Alphaweb

AI agent · Compliance & risk · Compare period to period

Access review evidence

The software takes each access snapshot, compares it with the last certified review, HR records and your role model, and puts the changes and outliers in front of the manager in plain words. Removals are verified, and the evidence pack assembles itself.

last certifiedaccess today3 grants to confirm, with reasonthe rest unchanged
15,000 entitlements / month · 91% handled by the agent · 9% to a person
Typical volumes for this process, not a client figure.
Today

Managers certify spreadsheets of access codes they barely recognise, once a quarter.

With the agent

Access compared with last period, HR and roles; only changes and outliers go to the manager.

Where the time goes today

For each application in scope, IT exports the list of accounts and entitlements. Compliance or internal control splits it by manager and sends each one a spreadsheet: keep or remove, sign and return. Removal requests become tickets. Exports, sign-offs and tickets are filed in folders for internal and external auditors, who test whether the export was complete, whether the reviews happened on time and whether removals were carried out.

The review often fails at the manager. Entitlement names such as 'GL_POST_ALL_E3' mean nothing to a sales director, so everything is approved. Accounts belonging to people who left months ago stay active because nobody compared the HR leaving date with the account status. Service accounts have no owner. Someone who moved department keeps the old department's access as well as the new.

Much of the effort goes into compiling exports, chasing late managers, matching removals to tickets and assembling evidence. Removals are often marked done when the ticket closes, not when the access has actually gone, and that is where audit findings come from.

How the agent works

  1. Snapshot the accessThe agent extracts accounts and entitlements from each in-scope system and records the query and timestamp as evidence of completeness. It reconciles the record count with the system's own totals.
  2. Compare to last periodIt compares line by line with the previous certified snapshot: new grants, removals and changes. For each new grant it looks for the approved request ticket.
  3. Check HR and rolesAccounts are matched to HR records to find leavers with active access, movers who kept old access and accounts with no person behind them. Entitlements are checked against the role model and your segregation-of-duties conflict list.
  4. Prepare the manager's reviewEach manager receives changes and outliers one by one, described in plain words from your entitlement catalogue, and the unchanged, previously approved access as a single block to confirm.
  5. Verify removalsAfter certification, the agent opens removal tickets through your normal process, then extracts again to confirm the access is gone. The evidence pack is assembled as it goes.

What stays with a person

Managers certify. The agent prepares the review but never certifies on anyone's behalf, and a manager cannot approve exceptions in bulk: each needs an individual decision and a reason. System owners decide how to handle a segregation-of-duties conflict and whether a compensating control is acceptable.

Your security team decides what to do about an orphaned administrator account found mid-cycle, and your auditors decide whether the evidence is sufficient. Removing access goes through your normal provisioning process, because removing the wrong access can stop someone working, and that process already has an owner.

What it reads, what it produces

It readsIt produces
Account and entitlement exports from each in-scope application and directoryA review pack per manager, with changes and outliers described in plain words
HR joiner, mover and leaver recordsAn exceptions list: leavers, orphaned accounts, conflicts, grants with no approval
Access request tickets and approvalsRemoval tickets, and confirmation from a later extraction
The role model and entitlement catalogueAn evidence pack with queries, timestamps, counts and sign-offs
Your segregation-of-duties conflict list
The previous certified review

Controls that come with it

How you know it works

Is your process ready?

The five candidacy checks are explained, with an exam, in the free Module 01.

What goes wrong

Questions we get

Does the agent certify access?

No. Certification is a manager's attestation and has to remain one. The agent prepares what the manager needs to make it meaningful: which access changed, why it looks unusual and what the entitlement actually allows, in plain words. It records the manager's decision, the time and the reason for each exception, and then follows through on removals.

Will our auditors accept the evidence?

Ask them early, with a sample pack from a pilot cycle. The pack is built around four questions an auditor can ask of an access review: completeness of the extraction, with query and counts; timeliness of certification; the decision and reason for each exception; and proof that removals happened, taken from a later extraction rather than from ticket status. Your auditors decide whether that is sufficient.

What about applications without an interface?

They stay in scope. Where an application offers a scheduled report, the agent reads the file. Where there is only a screen, the extraction becomes a documented manual step: someone exports or captures the list, and the agent records who did it and when. Leaving them out creates a gap in the evidence that an auditor can find.

Our identity management tool already runs review campaigns. Why add this?

If the tool covers every in-scope application, has a good entitlement catalogue and links to HR and ticketing, keep using it. The agent helps where coverage stops: applications outside the tool, comparisons with HR and tickets done in spreadsheets, and evidence assembled by hand before each audit. It can feed its findings into your existing campaigns.

Want this agent on your process?

Tell us about your version of this process — volumes, systems, what goes wrong. A person answers with an approach and a price, usually within two working days, or tells you it is the wrong project.