Latest news · Our new website is live — same platform, a fresh look
Identity Governance
Access granted on purpose. Reviewed and managed on time.
Governance is the part that has to hold up when somebody asks. Access requests with approval chains proportionate to what they open, certification campaigns a reviewer can actually decide on, segregation of duties, role policy and the lifecycle underneath — with the evidence trail behind each of them. For employees, contractors, partners, service accounts and the agents that turned up last year.
Provisioning without reconciliation is hope. Certification without context is a formality. Roles without maintenance become a second, undocumented access model. Governance is one process with nine moving parts, which is why it is usually the most expensive thing in an identity programme — and the one that repays most.
Identity lifecycle management
Identities and their relationship with the organisation are created, updated and closed from the systems that actually know: HR for employees, a sourcing system for contractors, a register for everyone else. Future-dated events count too — a resignation entered two weeks in advance becomes scheduled work, not a note in somebody's calendar.
Account provisioning
Accounts created, changed and removed in the target systems, then read back to check that what exists is what was asked for. Reconciliation matters as much as provisioning: an account that appeared outside the process is precisely the one worth knowing about.
Workflows
The sequence behind an approval, a review or a lifecycle event: who approves what, in which order, what happens on escalation when nobody answers. Drawn as a diagram rather than buried in a configuration screen.
Self-service
People request what they need and can see where the request has got to. The alternative is a ticket in a queue, and a manager who approves it mostly to make the queue shorter.
Access request and approval
A catalogue of what can be asked for, written in language the requester understands, with an approval chain proportionate to what the access opens. An entitlement called ADM_GRP_882 gets requested blindly and approved blindly.
Access certification
Campaigns scoped by risk, by application or by population — everything, or only what changed since last time. A review that lists technical entitlements with a deadline gets approved in bulk; one that shows last use, peer comparison and risk gets decided.
Segregation of duties
Combinations that must never land on the same person — raise a payment and approve it, write the code and push it to production — caught before they are granted, and reported where they already exist.
Policy and role management
Rules that grant access because of who somebody is, so the request queue carries the exceptions rather than the routine. Roles drift and multiply on their own: they need mining and maintenance, not only definition.
Audit and reporting
Who has access to what, who approved it, when it was granted and when it went away — with the history intact for identities that are no longer active. This is the artefact an auditor actually asks for.
Three rooms, three questions
Governance answers to more than the auditor
The same deployment has to satisfy three different people who rarely sit in the same meeting. Programmes that optimise for one of them tend to fail the other two quietly.
The auditor asks
“Who had access to this system last quarter, who approved it, and can you show me?”
Compliance is what funds most governance programmes and what gets measured most literally. The answer has to be evidence produced on demand, not a week of somebody assembling logs by hand before a deadline.
The security team asks
“What access exists that nobody needs?”
Orphaned accounts, entitlements untouched for a year, privileges that survived a change of role. Least privilege is not a policy you write once — it is a gap you keep closing, and it widens every day nobody is looking.
The new joiner asks
“Why is it day four and I still can't do my job?”
The driver that gets forgotten, because it never appears in an audit finding. Access that arrives on day one is worth as much to the business as access that leaves on the last day is worth to security.
The parts nobody puts in the brochure
Where governance programmes actually stall
Not in the features. In the three places below — every time, in every organisation, regardless of which platform was bought.
The applications that never get onboarded
Governance covers what was integrated, and integration has a long tail: an application with no connector, no API, no SCIM support. Everything beyond the tail keeps its account list in a spreadsheet — and those are often the systems where a review would have mattered most.
What helps
Reach what standards can reach first, and make the rest a deliberate choice: ITSM-driven manual fulfilment with the ticket as the evidence trail, rather than an application quietly outside the perimeter.
The data underneath
A governance platform is only as good as the identity data it reads. Duplicate identities, an HR feed that lags reality by a week, entitlements whose names mean nothing to the person approving them: automation inherits every one of these and applies them faster.
What helps
Clean and stabilise the authoritative sources before connecting them, and keep the entitlement catalogue readable by the people who have to approve from it.
The review that gets approved in bulk
A campaign arrives as a list of technical entitlements with a deadline attached. For a busy manager the rational move is to approve everything. The campaign completes, the metric turns green, and nothing was actually governed.
What helps
Give reviewers something to decide with — last use, peer comparison, risk — and scope campaigns by risk instead of running everything against everyone every quarter.
None of this is solved by buying software. It is solved by designing the process and then automating it — which is the order most programmes get backwards, and the reason the second attempt usually goes better than the first.
On the canvas
A campaign is a process, so draw it like one
A certification campaign, an approval chain, a joiner sequence: each one has branches, conditions, timeouts and an escalation for the manager who is on holiday. In most platforms that logic lives in configuration screens and is understood by two people.
On the Monokee canvas it is a diagram — reviewed by the people who own the process, versioned like anything else, and changed without a project. The same canvas that carries authentication and access journeys carries the governance ones, which means one place to look when an auditor asks how a decision was made.
Scope campaigns by risk and by application, not by the calendar
Approval chains that adapt to what the access opens
Escalation and expiry designed in, rather than discovered when a campaign stalls
Remediation that reaches the target system, not just the report
The populations with the worst data are the ones with the most standing access. A governance model built around the employee lifecycle and bolted onto everyone else is how organisations end up with accounts nobody can name.
Employees
The population with the cleanest source of truth and the most predictable lifecycle. Everything else is harder.
Contractors and partners
Fixed-term, often with no HR record, frequently onboarded by someone outside IT. The population where access most reliably outlives the reason for it.
Service accounts and bots
No manager, no leaving date, and a password that was set once. They need an owner who confirms they are still needed, like everyone else.
AI agents
Emerging
A new constituency with its own lifecycle: registered, scoped, tied back to the human who authorised it, and retired when the task is over.
Joiner, mover, leaver — and the one everybody skips
Every governance programme automates the first. Most automate the third, eventually, because an auditor asked. The middle one is where least privilege quietly dies.
Joiner
Productive on day one
Birthright access granted from the role, before the first login
Requests reserved for the exceptions, not the routine
The manager confirms a proposal instead of assembling one
What goes wrong
The new starter waits on four separate tickets — and somebody, to save time, copies the permissions of the person who just left.
Mover
Rights follow the role
The access the new role needs is granted
The access the old role needed is removed
Segregation of duties checked against the resulting combination, not the addition
What goes wrong
Nothing gets removed. After three moves a person holds the union of every job they have ever done, and no single grant ever looked unreasonable.
Leaver
Access ends when the relationship does
Triggered by the source of truth, not by a farewell email
Future-dated: a resignation entered in advance acts on the right day
Across every connected system, not only the well-known ones
What goes wrong
The accounts that close are the ones IT knew about. The rest stay open and become the orphaned accounts the next campaign discovers.
Automotive
Manufacturing
Public administration
Healthcare
Insurance
Banking
Bring us the access review nobody wants to run
We'll scope it with you and draw what the automated version looks like.