0x01
Access reviews nobody reads
Campaigns land in managers' inboxes as endless lists of entitlement codes. Everything gets approved, because reading it is impossible.
[ Agentic IGA ]
AI agents that review access, chase approvals and close audit findings — on top of the identity platform you already run, supervised by senior IGA consultants in Belgium.
Identity Security. Agent-driven.
status: operational
[01]
Most organisations bought an IGA platform years ago. The tooling is in place. The governance still is not.
0x01
Campaigns land in managers' inboxes as endless lists of entitlement codes. Everything gets approved, because reading it is impossible.
0x02
Movers keep what they had and gain what they need. Access accumulates for years, and nobody can say who should still have what.
0x03
Evidence is rebuilt by hand each cycle. The finding is closed, the cause is not, and it returns at the next audit.
[02]
We do not replace your IGA or IAM platform. We add a reasoning and automation layer above it, connected through the APIs you already own. Nothing to rip out, no second source of truth.
L01Conversational access
L02INCORP Agentic layer
activeL03Your existing platforms
Vendor-neutral. We work with the platform you have, not the one we prefer.
[03]
Six governance agents, each with a narrow job, a full audit trail aligned with ISO/IEC 42001, and a clear line where a human still decides.
agent/01
Turns a campaign into a short list. It groups entitlements into plain language, flags what changed since the last review and proposes a decision for each line.
The human decides
Approvals, revocations and any exception on privileged access.
agent/02
Watches the HR feed, derives what a role should have, and opens the requests and revocations a move implies instead of waiting for a ticket.
The human decides
Confirmation of role changes and anything outside the birthright model.
agent/03
Finds the roles hidden in the entitlements you actually granted, and surfaces segregation-of-duties conflicts before an auditor does.
The human decides
Role definitions, ownership and accepted risks.
agent/04
Assembles evidence continuously — who approved what, when, and on what basis — so a control review is a query, not a project.
The human decides
Sign-off and the response to the auditor.
agent/05
Keeps a live picture of the estate: coverage, orphaned accounts, review progress, SoD exposure and agent activity, explained in sentences rather than raw counters.
The human decides
Which indicators matter and what an acceptable threshold is.
agent/06
Brings a new application under governance: discovers its entitlements, proposes owners, roles and review cadence, and drafts the connector and policy configuration.
The human decides
Ownership, the final role model and go-live approval.
[04]
An AI assistant as the front door to identity services. Managers, the service desk and auditors ask in their own words and get an answer grounded in the graph — with the underlying data as the source, not a guess.
Built for
Illustrative example of the conversational layer.
[05]
A person — or an AI agent — holds one or more contexts, and every context has its own identity. Identity is the centre of gravity: roles and accounts hang off it, entitlements connect roles to accounts, and applications attach to accounts. No shortcut edges, so every answer follows a real path instead of a spreadsheet guess.
[06]
Your organisation is deploying AI agents. Each one runs on an identity: a service account, a token, a set of permissions nobody reviews. Non-human identities already outnumber people, and AI agents make that gap grow faster than any joiner process.
Every agent identity has a named human owner and a business justification, or it does not get created.
Entitlements scoped to what the agent actually calls, derived from observed behaviour rather than a hopeful guess.
Credentials and permissions carry an end date. Renewal is a decision, not the absence of one.
When an agent is decommissioned, its access disappears everywhere — and the evidence that it did is kept.
Agent identities are governed against the AI management controls of ISO/IEC 42001: accountability, oversight, traceability and lifecycle review.
[07]
We read from your IGA platform, directory, HR source and key applications through their APIs. Read-only first, always.
The graph is built, the agents run against your policies, and findings appear with the reasoning attached.
Humans approve, reject and set exceptions. The agents execute in your existing platform and keep the evidence.
[08]
A worked example, not a promise. We model the recurring identity workload of a mid-sized European organisation, then apply the share each agent can take over. Pick a size to see the numbers move.
| Workload | Today | With agents | Handled by agents | Saved / year |
|---|---|---|---|---|
| Joiners, movers, leavers720 events per 1,000 employees per year · 35 min each | 1,050 h | 315 h | 70% | €55,125 |
| Access requests & approvals2,400 requests per 1,000 employees per year · 12 min each | 1,200 h | 480 h | 60% | €54,000 |
| Access reviews & recertification3,600 review items per 1,000 employees per year · 3 min each | 450 h | 113 h | 75% | €25,313 |
| Access-related service desk1,680 tickets per 1,000 employees per year · 9 min each | 630 h | 284 h | 55% | €25,988 |
| Audit evidence & reporting96 evidence requests per 1,000 employees per year · 60 min each | 240 h | 48 h | 80% | €14,400 |
| Total | 3,570 h | 1,239 h | 65% | €174,825 |
Illustrative model based on public benchmarks and our own project experience — not a measured result from a named client. Give us your real volumes and we rebuild it with your numbers during the assessment.
[09]
A Belgian company of senior IAM and IGA consultants who deliver the work themselves.
The people who scope your programme are the people who build it. No pyramid, no handover to juniors.
Identity governance is what we do all day — not a practice line inside a general IT consultancy.
We have no license to resell. The right answer is the one that fits your estate.
On site when it matters, in your language, in your regulatory context.
Our agents are built and operated along ISO/IEC 42001, the AI management system standard: documented purpose, human oversight, logging and periodic review.
[10]
Three entry points, from a first look to a governed estate.
A short, focused review of where your identity governance actually stands.
One agent, one scope, in your environment — proof before commitment.
The layer, the agents and the expertise, run continuously alongside your team.
[11]
Tell us what you are running and where it hurts. A 30-minute conversation with a senior consultant, no sales pitch.