PrivAccessCertify
Our own product: an on-premises platform that automates privileged-access recertification: the periodic review that confirms who holds elevated access across your servers, databases and cloud platforms, whether it is still justified, and that anything no longer needed is actually removed.
ILLUSTRATION — CAMPAIGN REVIEW SCREEN
The review it replaces
Most mid-size organizations still run privileged-access reviews by hand: exporting privileged users from each system, merging them into an Excel master list, emailing managers for verification, then routing everything to a General Manager for sign-off.
It works, until an auditor asks you to prove it. Reviews drag on for weeks, spreadsheet versions multiply, and nobody can show that flagged access was ever removed.
| Today, manually | With PrivAccessCertify |
|---|---|
| Per-system exports and scripts | Read-only connectors on a schedule |
| Hand-merged Excel master list | Normalized, identity-linked review items |
| Email chains for verification | Structured decisions in a reviewer inbox |
| GM sign-off on a spreadsheet | Approver summary with a full audit trail |
| “Revoked”, taken on trust | Removal verified on the next sync |
| Evidence scattered across emails | Signed evidence package per campaign |
How it works
A recertification runs through eight stages. Every action is written to a tamper-evident, append-only audit trail.
Onboard
Define each business application, attach its read-only connectors, and set its review chain.Schedule
Build a campaign or let saved templates run it on a recurring cadence.Collect
Connectors gather privileged access read-only; accounts are correlated to identities.Review
Reviewers work a risk-first inbox of plain-language items with structured decisions.Escalate
Reminders and SLA escalation keep the campaign moving; unclear items get routed.Approve
The final approver signs off with exceptions, high-risk revokes and orphans summarized.Remediate
Rejected items become tasks; the next sync verifies each removal.Close
Once blockers clear, the campaign closes and produces a signed evidence package.
What it does
Campaigns & reviews
- ✓Full lifecycle: create, clone, schedule to recur, pause, freeze, abort
- ✓Templates frozen at launch, so a mid-cycle edit can't change a running review
- ✓Five decisions: Approve, Revoke, Exception, Not Mine, Clarify, with justification enforced where it matters
- ✓Plain-language entitlements: “Member of Domain Admins” reads as “Can administer the entire Windows domain”
- ✓Bulk actions with guardrails; amendments keep every version
Identity, remediation & reporting
- ✓Automatic account-to-identity correlation, with orphan detection that blocks closure
- ✓One remediation task per rejected item; reappearance reopens it automatically
- ✓Time-bound exceptions: never indefinite, always carried into the next campaign
- ✓Approver summary: missing justifications, long exceptions, high-risk revokes, orphans
- ✓Eight standard reports, exportable as PDF, CSV, Excel or JSON
Seven platform roles, segregation of duties enforced
Platform Administrator · Campaign Administrator · Reviewer · System Owner · Final Approver · Remediation Operator · Auditor (read-only). No one reviews or approves their own access. On-premises applications carry a frozen L1 Reviewer → L2 Custodian → L3 Business Owner chain; cloud platforms are reviewed as flat subscriptions.
Connectors: 11 source systems, all read-only
Every connector reads access and never changes it, running under a documented minimum-privilege service account. If a sync fails, the last good snapshot is retained.
| Connector | Category | Authentication |
|---|---|---|
| Active Directory | Directory | Kerberos, or LDAP simple bind over LDAPS |
| Azure / Microsoft Entra ID | Cloud identity | OAuth 2.0 client credentials |
| AWS IAM | Cloud identity | IAM role (assume-role) |
| Microsoft SQL Server | Database | SQL login, or Windows-auth domain account |
| Oracle | Database | DB user, or OS-auth domain account |
| PostgreSQL | Database | Username & password |
| MySQL | Database | Username & password |
| MariaDB | Database | Username & password |
| MongoDB | Database | Username & password (SCRAM) over TLS |
| Linux | Server / OS | SSH — password or key |
| Windows Server | Server / OS | WinRM — password or domain account |
Also built in: single sign-on (SAML 2.0 / OIDC), email over your own SMTP, SIEM/syslog export, and SCIM 2.0 / AD sync for platform users. On the roadmap: Microsoft Exchange, GCP IAM, Jira, ServiceNow.
Security, audit & evidence
Encryption
AES-256-GCM envelope encryption at rest; TLS 1.2+ everywhere, with mutual TLS between internal components.Audit trail
Append-only and hash-chained, with server-authoritative UTC timestamps. No role, not even Auditor, can edit or delete it; it streams to your SIEM as the record of truth.Fail-closed
Final approval, closure, credential changes, audit export and break-glass are blocked if the audit trail cannot be written.Signed evidence
Each closed campaign produces one package: SHA-256 checksums, a digital signature verifiable offline, indefinitely.Point-in-time
A campaign certifies access as it stood at launch; later changes never rewrite the certified record.
Deployment & operating model
- ✓On-premises, single deployment per customer, on your infrastructure
- ✓Docker Compose v2 on a single host; Kubernetes optional for larger installs
- ✓Air-gap friendly: signed, cosign-verified images, no phone-home by default
- ✓Backup, DR and RTO/RPO stay under your control, with our guidance and tiered support
What you provide
- ✓A central identity source: Active Directory or Microsoft Entra ID
- ✓Minimum-privilege, read-only service accounts for each connector
- ✓Named owners, custodians and reviewers for the applications in scope
A first campaign typically runs in weeks, not months: the scope is deliberately focused and the deployment deliberately simple.
What PrivAccessCertify is not
We state the boundaries plainly, because our buyers stake audits on them.
Deliberate boundaries
- Not a full IGA suite — no joiner/mover/leaver automation
- Not a PAM product — no credential vaulting or session recording
- Not an access-request or provisioning tool, and not an HR-lifecycle system
- Read-only and ticket-first: it never changes access on a target system: your team makes the change, it verifies it
- Campaign-based reviews, not continuous monitoring
Honest scope notes
- Connector-driven collection only: no CSV or manual import of access data
- Cloud platforms are reviewed as flat subscriptions without the L1/L2/L3 chain
- Dormant-access signals depend on what the source system exposes
- It produces strong evidence for ISO 27001, SOC 2, PCI DSS and SBP ITGC reviews; it does not itself certify compliance
- English-only interface in this release
Available now, and what's next
Everything under “available now” is shipping today. Later stages are roadmap, not promises of dates.
| Stage | Capabilities |
|---|---|
| Available now | Full recertification cycle · 11 read-only connectors · applications and escalation chains · templates and recurring schedules · five-decision reviews with plain-language entitlements · identity correlation and orphan detection · ticket-first remediation with re-sync verification · time-bound exceptions · final approval · SSO, SMTP and SIEM export · SCIM/AD platform-user provisioning · signed evidence packages and append-only audit trail · on-prem Docker Compose deployment |
| MVP-2 roadmap | Exchange and GCP IAM connectors · Jira and SolarWinds connectors · external ITSM (Jira Service Management, ServiceNow) · opt-in controlled direct revocation · continuous privileged-access posture dashboard · Entra PIM eligible-vs-active · AWS unused-access intelligence · custom report builder · deeper compliance control-to-evidence mapping |
| Phase 3 roadmap | HR/HRIS integration and event-triggered reviews · advanced identity correlation and risk-based recommendations · AI-assisted review recommendations |
| Phase 4 roadmap | Hybrid / vendor-hosted SaaS · multi-tenant MSP mode · EU data-residency package · partner connector SDK · executive risk analytics · additional languages |
Prove it on your own systems
A low-risk pilot runs a full campaign on one or two applications within a few weeks.
Scope
Pick one or two applications (say Active Directory plus one database or cloud account) and name the custodian, reviewers and approver.Connect
Provision read-only, minimum-privilege service accounts and configure the connectors.Run
Launch one recertification end to end, including remediation with re-sync verification.Generate evidence
Produce the signed evidence package and review it with internal audit or GRC.Evaluate
Measure effort saved, evidence quality, and whether rejected access reached an outcome.
A pilot is successful when
- One privileged-access campaign is completed in the product
- The evidence package is accepted by your internal audit or GRC owner
- Every rejected item is tracked through remediation or a time-bound exception
- Ownerless (orphan) privileged accounts are 100% flagged
- Your security and GRC stakeholders sign off on the pilot
Replace the spreadsheet before the next audit.
Tell us which systems hold your privileged access, and we will scope a pilot around them.