IAG

Identity Access Governance

Identity Access Governance

Know exactly who can touch which system — and prove it on demand.
IAG is an on-premise access-governance platform for any regulated organization. It catalogues your systems, the roles each one exposes and the people who hold them, then continuously reconciles what should be granted against what actually is — raising findings the moment access drifts out of policy, each mapped to the regulation it offends. It is built to align with the frameworks that govern access.

What you get

The outcomes that matter

One source of truth

Every system, the roles it exposes and the people who hold them — cataloged against one approved baseline.

Drift, caught continuously

SoD breaches, terminated users, orphaned profiles, missing MFA and over-privileged accounts — surfaced the moment they appear and risk-scored.

Compliance you can show

A live percentage per framework, drillable to the exact control behind every finding.

Inside IAG

Every module, end to end

IAG is organized into the work your team actually does — build the picture, govern it, and prove it. Each module below is part of one integrated platform.

Build the baseline

Authority Matrix
A living grid of job titles against systems — define the permission profiles each role may hold, enforce maker/checker separation, and approve every change through a four-eyes workflow. Your approved matrix is the baseline everything is measured against.
Authority Matrix Review Workflow
Matrices move through a formal send → review → approve / return cycle with four-eyes control, periodic-review scheduling and a tamper-evident audit ledger — so every baseline is signed off, on schedule, by the right people.
Systems & Roles Inventory
A live register of every system in scope, the roles each one exposes, and the access model behind them.
Job Titles Inventory
The authoritative list of job titles and the access each should — and should not — hold.

Request & control access

Access Request Portal
Staff request access through a guided portal with a built-in segregation-of-duties pre-check — conflicting requests are blocked before they are ever provisioned, with a documented override path for exceptions.
User Control
Enable or disable Active Directory accounts directly from IAG, with each action captured as an evidence-grade audit entry — turning a governance decision into an enforced one without ever leaving the platform.
Directory Single Sign-On
Integrates with your on-premise Active Directory; platform users are the members of a directory group you nominate, and roles are resolved server-side, never trusted from the browser. No cloud identity provider required.
Maker / Checker Approvals
Four-eyes separation on every matrix change, so no single person can both request and approve.

Detect drift

Continuous Reconciliation
Compares real, ingested entitlements against the approved baseline and flags the gaps — SoD breaches, terminated users who still have access, orphaned profiles, missing MFA and over-privileged accounts — each scored for risk and mapped to the regulation it offends.
Segregation of Duties (SoD)
Detects toxic combinations — maker and checker, request and approve — on a single identity.
Identity Attack Playbooks
A curated, offline reference of common identity attacks — Kerberoasting, token theft, MFA fatigue and more — each mapped to MITRE ATT&CK, NIST and CISA with phase-by-phase detect, contain, eradicate and recover steps.

Prove compliance

Regulatory Compliance Tracking
Out-of-the-box control mappings for international security frameworks — ISO/IEC 27001, SOC 2, NIST SP 800-53/800-171, PCI-DSS and COBIT — with a live compliance percentage per framework and drill-down to the exact controls behind every finding.
Reviews & Immutable Audit
Upload-and-compare reviews for roles, job titles and users surface drift on demand, and every action, sign-in and access-denied event is written to an append-only, tamper-evident ledger.
Dashboards & KPIs
A live command center — open findings by severity, a system-by-severity risk heat map, governance gaps and per-framework compliance — every tile clickable straight through to the underlying records.

How it works

From raw estate to evidence

  1. 01

    Inventory

    Import systems, roles and job titles to build the authority matrix.
  2. 02

    Reconcile

    Continuously compare real access against the matrix and surface every gap.
  3. 03

    Review

    Run evidenced access-review campaigns and resolve SoD conflicts.
  4. 04

    Prove

    Export a ledgered, tamper-evident trail for the regulator’s questions.

Added value

The value it creates

The authority matrix is the mechanism. This is what proving control of access is worth to the business.

Provable control

Answer “who can touch what” instantly

A live authority matrix replaces spreadsheets and screenshots — every role, system and permission, reconciled and current.

Audit-ready

Reviews that actually close

Campaign-based access reviews with reminders and a ledgered trail turn a quarterly fire-drill into a routine that finishes on time.

Fraud resistance

Catch toxic combinations

Segregation-of-Duties rules surface the permission pairs that let one person initiate and approve — before an auditor or attacker does.

Owned by you

On-prem, integrated

Deploys against your own directory on infrastructure you control, so identity data never leaves the building.

Regulatory fit

Where IAG fits your obligations

The frameworks that govern access — and exactly how IAG helps you satisfy each.

ISO/IEC 27001:2022International

Evidences A.5.15–A.5.18 (access control, privileged access, access rights) with a current, reviewed authority matrix.

PCI-DSS v4.0International

Supports Requirement 7 (least privilege) and Requirement 8 (unique IDs, periodic access review) with campaign records.

SOX · ICFRUSA

Produces the access-certification and SoD evidence external auditors request for financial-system controls.

SAMA CSFKSA

Covers the identity and access management domains with reconciled, evidenced periodic reviews.

NCA ECCKSA

Meets the IAM control requirements with role governance and scheduled recertification.

SWIFT CSCFInternational

Backs control 5 — manage identities and segregate privileges — for payment operators.

UAE IA · NESAUAE

Provides the access-governance evidence expected of critical UAE entities.

Risk mitigation

The risk it takes off the table

Access is where most breaches begin. Here is your exposure without IAG — and with it.

Without IAGWith IAG

Access lives in spreadsheets that are out of date the day they are saved.

A continuously reconciled authority matrix that reflects reality.

Leavers and movers keep permissions no one gets around to revoking.

Reconciliation flags orphaned and excess access for removal.

Reviews stall, and the “evidence” is screenshots pasted into a document.

Ledgered review campaigns with a tamper-evident trail behind every decision.

Toxic Segregation-of-Duties combinations go unnoticed until fraud or audit finds them.

SoD rules detect and block conflicting entitlements automatically.

The regulator asks “who approved this access, and when?” and no one can say.

Every grant, review and change is time-stamped and attributable.

Deployment & security

Yours to run, built to defend

Every Televestigo platform deploys inside your environment and stays under your control — hardened, directory-integrated, and audit-ready from day one.

On-premise & air-gap friendly

Runs entirely inside your own network and owned by you — no data leaves, and no external identity provider is required.

Directory sign-on, hardened

Group-based sign-on with roles resolved server-side, least-privilege bind accounts and strict TLS to your directory — so an attacker cannot elevate themselves by tampering with the browser.

Enterprise-grade operations

Automated database backups, bounded logging, memory-capped services, loopback-only data ports, scheduled health monitoring and one-step TLS trust — production-ready out of the box.

Branded, regulator-ready reports

Every export — CSV, PDF or on-screen — carries your organization name and logo, ready to hand to auditors.

See IAG in your environment

Tell us about your systems and obligations. We'll come back with a clear, practical view of where you stand — and what we'd do next.