Sphere Partners
IT & SecurityContinuous, Audit-Ready

Access review, continuous. Cited, not just flagged.

A standing review of every access grant across your identity, cloud, and application systems against policy — stale permissions and anomalies surfaced with a citation to the exact entitlement record, instead of a quarterly spreadsheet scramble. Built for IT and security teams carrying access certifications for SOC 2, ISO 27001, or an internal least-privilege standard.

12 cited fields per finding. Built on Sphere AI Foundry.

access_review — cycle #Q3-2026LIVE
00:00Pull grants → Okta, AWS IAM, NetSuite, 4,381 entitlementsread
00:05Policy match → role-to-entitlement mapping vs. least-privilege standardpassed
00:09Dormant account → j.reyes, AWS admin role, 97 days no loginflagged
00:13Orphaned grant → contractor offboarded 41 days ago, Salesforce access activeflagged
00:15Cycle summary → 4,381 reviewed, 23 findings, routed to ownerssealed
review time 15sgrants reviewed 4,381human sign-off required
Built on Sphere AI Foundry·SOC 2 & ISO 27001 aligned·21 years, 300+ clients

Access sprawl outruns the quarterly review

A quarterly access certification means an IT or security analyst exporting entitlement lists from a dozen systems, reconciling them against role definitions and offboarding records in a spreadsheet, then chasing managers for sign-off. By the time the review closes, the access it certified is already a quarter stale — and the grant that mattered, a dormant admin account or an orphaned contractor login, sat exposed the whole time.

89%
faster first-pass review vs. a manual spreadsheet cycle
12
fields extracted & cited per finding
100%
of findings traceable to a source entitlement record

Grant in, cited finding out

Four steps, every one logged and citable back to the source system of record.

01
Ingest

Pulls grants directly from your systems

Identity provider role assignments, cloud IAM policies, and application entitlements — read from Okta, Entra ID, AWS, Azure, GCP, and your IGA platform. No separate export or spreadsheet upload.

Source system
Okta + AWS IAM — Q3 2026 cycle
02
Review against policy

Every grant checked against your access policy

Role-to-entitlement mapping, segregation-of-duties rules, least-privilege standard, offboarding SLA — each grant checked against a policy-mapped review standard, not a generic anomaly score.

Example query
"Does j.reyes's AWS admin role match their current job function and manager-approved request?"
03
Cite every finding

No finding without a citation

Each stale grant, anomaly, or policy exception links back to the exact entitlement record, approval history, and activity log it was evaluated against — the citation travels with the finding.

Cited finding
Orphaned Salesforce access: contractor account active 41 days past offboarding date.
cited to Okta deprovisioning log, ticket OFF-2216
04
Classify & route

One disposition, one routed queue

The agent returns Retain, Revoke, or Escalate for review, with each finding routed to the accountable system owner for sign-off before any access is actually removed.

Disposition
RetainEscalate for review ✓Revoke

12 fields, every one cited

What the agent extracts and produces for every review cycle.

Review summary & disposition
Identity & employment status check
Role-to-entitlement mapping
Segregation-of-duties conflict check
Dormant & stale-access detection
Orphaned & offboarding-lag accounts
Privileged access validation
Approval & justification trail
Consolidated exception list
SOC 2 / ISO 27001 certification report

Typical inputs

What the agent reads, and what it connects to.

Documents

  • Access policy and least-privilege standard
  • Role and entitlement catalog
  • Offboarding and deprovisioning records
  • Prior access certification, where one exists
  • Segregation-of-duties matrix

Systems

  • Identity provider (Okta, Entra ID)
  • Cloud IAM (AWS, Azure, GCP)
  • Identity governance & administration (IGA) platform
  • HRIS for employment and role status
  • SIEM for activity and login telemetry

Is this the right fit?

Built for continuous coverage — not a one-off cleanup.

✓ Works best for

  • IT and security teams running recurring access certifications
  • Organizations standardizing on a fixed, policy-mapped review standard
  • Teams wanting every finding traceable to a source entitlement record

Too small for

  • A single small team a manager can review by hand faster than configuring the agent
  • Replacing security leadership's final revocation decision
  • Environments with no defined roles or policy to review access against

Grounded in your access policy, not a black box

Compliance-first, the same standard every Sphere agent is held to.

The agent flags and routes; it never revokes access on its own. Every disposition sits between the automated policy check and the accountable system owner's sign-off — never past it. A human reviewer confirms every Retain, Revoke, or Escalate before any access is actually removed.

Findings reference your access policy, SOC 2 CC6 controls, and ISO 27001 Annex A entitlement requirements directly — see how the same audit-trail standard applies across regulated deployments in Governed AI for Banks and Private LLM Deployment for Banks and Financial Institutions.

Prerequisites policy on file

A defined access policy and role catalog required before a review cycle can run.

Human review required

A system owner confirms every disposition before access is retained, revoked, or escalated.

Regulatory grounding SOC 2 / ISO 27001

Findings reference SOC 2 CC6 and ISO 27001 Annex A controls directly in every certification report.

Foundation Sphere AI Foundry

Access controls and audit trail configured here carry forward to every other agent you deploy.

Frequently asked

Does the Security & Access Review Agent replace our identity governance team?

No. It replaces the manual first pass of the review — pulling entitlements, checking them against policy, and drafting the findings. A human reviewer still confirms every revocation and every access certification before it's actioned.

What systems can the Security & Access Review Agent pull access grants from?

Identity providers such as Okta and Entra ID, cloud platforms such as AWS IAM, Azure, and GCP, and any application with a role or entitlement model exposed through your IGA platform or SCIM. Additional systems can be added during onboarding.

How does it integrate with our existing IGA or SIEM platform?

It reads directly from your identity governance platform, HRIS, and SIEM — no separate export or spreadsheet upload required. Integration scope is confirmed during deployment planning.

Is every anomaly or stale-access finding traceable to a source record?

Yes. Every flagged grant, orphaned account, and policy exception cites the specific entitlement record, role assignment, and last-activity timestamp it was evaluated against — there is no finding without a citation back to the source.

How is this different from a generic access review or IGA tool?

It is built specifically around a policy-mapped review standard and the fields a SOC 2 or ISO 27001 access recertification needs, not a generic dashboard. It runs on Sphere AI Foundry, so the access controls and audit trail configured here carry forward to other agents you deploy.

Start here

See it on your own access grants

Bring one identity provider and one cloud account to the demo. We'll show the review output live — flagged grants, citations, and the routed exception queue, on your own entitlements.

Looking for a different workflow? Browse the full Agent Catalog.

Talk to a solutions architect

Direct to a senior architect — never a sales queue. Replies within one business day.

By submitting, you agree to be contacted about this request. We never share your details.