+33 (0)1 87 66 00 65 · Monday to Friday, 9am–6pm Free audit (15 min)
This agent is priced on quotation. This agent is available, and its capabilities really are the ones described below. Its price depends on your estate: how many systems are covered, the volume handled, the connections to open and the service level expected. We therefore price it on quotation, after scoping your need — and the quotation commits the scope. If you already run an agent covering part of this scope, that part is not charged again: only the real extension is priced. Request a quote
● B2B offer — Identities & entitlements

IAM and access reviews: who can access what, why, and the gap to close

An entitlement review happens in a spreadsheet, once a year, on the applications there is time to look at. Your agent works on the extracts you deposit: it links accounts to people, exposes the inheritance path of every right, names the gaps with the rule behind them and drafts the change order. Hosted in France: your entitlement graph, which says where your keys are, does not leave the company. Removing an access stays a human decision, taken by the resource owner and recorded.

Hosted in France Entitlement graph protected GDPR & AI Act: governed deployment Human oversight

Updated on

Deployed in a few weeks
IAM & access reviews · hosted in France
Where does our annual entitlement review stand?
On the extracts deposited, every account is linked to a person or to a bearing service, and every right shows its inheritance path and its owner.
Gaps are ranked by reach, with the rule, its version and the values observed.
An account the data cannot settle is marked undetermined, never compliant.
🔗 Sourced · deposited extracts, each with its date and age
Can it remove the access of people who have left?
The change order is drafted, complete and replayable: account, right, reason, rule, owner, expected effect.
Removing an access can interrupt an activity or erase a trace an investigation needs: the decision belongs to the resource owner, and the effect is only declared obtained after the next extract has been read back.
✎ Framework · order prepared, decision and execution human
Local inference · no data outside the EU
Entitlement graph hosted in France
Sovereign by designLocal inference or hosting in France
GDPR & AI Act: governed deploymentTraceability & human oversight
TurnkeyDesigned, installed and operated for you
The owner decidesThe agent prepares, it never revokes
✦ In brief

A Blue Lemon Agent access-review agent, working on the extracts you deposit: it links accounts to people, exposes the inheritance path of every right and its owner, names the gaps with the rule and its version, and drafts the change order for your operator. No access is removed by the agent; no direct connection to a directory or an identity provider is sold here. It runs on local inference or is hosted in France: your entitlement graph stays with you, architecture designed to reduce exposure to extraterritorial legislation, location alone not guaranteeing immunity.

100 %
hosted in France in the target architecture
0
transfer outside the EU in the target architecture
12
access-review modules included in the core offer
0
access removed without a human decision

Reference points describing our offer, not results measured at a client. How much is gained on your number of accounts, applications and owners is confirmed by a pilot.

The context

What does an AI agent bring to your entitlement review?

A right whose inheritance path and owner are visible is settled in a minute; a spreadsheet of raw accounts is copied out for weeks.

! The challenge

The French data protection authority recommends a regular review of entitlements, at least once a year, and the removal of permissions as soon as a person is no longer entitled (CNIL, “Sécurité : gérer les habilitations”, published 13/03/2024). What jams is not the decision: it is linking thousands of accounts to people, finding who is accountable for each application and reconstructing where a right comes from. That work is systematic, and it can be prepared.

Our answer

Your resource owners receive batches already worked through: the account, the person, the path of the right, the rule questioning it and the values observed. They decide, and their reasoned decision is kept with its date and its author. Silence never amounts to certification, and an account the data cannot settle is marked undetermined. Local inference or an isolated resource hosted in France: the graph describing your accesses, and therefore your entry points, does not leave the company.

The decisive point

Your entitlement graph: sovereignty & confidentiality

The list of your privileged accounts says where your keys are. Its confidentiality is a security matter in itself; here is how it is held.

Local inference

The agent can run on a machine of your own organisation: no directory extract and no entitlement graph leaves the network.

Hosting in France

Otherwise, a dedicated and isolated resource hosted in France, under French law — your extracts and your review decisions: processing and access operated in the European Union targeted by the architecture.

Reduced extraterritorial exposure

For your entitlement graph and your privileged accounts, the architecture aims to reduce exposure to the Cloud Act and FISA 702; location in France or in the European Union alone does not guarantee immunity.

Entities kept apart

Each subsidiary, entity or site has its own space: a review batch never shows another entity's accounts, and roles follow that separation.

Decisions preserved

Every decision keeps its author, its date, its reason and the version of the rule applied; encryption, role-based access (RBAC) and logging usable in a control.

AI Act: governed deployment

The agent is strictly in support; no account disabled, no right removed and no campaign closed automatically; traceability and human oversight throughout.

What depends on the architecture chosen These points are not general guarantees: they are settled deployment by deployment, in the quotation.

  • The applicable location is that of the architecture set out in the quotation and verified before commissioning.
  • Local execution is announced only for the configuration explicitly described and accepted in the quotation.
  • The applicable isolation depends on the deployment mode set out in the quotation; no dedicated isolation is presumed.
  • Roles and permissions are configured and accepted for the identities and systems actually connected.
  • The events logged, their content, their retention period and who may access them are defined for the deployment chosen.
For entities under a sector regime — financial services, essential or important entities — SecNumCloud and reinforced hosting options are available according to your level of requirement. Whether a text applies is checked entity by entity, and this page is neither a finding nor a guarantee of it.
Demonstration

See the agent at work

5 real situations, taken from those that come up most often. Pick one: the exchange unfolds as it would in your organisation.

A scripted demonstration. These exchanges show how the agent behaves — its sources, its refusals, what it leaves to your teams. Nothing is sent from this page, no model is queried here, and the matters named are fictional. That is precisely what we promise your data.
The behaviours shown here — monitoring, automation rules, routing and reminders — are configured with you during deployment, from your tools, your rules and your thresholds.
The architecture points named in these exchanges — location, local execution, isolation, encryption, role-based access, logging — are not a guarantee attached to the demonstration: they are those of the architecture set out in your quotation, and verified before commissioning.

The company in this demonstration

Fictional company

Vallonis Participations — an active holding company, six holdings and one semi-public company

Sector
Activities of holding companies (NAF 64.2) — ownership, steering, shared finance and IT management
Headcount
41 staff at head office, 3 of them in shared IT; 2,340 people across the consolidated scope, no CISO role anywhere
Holdings served
6 subsidiaries and 1 semi-public company: digital services, industry, energy, a clinic held as a stake, two portfolio companies
Order of magnitude
3,180 active accounts, 74 applications listed, 214 accounts with no named owner; one review a year, required by the statutory auditor
Tools in place
A corporate directory and a ticketing tool at head office, one shared finance ERP, four separate application estates in the subsidiaries — the agent reads the EXTRACTS deposited, it connects to none of these tools
Who decides
The group chief financial officer arbitrates removals; the head of internal control runs the instruction and keeps the evidence; each subsidiary director owns their applications; the outsourced operator executes signed orders
Room for improvement
The 2025 review covered 11 applications out of 74 and stopped in April for want of identified owners; 214 accounts have nobody accountable, and 38 leavers' accounts were still active at extraction time

Vallonis Participations has to prove to its statutory auditor every year that access across its consolidated scope is reviewed. The difficulty is not the decision: it is that the holding owns none of these accounts, that its six holdings share neither a directory nor a vocabulary, and that no security role decides in their place. The agent runs on local inference on a machine at head office and reads the extracts each subsidiary deposits, with their date. It links, explains, names the gaps and drafts the orders; the chief financial officer decides, each subsidiary director answers for their applications, and the outsourced operator executes. The five tabs are the five perimeters of the 2026 campaign, from the first triage to the file handed to the auditor.

This company, its figures and the exchanges that follow were invented for the demonstration. They illustrate a common situation; they describe no real client.

IAM & access reviews · hosted in France
The 2026 campaign is open on the first perimeter: Sillage Numérique, your digital services subsidiary. 412 accounts deposited on 2 September, 409 linked to a person or to a bearing service, 3 left undetermined.
Linking an account means establishing who answers for it: a person on the personnel file, or a technical service with a named bearer. A match on a name alone is not enough — two namesakes exist across your consolidated scope.
What the 2 September extract carries, and its age: subsidiary directory — 6 hours; head office personnel file — 31 hours; last sign-in log — 6 hours. All below the 72-hour threshold you set.
The batch's input document is attached: the extract exactly as I received it, untouched, with the fingerprint of the deposited file. Everything below is derived from it, and you can replay any figure against it.
The four open cases all come from the same cycle — joiners, movers and leavers —, and that is where the gaps appear, never anywhere else:
· PME-01 — an application account still active sixteen days after a departure. Contract ended on 17 August on the personnel file, account open and used on 29 August. Change requested, priority 1.
· PME-04 — an administration account shared between three people. Three separate workstations sign in over thirty days. No action taken from that account is attributable to anyone: I cannot certify it, so I open a dated exception, priority 1.
· PME-02 — a guest account inactive for 190 days, owner identified: the project director who requested it. Eligible for review, priority 2.
· PME-03 — a joiner on 1 September. I propose the baseline rights of her population, and nothing else: the eight rights shared by the eleven people in the same job, never those of a colleague taken as a template. Review assigned, priority 4.
What I suggest next: open case PME-01, see where the right comes from, and judge whether the order I drafted is the one you would have written. deposited-extract_sillage-numerique.csvInput document · 412 rows received, untouched review-batch_sillage-numerique.pdf412 accounts, 4 cases opened, 3 undetermined
⛓ Sourced · extracts deposited 02/09 (directory 6 h, personnel file 31 h, sign-ins 6 h)
The leaver's account — do we cut it right away?
The order is written and ready: account, right, reason, rule applied, owner, expected effect, and it replays without double effect. What it is waiting for is your signature — not mine.
Why I do not take it in your place, and this is not a formality: that account still carries the scheduling of two nightly billing jobs and owns eleven shared files. Cutting it tonight stops tomorrow morning's billing. This is exactly the kind of effect an automatic revocation does not see.
What I prepared so the cut has no consequence, and it is the work nobody has time for:
· the two jobs rescheduled under the service account svc-factu-nuit, named bearer, with the switch-over window;
· the eleven files transferred to the project director, list attached;
· the removal order, to be handed to your operator, with the effective date you choose. That is what controlled remediation means: a replayable order, a chosen date, and the effect checked on the source before it is declared obtained.
The framework: the French data protection authority recommends removing permissions as soon as a person is no longer entitled (“Sécurité : gérer les habilitations”, published 13/03/2024). It recommends doing it, it does not say to do it blind: sixteen days of delay are caught up with one signature, a stopped billing run takes a week.
What I do after you sign: I wait for the next extract and read the account back. Until the source shows it closed, the effect is not declared obtained — an order sent is not an order applied. change-order_PME-01.pdfRemoval prepared, dependencies handled, effect to be confirmed
✎ Framework · order drafted, decision with the owner, effect confirmed on the source
And the 214 accounts with no owner we have been talking about for two years?
On this perimeter there are 61 of them. I have proposed an owner for 47, and I tell you what I base it on — you correct what is wrong.
The method, and it guesses nothing: for each application without an accountable person, I look at who requested the access in your tickets, who approved it, and which department the sign-ins come from. When the three agree, I propose; when they diverge, I say so.
· 34 applications: all three indications agree. Proposal made, to be confirmed with one click by the subsidiary director.
· 13 applications: two indications out of three. Proposal made, with the disagreement shown — management control approves, but the sign-ins come from operations.
· 14 applications: nothing agrees. I propose nobody. One of those fourteen has had no sign-in for 400 days: the real question is not who answers for it, but whether it should still exist.
The figure that does not flatter me, and I publish it: of the 47 proposals, your internal control rejected 6 in the dry run — all of them applications taken over in a 2023 acquisition, where the original tickets belong to a company that no longer exists. 13 % of my proposals were wrong on that subset, and none anywhere else. So I added a rule: an application inherited from an acquisition predating its takeover no longer gets an automatic proposal, it goes straight to the subsidiary director.
What I suggest next: move to the industrial perimeter, where the subject is no longer the owner but the combination of rights. proposed-owners_61-applications.pdf47 proposals, 14 abstentions, 6 rejected in the dry run
⛓ Sourced · 3,400 access tickets, 12 months of sign-in logs, approval history
Local inference · no data outside the EU

Your case is not here? That is exactly what a 15-minute conversation is for. Book the free audit

Use cases

What does the agent actually do?

Twelve review modules included in the core offer, from listing the sources to the evidence file, plus the sovereign-AI foundation they run on. All of them work in support, under your validation.

Included in your agent The 13 capabilities essential to this promise are included, at no extra cost.

Inventory of identity sources

Lists the extracts you deposit — directory, payroll, applications, technical accounts — each with its date and its age at review time.

Identity resolution

Links an account to a person or to a bearing service, on strong identifiers. A match based on a name alone is left for you to confirm.

Joiners, movers and leavers

Compares the personnel file movements with the rights observed, and prepares the creations, changes and removals that follow.

Entitlement graph

Shows, for each right, its inheritance path: the person, the group, the role, the resource and the owner accountable for it.

Catalogue of rights and their owners

Versions roles, rights, justification, criticality, duration and resource owner — and flags those with nobody accountable.

Baseline roles by population

Proposes a baseline set of rights per job family from rules you approve. No entitlement is inferred from a mere resemblance between accounts.

Segregation of duties

Detects incompatible combinations of rights from your matrix, with the rule, its version, the context and the dated exception where there is one.

Accounts at risk

Spots orphaned, dormant, shared, expired and unowned accounts, and technical accounts open to interactive sign-in.

Recertification campaigns

Distributes batches to owners, collects the reasoned decision, chases late reviewers and keeps the evidence of every answer.

Privileges and time-bound access

Prepares time-limited elevations, the approvals required, emergency access and the review that follows its use.

Controlled remediation

Drafts the change order for your operator, replayable without double effect, then waits for the next extract to confirm the effect obtained.

Evidence and steering

Logs source, decision, campaign, exception, action, acknowledgement and delay — the file an internal control or a statutory auditor asks for.

Sovereign AI

The hosting and confidentiality foundation the agent runs on.

Controls and safeguards These 4 controls are built into the agent: they frame what it does, whatever plan you pick. They are not chosen and are not added to your order.
Human validation, exceptions and escalation Status, safe closure and audit trail Access the technical context with least-privilege permissions Version, log, roll back and measure quality
The gain

How many applications can one review cover?

By taking on the matching, the search for owners and the reconstruction of inheritance paths, the effort moves to the decision. How much is gained depends on your estate and is confirmed by a pilot.

Matching accounts and people
Today · done by hand
Accounts linked, gaps named
Finding the owner of an application
Today · done by hand
Owner proposed, to be confirmed
Building the evidence file
Today · done by hand
File built as decisions come in
Illustrative, non-contractual reference points, to be confirmed by a pilot on your number of accounts, applications and owners. Removing an access can interrupt an activity or erase a useful trace: that decision belongs to the resource owner, and its execution to your operator.
How it works

The stages of your AI agent project

1

Audit & scoping

15 minutes to target the use case with the best return.

2

Quote or direct sign-up

A catalogue offer is bought online; a specific need gets a costed quote.

3

Design

We design the agent and its guardrails.

4

Integration & testing

We connect your tools to the agent, which is itself hosted in France.

5

Rollout

Going live and training your team.

6

Operation

Continuous supervision and improvement.

Quote

One agent, a scope framed with you

An access-review agent (matching, graph, campaigns, evidence), installed and operated for you. The scope is framed entity by entity — your sources, your applications, your resource owners — and the quote follows that framing.

This agent is priced on quotation. This agent is available, and its capabilities really are the ones described below. Its price depends on your estate: how many systems are covered, the volume handled, the connections to open and the service level expected. We therefore price it on quotation, after scoping your need — and the quotation commits the scope. Request a quote
Our commitment

Four guarantees that matter for your entitlements

Your entitlement graph stays with youLocal inference or an isolated resource hosted in France; no extract entrusted to a third party, no data used to train a model.
Data in France, under French lawYour extracts, your graph and your review decisions: minimisation and location in France, architecture designed to reduce exposure to extraterritorial legislation, location alone not guaranteeing immunity.
The owner keeps the decisionThe agent prepares worked-through batches and change orders, verifiable and editable; no revocation, no identity merge and no closure is automated.
Human oversight & traceabilityEvery decision carries its author, its date, its reason and the version of the rule applied; systematic logging and follow-up, compliant with the AI Act.
Frequently asked questions

Your questions, our answers

Does the agent replace our directory or our identity governance tool?
No. The directory remains the source and the authority; the identity governance tool remains the system that executes. The agent prepares the review: it matches, explains, names the gaps and drafts the change order. It holds no account of its own.
Can it revoke an access automatically?
No, and this is not a setting. The agent prepares a complete, replayable change order; the decision belongs to the resource owner and the execution to your operator. The effect is only declared obtained after the next extract has been read back — not on the strength of the order sent.
How does it get our application data?
Through the extracts you deposit, in the format you already produce, with their date. No direct connection to a directory or an identity provider is sold on this page: such a link is handled case by case, after a feasibility study, and is only announced once it is established and documented.
How does it handle shared accounts?
It names them and refuses to certify them as they stand: an action taken from a shared account cannot be attributed to anyone. The CNIL recommends avoiding generic accounts shared between several people (“Gérer les utilisateurs”, published 27/01/2020). The agent opens a dated exception, with a named bearer and a deadline, or prepares the move to named accounts.
How does it detect a segregation-of-duties conflict?
From your versioned matrix of forbidden combinations: it shows the rule applied, its version, the two rights involved, their inheritance path and the compensating control where there is one. It guesses none of your organisation's rules.
What happens if an owner does not answer?
The batch stays open and the agent chases. Silence is never turned into certification: the account remains to be settled, and the absence of an answer is itself recorded, with its date, in the evidence file.
How does it keep our subsidiaries apart?
Each entity has its own space: extracts, review batches, decisions and exceptions stay there. An owner in one subsidiary sees neither the accounts nor the decisions of another, and cross-entity read roles are named and traced.
Does this page prove our compliance with a text?
No. Commission Implementing Regulation (EU) 2024/2690 of 17 October 2024 sets access-control requirements for certain digital entities, and Commission Delegated Regulation (EU) 2024/1774 of 13 March 2024 sets access-rights management requirements for the financial entities covered by DORA. Whether either text applies to you, and on what basis, is checked entity by entity: the agent produces evidence usable in a control, it issues no finding of compliance.
Let's talk

Let us size the potential on your next review campaign

15 minutes to frame your sources, your entities and your owners — hosted in France, supervised, no commitment.