PrivAccessCertify

Our own product: an on-premises platform that automates privileged-access recertification: the periodic review that confirms who holds elevated access across your servers, databases and cloud platforms, whether it is still justified, and that anything no longer needed is actually removed.

On-premises Read-only collection Ticket-first remediation Audit-ready evidence

ILLUSTRATION — CAMPAIGN REVIEW SCREEN

The review it replaces

Most mid-size organizations still run privileged-access reviews by hand: exporting privileged users from each system, merging them into an Excel master list, emailing managers for verification, then routing everything to a General Manager for sign-off.

It works, until an auditor asks you to prove it. Reviews drag on for weeks, spreadsheet versions multiply, and nobody can show that flagged access was ever removed.

Today, manuallyWith PrivAccessCertify
Per-system exports and scriptsRead-only connectors on a schedule
Hand-merged Excel master listNormalized, identity-linked review items
Email chains for verificationStructured decisions in a reviewer inbox
GM sign-off on a spreadsheetApprover summary with a full audit trail
“Revoked”, taken on trustRemoval verified on the next sync
Evidence scattered across emailsSigned evidence package per campaign

How it works

A recertification runs through eight stages. Every action is written to a tamper-evident, append-only audit trail.

  1. Onboard

    Define each business application, attach its read-only connectors, and set its review chain.
  2. Schedule

    Build a campaign or let saved templates run it on a recurring cadence.
  3. Collect

    Connectors gather privileged access read-only; accounts are correlated to identities.
  4. Review

    Reviewers work a risk-first inbox of plain-language items with structured decisions.
  5. Escalate

    Reminders and SLA escalation keep the campaign moving; unclear items get routed.
  6. Approve

    The final approver signs off with exceptions, high-risk revokes and orphans summarized.
  7. Remediate

    Rejected items become tasks; the next sync verifies each removal.
  8. Close

    Once blockers clear, the campaign closes and produces a signed evidence package.

What it does

Campaigns & reviews

  • Full lifecycle: create, clone, schedule to recur, pause, freeze, abort
  • Templates frozen at launch, so a mid-cycle edit can't change a running review
  • Five decisions: Approve, Revoke, Exception, Not Mine, Clarify, with justification enforced where it matters
  • Plain-language entitlements: “Member of Domain Admins” reads as “Can administer the entire Windows domain”
  • Bulk actions with guardrails; amendments keep every version

Identity, remediation & reporting

  • Automatic account-to-identity correlation, with orphan detection that blocks closure
  • One remediation task per rejected item; reappearance reopens it automatically
  • Time-bound exceptions: never indefinite, always carried into the next campaign
  • Approver summary: missing justifications, long exceptions, high-risk revokes, orphans
  • Eight standard reports, exportable as PDF, CSV, Excel or JSON

Seven platform roles, segregation of duties enforced

Platform Administrator · Campaign Administrator · Reviewer · System Owner · Final Approver · Remediation Operator · Auditor (read-only). No one reviews or approves their own access. On-premises applications carry a frozen L1 Reviewer → L2 Custodian → L3 Business Owner chain; cloud platforms are reviewed as flat subscriptions.

Connectors: 11 source systems, all read-only

Every connector reads access and never changes it, running under a documented minimum-privilege service account. If a sync fails, the last good snapshot is retained.

ConnectorCategoryAuthentication
Active DirectoryDirectoryKerberos, or LDAP simple bind over LDAPS
Azure / Microsoft Entra IDCloud identityOAuth 2.0 client credentials
AWS IAMCloud identityIAM role (assume-role)
Microsoft SQL ServerDatabaseSQL login, or Windows-auth domain account
OracleDatabaseDB user, or OS-auth domain account
PostgreSQLDatabaseUsername & password
MySQLDatabaseUsername & password
MariaDBDatabaseUsername & password
MongoDBDatabaseUsername & password (SCRAM) over TLS
LinuxServer / OSSSH — password or key
Windows ServerServer / OSWinRM — password or domain account

Also built in: single sign-on (SAML 2.0 / OIDC), email over your own SMTP, SIEM/syslog export, and SCIM 2.0 / AD sync for platform users. On the roadmap: Microsoft Exchange, GCP IAM, Jira, ServiceNow.

Security, audit & evidence

  1. Encryption

    AES-256-GCM envelope encryption at rest; TLS 1.2+ everywhere, with mutual TLS between internal components.
  2. Audit trail

    Append-only and hash-chained, with server-authoritative UTC timestamps. No role, not even Auditor, can edit or delete it; it streams to your SIEM as the record of truth.
  3. Fail-closed

    Final approval, closure, credential changes, audit export and break-glass are blocked if the audit trail cannot be written.
  4. Signed evidence

    Each closed campaign produces one package: SHA-256 checksums, a digital signature verifiable offline, indefinitely.
  5. Point-in-time

    A campaign certifies access as it stood at launch; later changes never rewrite the certified record.

Deployment & operating model

  • On-premises, single deployment per customer, on your infrastructure
  • Docker Compose v2 on a single host; Kubernetes optional for larger installs
  • Air-gap friendly: signed, cosign-verified images, no phone-home by default
  • Backup, DR and RTO/RPO stay under your control, with our guidance and tiered support

What you provide

  • A central identity source: Active Directory or Microsoft Entra ID
  • Minimum-privilege, read-only service accounts for each connector
  • Named owners, custodians and reviewers for the applications in scope

A first campaign typically runs in weeks, not months: the scope is deliberately focused and the deployment deliberately simple.

What PrivAccessCertify is not

We state the boundaries plainly, because our buyers stake audits on them.

Deliberate boundaries

  • Not a full IGA suite — no joiner/mover/leaver automation
  • Not a PAM product — no credential vaulting or session recording
  • Not an access-request or provisioning tool, and not an HR-lifecycle system
  • Read-only and ticket-first: it never changes access on a target system: your team makes the change, it verifies it
  • Campaign-based reviews, not continuous monitoring

Honest scope notes

  • Connector-driven collection only: no CSV or manual import of access data
  • Cloud platforms are reviewed as flat subscriptions without the L1/L2/L3 chain
  • Dormant-access signals depend on what the source system exposes
  • It produces strong evidence for ISO 27001, SOC 2, PCI DSS and SBP ITGC reviews; it does not itself certify compliance
  • English-only interface in this release

Available now, and what's next

Everything under “available now” is shipping today. Later stages are roadmap, not promises of dates.

StageCapabilities
Available now Full recertification cycle · 11 read-only connectors · applications and escalation chains · templates and recurring schedules · five-decision reviews with plain-language entitlements · identity correlation and orphan detection · ticket-first remediation with re-sync verification · time-bound exceptions · final approval · SSO, SMTP and SIEM export · SCIM/AD platform-user provisioning · signed evidence packages and append-only audit trail · on-prem Docker Compose deployment
MVP-2 roadmap Exchange and GCP IAM connectors · Jira and SolarWinds connectors · external ITSM (Jira Service Management, ServiceNow) · opt-in controlled direct revocation · continuous privileged-access posture dashboard · Entra PIM eligible-vs-active · AWS unused-access intelligence · custom report builder · deeper compliance control-to-evidence mapping
Phase 3 roadmap HR/HRIS integration and event-triggered reviews · advanced identity correlation and risk-based recommendations · AI-assisted review recommendations
Phase 4 roadmap Hybrid / vendor-hosted SaaS · multi-tenant MSP mode · EU data-residency package · partner connector SDK · executive risk analytics · additional languages

Prove it on your own systems

A low-risk pilot runs a full campaign on one or two applications within a few weeks.

  1. Scope

    Pick one or two applications (say Active Directory plus one database or cloud account) and name the custodian, reviewers and approver.
  2. Connect

    Provision read-only, minimum-privilege service accounts and configure the connectors.
  3. Run

    Launch one recertification end to end, including remediation with re-sync verification.
  4. Generate evidence

    Produce the signed evidence package and review it with internal audit or GRC.
  5. Evaluate

    Measure effort saved, evidence quality, and whether rejected access reached an outcome.

A pilot is successful when

  • One privileged-access campaign is completed in the product
  • The evidence package is accepted by your internal audit or GRC owner
  • Every rejected item is tracked through remediation or a time-bound exception
  • Ownerless (orphan) privileged accounts are 100% flagged
  • Your security and GRC stakeholders sign off on the pilot

Replace the spreadsheet before the next audit.

Tell us which systems hold your privileged access, and we will scope a pilot around them.