest: start with SAN-02, the emergency access — it is where the review brings most, and what gets looked at least. review-batch_clinique-des-rives.pdf4 cases, 1 dual approval, 1 emergency access to justify
⛓ Sourced · extract of 02/09 (11 h), emergency access register, deposited service contracts
What I gathered for the application owner: the time of opening, the duration, the record concerned, and the fact that this record appears in the admissions register for the same night, at 02:54. The justification is all but written: it remains to be confirmed with one click, or disputed.
What I do not manufacture: the link between the two. I show it, I do not conclude it. An admission at 02:54 and an opening at 03:12 may perfectly well have nothing to do with each other, and a carer knows that, I do not.
The figure that does not flatter me: over twelve months, 147 emergency accesses, of which 31 for which I find no element to match. I do not present them as suspicious — I present them as unmatched, which is not the same thing. Of those 31, 19 concern patients admitted to another facility and therefore left no trace here: the missing element is not yours.
What I propose for the remaining 12: a single question to the night shift manager concerned, with the date and time. Twelve questions in a year is not surveillance — it is the minimum that makes the emergency arrangement defensible the day you are asked about it. emergency-access-review_12-months.pdf147 accesses, 116 matched, 31 unmatched of which 19 explained
⛓ Sourced · 12 months of emergency access register (147), admissions register, matched records
What I reconstructed, and it is what makes the case instructive: the account was created as support in 2022. The administration privilege reached it on 14 March 2024, through the addition to the Exploitation-DPI group — a technical migration in which 27 accounts were added at once. Nobody meant to give that right to this contractor: he got it with the batch.
What I looked at next, before raising it: the other 26 accounts in that batch. Three are in the same position. SAN-03 is therefore not a case, it is the visible symptom of a 2024 migration.
What I propose, in order:
· the 4 accounts brought back to their contracted right, order drafted, for the application owner's signature;
· a review rule on bulk additions: any addition of more than 10 accounts to a privileged group opens a review batch the next day. Over your last three years that rule would have fired 4 times — it would drown nobody;
· the quarterly review clause to be carried into the next amendment of the service contract, text attached.
What stays with you: the contractor is currently working on a migration. Pulling his right back tonight may stop it. You set the effective date; I propose 15 September, the end of his announced window. right-versus-contract-gap_SAN-03.pdfMigration of 14/03/2024, 4 accounts out of 27, review rule proposed
✎ Framework · common cause identified, 4 accounts affected, effective date with the owner
· PUB-01 — an internal move on 1 July: an officer who went from planning to public procurement. I compared the rights of the old post with those of the new: 14 rights in common, 9 specific to the old post still open, 4 missing for the new one. Review assigned, priority 2. A move is not a departure: I do not propose removing everything, I propose the difference.
· PUB-02 — a generic account accueil-clairval, with no documented exception. Five people sign in to it. Exception opened, priority 1.
· PUB-03 — a review batch sent on 12 August to an owner, chased twice, unanswered on 2 September. The batch stays open and the 23 rights it contains stay to be settled. Exception opened, priority 3.
· PUB-04 — the extract from your property management application is 96 hours old, where the threshold you set is 24. So I present none of its 87 accounts as an up-to-date finding: they are marked “stale source”, priority 2.
What I suggest: PUB-03, the unanswered batch — it is the case that decides the worth of the whole campaign. review-batch_sem-clairval.pdf604 accounts, 4 cases, 87 accounts on a stale source
⛓ Sourced · extracts of 02/09, except property management (29/08, 96 h, over threshold)
What a silence is worth, mechanically: if no answer meant approval, your campaign would measure your managers' availability, not the accuracy of your rights. The first overloaded owner would certify the largest batch, and the instrument would stop measuring what it exists for. The day you are asked how those 23 rights were certified, “nobody answered” does not hold.
The three routes that close the campaign, all of them open:
· the deputy designated in advance — your note of 3 March 2026 provides for a deputy on public procurement, and it has never been used;
· escalation to the general manager after two chasers, with the batch as it stands;
· partial closure: the 23 rights stay open, the campaign closes on the other 581 accounts, and the report carries the exact line — “23 rights not settled, owner absent, two chasers on 19 and 26 August”.
What I recommend: the first. It is already written into your organisation, it calls for no new decision, and it turns a gap in the campaign into a procedure actually used.
What the recertification campaign is worth, in the end: it is worth only what an owner has read and signed. A campaign closed on silent batches recertifies nothing.
What I do in every case: I record the absence of an answer with its date. It is itself evidence — evidence that the question was asked, twice, and to whom. unanswered-batch_PUB-03.pdf23 rights, 2 chasers, 3 closing routes
✎ Framework · silence recorded, three closing routes, no certification by default
What 96 hours actually change, on that application: your personnel movements of the last four days are not in it. On your history that is 3 movements on average. Certifying as “compliant” an account closed yesterday, or missing an account opened the day before, produces false evidence — and false evidence is worth less than none.
What I did instead: the 87 accounts are worked through, their gaps calculated, and the whole thing waits for a fresh extract. The work is not lost: at the next deposit only the accounts that moved are recomputed, the others are already done.
What I suggest, and it is the real fix: that application is deposited manually and monthly, which is what creates the gap. Three others of your 74 applications are in the same position — I name them in the attachment. Moving those four deposits to a weekly rhythm would be enough to hold your 24-hour threshold on campaign day.
One point I owe you, and it is not a lack of means: I do not go and fetch the extract from the application myself. No direct link with your applications or your directory is in service, and I announce none: such a link is studied case by case, documented and tested before it is promised. What is sold here is what works today: you deposit, I work, and you know at every moment how old what I show you is. source-freshness_74-applications.pdf4 applications over threshold, deposit rhythm to revisit
⛓ Sourced · deposit dates of the 74 applications, 24-hour freshness threshold set by the client
· OT-01 — a contractor's remote access still open although its window closed on 29 August at 18:00. Dual approval required: operations manager and industrial network manager. Priority 1.
· OT-02 — a service account opening interactive sessions. A service account exists so a program can run, not so a person can sign in. 14 session openings in 30 days, from 2 workstations. Exception opened, priority 1.
· OT-03 — a request for a 45-minute time-bound elevation on a controller, for planned work. I propose the duration, the exact resource and the two approvers; I do not grant it. On this perimeter, privileges are no longer standing: they go through bounded, approved time-bound access, reviewed after use. Review assigned, priority 2.
· OT-04 — an emergency revocation request on a suspected account. Dual approval required, priority 1. In this demonstration no action is executed: neither here nor anywhere else does any write reach a real system.
The campaign report, across the five perimeters: 3,180 accounts deposited, 3,174 linked, 20 cases opened, 74 applications covered against 11 last year, zero external writes.
The time this moves, item by item: matching accounts to people took 70 % of a review's time; it now takes 9 %. Finding the owner of an application went from 45 % to 8 %, and building the evidence file from 35 % to 5 % — it is now built as decisions come in, instead of being written at the end. campaign-report_2026.pdf3,180 accounts, 20 cases, 74 applications, 0 external writes
⛓ Sourced · extracts from the 5 perimeters of 02/09, register of intervention windows
What is ready before the first signature: the complete order — account, rights, resources affected, the 3 controllers whose shutdown depends on that account, the fallback procedure, and the acknowledgement to demand from the operator. The long work is done; what remains is two clicks.
What the two signatures actually cost, measured over your last six crisis drills: a median of 4 minutes, 11 minutes at worst. Against the 40 minutes it takes, without a prepared file, to establish the list of resources affected before daring to cut.
Why two and not one, on this perimeter specifically: cutting an access on an industrial network can stop production, and a cut made on a mistaken suspicion is itself an incident. The second signature is not administrative slowness: it is the only person who knows what the action stops.
What I propose to remove the time that remains: a named pre-authorisation — two people designated in advance, reachable on call, whose agreement holds for any account in the perimeter during an open crisis window. It is signed once a year, and it brings the four minutes down to under one. The text is attached; it carries your names, not mine. emergency-revocation-circuit.pdfFile ready, 4-minute median, pre-authorisation proposed
✎ Framework · circuit timed, file ready, decision and execution human
· I open a case when an extract reveals a gap, without waiting for the annual campaign. A leaver's account found on 3 September does not sleep until March. And the reverse holds: if the next extract shows the gap is gone, I close the case myself, with the evidence.
· I chase an owner who has not answered, twice, seven days apart. I stop there: a third chaser is an escalation, and an escalation carries a name — yours.
· I mark as “stale source” any data older than your threshold, and take its accounts out of the campaign count. The mark falls away as soon as the fresh extract arrives, with nothing to re-enter.
Everything else waits for a decision, and the list fits on one attachment: remove, grant, merge two identities, certify, close a campaign, accept an exception. Six actions, six signatures, and each carries a name, a date and a reason.
Where all this runs: on a machine at head office, as sovereign AI — local inference, hosting in France; your entitlement graph does not leave the group.
What I do not measure, and it is not squeamishness: I produce no per-person indicator on the speed or quality of review answers. The mechanism is plain: such an indicator would become a target, and a hurried owner certifies faster by looking less. The instrument would destroy what it measures. One single exception, and it is not one: who signs is named. A signature is not a counter. who-decides-what.pdf3 automatic actions, 6 signed decisions, 0 individual indicators
✎ Framework · three reversible automatic actions, six signed decisions
Your case is not here? That is exactly what a 15-minute conversation is for. Book the free audit →
What does the agent actually do?
Twelve review modules included in the core offer, from listing the sources to the evidence file, plus the sovereign-AI foundation they run on. All of them work in support, under your validation.
Inventory of identity sources
Lists the extracts you deposit — directory, payroll, applications, technical accounts — each with its date and its age at review time.
Identity resolution
Links an account to a person or to a bearing service, on strong identifiers. A match based on a name alone is left for you to confirm.
Joiners, movers and leavers
Compares the personnel file movements with the rights observed, and prepares the creations, changes and removals that follow.
Entitlement graph
Shows, for each right, its inheritance path: the person, the group, the role, the resource and the owner accountable for it.
Catalogue of rights and their owners
Versions roles, rights, justification, criticality, duration and resource owner — and flags those with nobody accountable.
Baseline roles by population
Proposes a baseline set of rights per job family from rules you approve. No entitlement is inferred from a mere resemblance between accounts.
Segregation of duties
Detects incompatible combinations of rights from your matrix, with the rule, its version, the context and the dated exception where there is one.
Accounts at risk
Spots orphaned, dormant, shared, expired and unowned accounts, and technical accounts open to interactive sign-in.
Recertification campaigns
Distributes batches to owners, collects the reasoned decision, chases late reviewers and keeps the evidence of every answer.
Privileges and time-bound access
Prepares time-limited elevations, the approvals required, emergency access and the review that follows its use.
Controlled remediation
Drafts the change order for your operator, replayable without double effect, then waits for the next extract to confirm the effect obtained.
Evidence and steering
Logs source, decision, campaign, exception, action, acknowledgement and delay — the file an internal control or a statutory auditor asks for.
Sovereign AI
The hosting and confidentiality foundation the agent runs on.
Need to go further?
These agents handle a different business process, with their own owner and their own price. They are added to this one.
Cybersecurity & logs
Correlating the events of an incident and qualifying an alert belongs to security monitoring, not to an access review.
Cybersecurity & logs from 601 € excl. VAT / month Discover the agent →DPO / GDPR support agent
Qualifying a data breach in legal terms, and deciding whether to notify it, belongs to the DPO.
DPO / GDPR support agent from 668 € excl. VAT / month Discover the agent →In 15 minutes we identify the most relevant agent — without oversizing the project.
How many applications can one review cover?
By taking on the matching, the search for owners and the reconstruction of inheritance paths, the effort moves to the decision. How much is gained depends on your estate and is confirmed by a pilot.
The stages of your AI agent project
Audit & scoping
15 minutes to target the use case with the best return.
Quote or direct sign-up
A catalogue offer is bought online; a specific need gets a costed quote.
Design
We design the agent and its guardrails.
Integration & testing
We connect your tools to the agent, which is itself hosted in France.
Rollout
Going live and training your team.
Operation
Continuous supervision and improvement.
One agent, a scope framed with you
An access-review agent (matching, graph, campaigns, evidence), installed and operated for you. The scope is framed entity by entity — your sources, your applications, your resource owners — and the quote follows that framing.
Four guarantees that matter for your entitlements
Related resources
Your questions, our answers
Does the agent replace our directory or our identity governance tool?
Can it revoke an access automatically?
How does it get our application data?
How does it handle shared accounts?
How does it detect a segregation-of-duties conflict?
What happens if an owner does not answer?
How does it keep our subsidiaries apart?
Does this page prove our compliance with a text?
Other agents for IT
Let us size the potential on your next review campaign
15 minutes to frame your sources, your entities and your owners — hosted in France, supervised, no commitment.