Solutions

A single link, an email domain verification, and a form: anyone can request access for themselves, a colleague, or a vendor —without an IT ticket.
Each request is time-stamped, assigned, approved, or rejected with a reason.
Open and closed requests are sorted by status: your backlog remains easy to read.
Assign a review frequency to each user type —employee, contractor, technical account — and receive a reminder when recertification is due. Even outside the HRIS.
A process that ensures compliance when granting internal access
Your internal requesters act as authorized intermediaries for any access request, whether it is from an employee, a contractor, or simply a request on their own behalf.
Ensure that no sensitive assets in your organisation are put at risk.
During a cyber insurance audit or questionnaire, export your access decision history with just a few clicks.
GA (Identity Governance and Administration) helps organizations manage and oversee identities and access rights. It answers three key questions: who has access to what, why, and for how long? It covers granting, reviewing, and removing access when someone leaves or changes roles. The goal is to give each person the access they need to do their job and maintain a clear record of access decisions.
IAM (Identity and Access Management) encompasses the practices and tools used to manage digital identities and access, including authentication, single sign-on (SSO), and authorization. IGA is the governance component of IAM: it helps determine which access is appropriate, who should approve it, and when it should be removed. For example, SSO lets an employee sign in to an application; IGA helps verify that their access is still justified after a role change.
An access review checks whether assigned access rights are still needed. Start by defining which applications and users to include, then build an up-to-date inventory of their permissions. Managers or application owners decide which access to retain, modify, or remove. Set a deadline, document decisions, and verify that removals have been completed. Repeat reviews at a frequency that reflects the sensitivity of the access and your organization’s risks.
Managing SaaS access goes beyond employees listed in the HR system. Contractors, freelancers, interns, consultants, and temporary accounts are often excluded from standard onboarding and offboarding processes, increasing the risk of forgotten accounts.
To reduce this risk, organizations should define access review schedules based on each user category. MIA allows administrators to assign review frequencies to different member types (employees, contractors, partners, service accounts, and more) and automatically send reminders when access reviews are due. This helps identify unnecessary accounts, dormant access, and users who should no longer retain certain permissions.
Contractors can be tracked in a dedicated register even if they are not listed in your Human Resources Information System (HRIS). For each contractor, record an internal sponsor, the access they need, and their assignment’s start and end dates. Require approval for access requests, set access expiry dates, and require explicit approval for extensions. Regular reviews and verified access removal at the end of each assignment help prevent forgotten accounts.
The evidence required depends on the audit framework and scope. It typically includes a dated inventory of accounts and permissions, access requests and approvals, access review results, and records of permission changes or removals. Auditors want to understand who approved what, when, and why, and verify that those decisions were implemented. An access removal request should therefore be accompanied by evidence that the access was actually revoked.