[ Agentic IGA ]

Identity governance that works

AI agents that review access, chase approvals and close audit findings — on top of the identity platform you already run, supervised by senior IGA consultants in Belgium.

Identity Security. Agent-driven.

L01Conversational access
L02INCORP Agentic layer
L03Your existing platforms

status: operational

[01]

Identity governance still runs on spreadsheets

Most organisations bought an IGA platform years ago. The tooling is in place. The governance still is not.

0x01

Access reviews nobody reads

Campaigns land in managers' inboxes as endless lists of entitlement codes. Everything gets approved, because reading it is impossible.

0x02

Joiner-mover-leaver backlogs

Movers keep what they had and gain what they need. Access accumulates for years, and nobody can say who should still have what.

0x03

The same audit findings every year

Evidence is rebuilt by hand each cycle. The finding is closed, the cause is not, and it returns at the next audit.

[02]

A layer on top of what you already run

We do not replace your IGA or IAM platform. We add a reasoning and automation layer above it, connected through the APIs you already own. Nothing to rip out, no second source of truth.

L01Conversational access

  • Managers
  • Service desk
  • Auditors

L02INCORP Agentic layer

  • Governance agents
  • Identity graph
  • Policy & evidence

L03Your existing platforms

  • IGA suite
  • Directory & SSO
  • HR source
  • Applications

Vendor-neutral. We work with the platform you have, not the one we prefer.

[03]

What Agentic IGA actually means

Six governance agents, each with a narrow job, a full audit trail aligned with ISO/IEC 42001, and a clear line where a human still decides.

agent/01

Access Review Agent

Turns a campaign into a short list. It groups entitlements into plain language, flags what changed since the last review and proposes a decision for each line.

The human decides

Approvals, revocations and any exception on privileged access.

agent/02

Joiner-Mover-Leaver Agent

Watches the HR feed, derives what a role should have, and opens the requests and revocations a move implies instead of waiting for a ticket.

The human decides

Confirmation of role changes and anything outside the birthright model.

agent/03

Role Mining & SoD Agent

Finds the roles hidden in the entitlements you actually granted, and surfaces segregation-of-duties conflicts before an auditor does.

The human decides

Role definitions, ownership and accepted risks.

agent/04

Audit Evidence Agent

Assembles evidence continuously — who approved what, when, and on what basis — so a control review is a query, not a project.

The human decides

Sign-off and the response to the auditor.

agent/05

IAM Dashboard Agent

Keeps a live picture of the estate: coverage, orphaned accounts, review progress, SoD exposure and agent activity, explained in sentences rather than raw counters.

The human decides

Which indicators matter and what an acceptable threshold is.

agent/06

App Onboarding Agent

Brings a new application under governance: discovers its entitlements, proposes owners, roles and review cadence, and drafts the connector and policy configuration.

The human decides

Ownership, the final role model and go-live approval.

[04]

Ask your identity estate a question

An AI assistant as the front door to identity services. Managers, the service desk and auditors ask in their own words and get an answer grounded in the graph — with the underlying data as the source, not a guess.

Built for

  • Managers who need to decide, not decode
  • A service desk that answers in seconds
  • Auditors who can self-serve the evidence
identity assistantsession live
Who can approve payments in the finance system?
14 people. 9 through the Finance Approver role, 5 through direct grants — 3 of those have had no activity in 90 days.
Request the standard access for a new treasury analyst.
Drafted 6 entitlements from the treasury birthright model. Two need the application owner's approval — shall I send them?

Illustrative example of the conversational layer.

PersonAI agentContextContextContextIdentityIdentityIdentityRoleEntitlementRoleAccountAccountAccountApplication

[05]

The identity graph underneath

A person — or an AI agent — holds one or more contexts, and every context has its own identity. Identity is the centre of gravity: roles and accounts hang off it, entitlements connect roles to accounts, and applications attach to accounts. No shortcut edges, so every answer follows a real path instead of a spreadsheet guess.

Blast radius
See what one compromised account actually reaches, across applications and nested groups.
Toxic combinations
Detect segregation-of-duties conflicts that only exist through a chain of inherited access.
Orphaned access
Find entitlements with no owner, no policy and no recent use — the ones reviews never catch.

[06]

The IGA agents that govern your AI agents

Your organisation is deploying AI agents. Each one runs on an identity: a service account, a token, a set of permissions nobody reviews. Non-human identities already outnumber people, and AI agents make that gap grow faster than any joiner process.

Ownership

Every agent identity has a named human owner and a business justification, or it does not get created.

Least privilege

Entitlements scoped to what the agent actually calls, derived from observed behaviour rather than a hopeful guess.

Expiry by default

Credentials and permissions carry an end date. Renewal is a decision, not the absence of one.

Revocation that works

When an agent is decommissioned, its access disappears everywhere — and the evidence that it did is kept.

ISO/IEC 42001 controls

Agent identities are governed against the AI management controls of ISO/IEC 42001: accountability, oversight, traceability and lifecycle review.

[07]

How an engagement runs

  1. STEP_01

    Connect

    We read from your IGA platform, directory, HR source and key applications through their APIs. Read-only first, always.

  2. STEP_02

    Reason

    The graph is built, the agents run against your policies, and findings appear with the reasoning attached.

  3. STEP_03

    Decide

    Humans approve, reject and set exceptions. The agents execute in your existing platform and keep the evidence.

[08]

What it saves

A worked example, not a promise. We model the recurring identity workload of a mid-sized European organisation, then apply the share each agent can take over. Pick a size to see the numbers move.

Organisation size
employees
€174,825
per year
2,331 h
hours / year
1.5
FTE equivalent
What it saves
WorkloadTodayWith agentsHandled by agentsSaved / year
Joiners, movers, leavers720 events per 1,000 employees per year · 35 min each1,050 h315 h70%€55,125
Access requests & approvals2,400 requests per 1,000 employees per year · 12 min each1,200 h480 h60%€54,000
Access reviews & recertification3,600 review items per 1,000 employees per year · 3 min each450 h113 h75%€25,313
Access-related service desk1,680 tickets per 1,000 employees per year · 9 min each630 h284 h55%€25,988
Audit evidence & reporting96 evidence requests per 1,000 employees per year · 60 min each240 h48 h80%€14,400
Total3,570 h1,239 h65%€174,825

Assumptions behind the model

  • Fully loaded internal cost of €75 per hour.
  • Volumes scale linearly with headcount; a real estate is rarely that tidy.
  • Automation shares reflect what our agents can close end-to-end; everything else still reaches a human, faster and better prepared.
  • Excluded: licence cost, avoided audit findings, and the risk reduction from cutting leaver revocation from days to minutes.
  • 1,600 productive hours per FTE per year.

Illustrative model based on public benchmarks and our own project experience — not a measured result from a named client. Give us your real volumes and we rebuild it with your numbers during the assessment.

[09]

Why INCORP

A Belgian company of senior IAM and IGA consultants who deliver the work themselves.

Senior-only

The people who scope your programme are the people who build it. No pyramid, no handover to juniors.

IGA specialists

Identity governance is what we do all day — not a practice line inside a general IT consultancy.

Vendor-neutral

We have no license to resell. The right answer is the one that fits your estate.

Belgian and close by

On site when it matters, in your language, in your regulatory context.

ISO/IEC 42001 by design

Our agents are built and operated along ISO/IEC 42001, the AI management system standard: documented purpose, human oversight, logging and periodic review.

[10]

Ways to start

Three entry points, from a first look to a governed estate.

Assessment

A short, focused review of where your identity governance actually stands.

  • Maturity and gap analysis
  • Graph built from a data extract
  • Prioritised roadmap

Agentic pilot

One agent, one scope, in your environment — proof before commitment.

  • Single use case, e.g. access reviews
  • Runs against your real data
  • Measured outcome and decision point

Managed Agentic IGA

The layer, the agents and the expertise, run continuously alongside your team.

  • Continuous governance, not campaigns
  • Audit evidence kept current
  • Senior consultant on the account

[11]

Let's look at your identity estate

Tell us what you are running and where it hurts. A 30-minute conversation with a senior consultant, no sales pitch.

We reply within one business day. No newsletter, no list.