Pillar two

Identity that fits the directory you already operate.

Authentication, group membership, lifecycle, and offboarding stay where your auditors expect them — in your identity provider. The platform consumes the signal and enforces the consequence on every session.

A user who leaves your directory leaves your network the same minute.

In depth

What the identity layer actually does.

No second directory. No duplicate accounts. The platform reads from your authoritative source and binds every session to a current identity record.

Single sign-on

Microsoft Entra ID, Okta, Google Workspace, Ping Identity, and any standards-compliant SAML or OpenID Connect provider.

Strong second factors

Passkeys and authenticator apps enrolled through the platform. Backup codes generated and rotated.

Lifecycle automation

Users and groups arrive and depart by directory event. A leaver loses access on the deprovisioning event, not on the next access review.

Role and permission model

Built-in roles for the common shapes — administrator, operator, viewer — plus fully bespoke roles where the organisation has a specific need.

Time-bound invitations

Single-use invitation links for contractors, counsel, and external collaborators. Links expire on schedule with no admin action required.

Just-in-time elevation

Privileged actions request access, log the request, and time out automatically. There is no standing administrator access.

Per-tenant identity providers

Each tenant binds its own identity provider. A multi-organisation deployment does not commingle authentication paths.

Continuous re-evaluation

Group membership and entitlement changes propagate to live sessions immediately, not at the next token refresh.

Bring your identity team. We will walk through the integration with the directory you already operate.