The identity estate, in one platform
We build Rivitan Platform so enterprises can govern access and run day-2 identity work without chaos — and offer senior advisory when the architecture needs hands-on help.
Why Rivitan exists
Rivitan exists because enterprise identity still runs on sprawl: duplicate accounts, over-privileged admins, expired secrets, and access nobody can fully explain. Most tools either stop at cloud apps or bury you in a year-long IGA programme.
We built Rivitan Platform so teams can govern access, run day-2 identity work, and operate the estate underneath — directories, apps, DNS, DHCP — from one place, with an assistant that understands plain English.
Behind the product is deep Microsoft identity experience and optional senior advisory. Start with a demo or pilot; bring in architecture help only when you need it.
“One platform. Seven portals. Governance that actually changes the directory — not another spreadsheet.”
Rivitan is an identity platform first — ten dedicated portals, a production-grade API, and governance that actually changes the directory. If you reach out, you talk to the people building and running it.
The product comes from years inside large, messy enterprise estates. We built what operators and auditors actually needed, then made advisory available for the work that still needs a senior architect.
Rivitan
Founder · Dallas–Fort Worth, TX
What Rivitan Platform is
Seven portals after sign-in — IAM, Group Access, Application Access, Identity Analysis, AWS IAM, Infrastructure, and App Owner.
IAM Console
Enterprise categories for identities, access, lifecycle, governance, data access, directory & cloud, insights, and platform admin — with a live dashboard.
Group Access Portal
Self-service membership and group requests with real approvals — not hallway access.
Application Access
Requestable app catalog with owners, access levels, approve/fulfill, and auto-grant policies.
Identity Analysis
Hygiene scans, scored findings, dry-run remediation, and role discovery into access roles.
AWS IAM
Identity Center assignments, classic IAM hygiene, secure connections, and audited writes.
File & NTFS Governance
Share permissions, folder policies, self-service folder access, and NTFS audit in a dedicated portal.
Reporting & Analytics
Operational intelligence, audit logs, custom security reports, and compliance exports from one hub.
O365 License Management
Microsoft 365 SKU inventory, utilization reports, cleanup automations, and license audit.
Infrastructure Operations
DNS, DHCP, domain controllers, and IP visibility without living in an RDP session.
App Owner Portal
Secret health, rotation, owners, and sign-in context for the apps people are responsible for.
Principles behind the product
Software that closes the loop
Reviews that revoke access, secrets that get rotated, and an audit trail operators can defend. Rivitan is built for outcomes — not dashboards that stop at reporting.
One console, ten portals
IAM operators, group owners, app requesters, analysts, file governance teams, reporting and license ops, AWS operators, infrastructure teams, and app owners each get a workspace that fits their job.
Your estate, your boundary
Rivitan runs where your directory data already lives. Depth today across Active Directory, Entra ID, and AWS IAM — with Rivitan AI and a production-grade API included.
Custom IAM tooling
When standard portals aren't enough, we build bespoke request flows, integrations, and automation that match how your company actually runs identity.
Advisory when you want it
The product stands on its own. When you need senior architecture, migration delivery, or a fractional identity lead, the same team that builds Rivitan can help.
Credentials that back the work
SC-300
Microsoft Identity & Access Administrator
Azure
Microsoft Certified
AWS
Amazon Web Services Certified
SC-100
Microsoft Cybersecurity Architect
Built for regulated, complex estates
Experience spanning the sectors where identity, compliance, and uptime carry the highest stakes.
Microsoft-deep, expanding outward
Depth today across Active Directory, Entra ID, and AWS IAM — the same estate Rivitan Platform governs — with broader SaaS provisioning continuing on the roadmap.
Directories & IdPs
- Microsoft Entra ID
- Active Directory
- Okta
- Ping Identity
- Google Workspace
Cloud IAM
- AWS IAM & IAM Identity Center
- Azure RBAC
- GCP IAM
Governance (IGA)
- Entra ID Governance
- ConductorOne
- SailPoint
- Saviynt
Privileged Access (PAM)
- Entra PIM
- CyberArk
- BeyondTrust
Automation & standards
- Microsoft Graph
- PowerShell
- SCIM
- SAML / OIDC
- Terraform
Built from real enterprise identity work
The platform is informed by years of running the messy estates Rivitan is designed to govern.
Active Directory Engineer
Cut teeth running large multi-domain Active Directory environments — replication, Group Policy, and the unglamorous work of keeping the directory healthy at scale.
Identity & Security Architect
Led federation and single sign-on programs across Fortune 500 environments, designing ADFS, SAML, and the early hybrid bridges between on-prem and the cloud.
Cloud Identity Lead
Owned enterprise Entra ID (Azure AD) adoption: Conditional Access, MFA and passwordless rollouts, and large-scale migrations off legacy federation.
Founder, Rivitan
Building Rivitan Platform and custom IAM tooling for enterprises — with optional senior advisory when the architecture needs hands-on help.
Short, honest takes from real work
Not polished articles — just things I keep running into on engagements, written as they come up.
The 'temporary' admin account is never temporary
Found a Domain Admin created 'just for the migration' in 2019. It still had a password from then. Standing privilege is debt — it compounds quietly until someone finds it. Usually a pen tester. Sometimes worse.
Start Conditional Access in report-only
Every painful CA rollout I've cleaned up skipped report-only mode. A week of watching the sign-in logs tells you exactly which policy will lock out the CFO at 7am. Patience here is cheaper than an outage.
I still sketch the architecture by hand first
Before any diagram tool, I draw the identity flow on paper. If I can't explain it in a napkin sketch, the design is too complicated — and the client's team won't be able to run it after I'm gone.
ADFS isn't evil — it's just finished
It was the right call a decade ago. The problem isn't the technology, it's that it became a forgotten internet-facing server nobody patches. Most migrations off it are easier than teams fear once you map the relying parties.
See Rivitan against your estate
Book a platform walkthrough, or ask about an 8-week pilot. Advisory is available if you need architecture help alongside the product.