Access review, continuous. Cited, not just flagged.
A standing review of every access grant across your identity, cloud, and application systems against policy — stale permissions and anomalies surfaced with a citation to the exact entitlement record, instead of a quarterly spreadsheet scramble. Built for IT and security teams carrying access certifications for SOC 2, ISO 27001, or an internal least-privilege standard.
12 cited fields per finding. Built on Sphere AI Foundry.
Access sprawl outruns the quarterly review
A quarterly access certification means an IT or security analyst exporting entitlement lists from a dozen systems, reconciling them against role definitions and offboarding records in a spreadsheet, then chasing managers for sign-off. By the time the review closes, the access it certified is already a quarter stale — and the grant that mattered, a dormant admin account or an orphaned contractor login, sat exposed the whole time.
Grant in, cited finding out
Four steps, every one logged and citable back to the source system of record.
Pulls grants directly from your systems
Identity provider role assignments, cloud IAM policies, and application entitlements — read from Okta, Entra ID, AWS, Azure, GCP, and your IGA platform. No separate export or spreadsheet upload.
Every grant checked against your access policy
Role-to-entitlement mapping, segregation-of-duties rules, least-privilege standard, offboarding SLA — each grant checked against a policy-mapped review standard, not a generic anomaly score.
No finding without a citation
Each stale grant, anomaly, or policy exception links back to the exact entitlement record, approval history, and activity log it was evaluated against — the citation travels with the finding.
One disposition, one routed queue
The agent returns Retain, Revoke, or Escalate for review, with each finding routed to the accountable system owner for sign-off before any access is actually removed.
12 fields, every one cited
What the agent extracts and produces for every review cycle.
Typical inputs
What the agent reads, and what it connects to.
Documents
- Access policy and least-privilege standard
- Role and entitlement catalog
- Offboarding and deprovisioning records
- Prior access certification, where one exists
- Segregation-of-duties matrix
Systems
- Identity provider (Okta, Entra ID)
- Cloud IAM (AWS, Azure, GCP)
- Identity governance & administration (IGA) platform
- HRIS for employment and role status
- SIEM for activity and login telemetry
Is this the right fit?
Built for continuous coverage — not a one-off cleanup.
✓ Works best for
- IT and security teams running recurring access certifications
- Organizations standardizing on a fixed, policy-mapped review standard
- Teams wanting every finding traceable to a source entitlement record
Too small for
- A single small team a manager can review by hand faster than configuring the agent
- Replacing security leadership's final revocation decision
- Environments with no defined roles or policy to review access against
Grounded in your access policy, not a black box
Compliance-first, the same standard every Sphere agent is held to.
The agent flags and routes; it never revokes access on its own. Every disposition sits between the automated policy check and the accountable system owner's sign-off — never past it. A human reviewer confirms every Retain, Revoke, or Escalate before any access is actually removed.
Findings reference your access policy, SOC 2 CC6 controls, and ISO 27001 Annex A entitlement requirements directly — see how the same audit-trail standard applies across regulated deployments in Governed AI for Banks and Private LLM Deployment for Banks and Financial Institutions.
Prerequisites policy on file
A defined access policy and role catalog required before a review cycle can run.
Human review required
A system owner confirms every disposition before access is retained, revoked, or escalated.
Regulatory grounding SOC 2 / ISO 27001
Findings reference SOC 2 CC6 and ISO 27001 Annex A controls directly in every certification report.
Foundation Sphere AI Foundry
Access controls and audit trail configured here carry forward to every other agent you deploy.
Frequently asked
Does the Security & Access Review Agent replace our identity governance team?
No. It replaces the manual first pass of the review — pulling entitlements, checking them against policy, and drafting the findings. A human reviewer still confirms every revocation and every access certification before it's actioned.
What systems can the Security & Access Review Agent pull access grants from?
Identity providers such as Okta and Entra ID, cloud platforms such as AWS IAM, Azure, and GCP, and any application with a role or entitlement model exposed through your IGA platform or SCIM. Additional systems can be added during onboarding.
How does it integrate with our existing IGA or SIEM platform?
It reads directly from your identity governance platform, HRIS, and SIEM — no separate export or spreadsheet upload required. Integration scope is confirmed during deployment planning.
Is every anomaly or stale-access finding traceable to a source record?
Yes. Every flagged grant, orphaned account, and policy exception cites the specific entitlement record, role assignment, and last-activity timestamp it was evaluated against — there is no finding without a citation back to the source.
How is this different from a generic access review or IGA tool?
It is built specifically around a policy-mapped review standard and the fields a SOC 2 or ISO 27001 access recertification needs, not a generic dashboard. It runs on Sphere AI Foundry, so the access controls and audit trail configured here carry forward to other agents you deploy.
See it on your own access grants
Bring one identity provider and one cloud account to the demo. We'll show the review output live — flagged grants, citations, and the routed exception queue, on your own entitlements.
Talk to a solutions architect
Direct to a senior architect — never a sales queue. Replies within one business day.
By submitting, you agree to be contacted about this request. We never share your details.