Skip to content
Product

Rivitan Platform

Identity governance and operations for hybrid Microsoft environments

Govern access across Active Directory and Microsoft Entra ID, run access reviews that actually remove access, and operate the identity estate from one console — without a year-long IGA programme.

The difference

A review that ends in revoked access

Most access reviews produce evidence and nothing else. The decisions are recorded, the export is filed, and the access stays exactly where it was. Rivitan Platform closes that loop: after an auditor verifies the campaign, you preview the removals and then apply them to Active Directory and Entra ID.

Privileged groups such as Domain Admins are blocked unless an administrator explicitly overrides the guard, and every applied change lands in the audit log.

How access reviews work
  1. 1

    Campaign

    A review is created on a schedule or on demand, scoped to the groups that matter.

  2. 2

    Owner decides

    The people who own the access keep, revoke, or flag each member — with context, not just a list of names.

  3. 3

    Auditor verifies

    A separate auditor step confirms the campaign before anything is allowed to touch the directory.

  4. 4

    Dry run

    A preview shows the exact set of memberships that would be removed. Nothing has changed yet.

  5. 5

    Apply

    Removals are executed in Active Directory and Entra ID, each one written to the audit log.

Capabilities

Eight areas, one platform

Governance and operations in the same product, because in a hybrid Microsoft estate they are usually the same team.

Inside the product

What operators and auditors actually see

The console is built for the people doing the work — dense where it needs to be, and explicit about what a destructive action will do before it does it.

Access review campaigns

Access review campaigns

The auditor view: every campaign, its progress, and what is waiting on verification.

/public/platform/access-review-dashboard.png
The auditor view: every campaign, its progress, and what is waiting on verification.
Dry run, then apply

Dry run, then apply

A preview of exactly which memberships would be removed, before anything touches the directory.

/public/platform/access-review-remediation.png
A preview of exactly which memberships would be removed, before anything touches the directory.
One person, both directories

One person, both directories

On-premises and Entra ID attributes, group membership, and account state on a single screen.

/public/platform/directory-user.png
On-premises and Entra ID attributes, group membership, and account state on a single screen.
Requests and approvals

Requests and approvals

A request moving through its approval stages, with SLA state and notification history.

/public/platform/requests-and-approvals.png
A request moving through its approval stages, with SLA state and notification history.
App registration lifecycle

App registration lifecycle

Registrations with real owners, and secrets flagged well before they expire.

/public/platform/app-registrations.png
Registrations with real owners, and secrets flagged well before they expire.
Infrastructure operations

Infrastructure operations

DNS, DHCP, and domain controller health across the estate, refreshed on a schedule.

/public/platform/infrastructure-dashboard.png
DNS, DHCP, and domain controller health across the estate, refreshed on a schedule.
Where it fits

Chosen on depth, not connector count

A straight answer about what this product is for, and what it is not.

Compared with cloud-only governance tools

The modern SaaS-first governance platforms are strong on cloud applications and thin where Active Directory, file shares, and Windows infrastructure live. If your estate is still substantially on-premises, that gap is the part you most need covered.

Compared with the large IGA suites

The enterprise suites are deep and defensible, and they ask for a multi-phase programme, a dedicated team, and a six-figure budget before you see value. Rivitan Platform is scoped to prove itself in a matter of weeks.

What we do not claim

This is not a catalogue of hundreds of SaaS connectors, and it is not an identity provider — it governs and operates the estate you already run on Microsoft. We would rather tell you that now than during a proof of concept.

Security & deployment

Runs where your directory data already lives

The questions a security review asks first, answered before you have to ask them.

Runs in your environment

Deployed on infrastructure you control. Your directory data is not pooled into a shared multi-tenant service alongside other organisations.

Entra ID single sign-on

Operators sign in with Entra ID SSO, restricted to the groups you nominate, with a local break-glass account for installation.

Role-based authorisation

Admin, auditor, and operator roles gate both pages and API calls, so people and integrations get only what they need.

Encrypted credentials

Integration credentials are encrypted at rest with a key unique to your deployment. API keys are stored hashed, never in clear text.

Destructive actions are deliberate

Removals preview first, privileged groups are blocked unless explicitly overridden, and every applied change is written to the audit log.

No public exposure required

The console is normally reachable over your private network or VPN. It does not need to be published to the internet to work.

How you start

A 8-week pilot with a decision at the end

Fixed scope, agreed success criteria, and a written readout. No open-ended programme.

1

Install and connect

Weeks 1–2

Stand up the platform on your host, connect one Active Directory domain and one Entra ID tenant, and configure single sign-on and roles.

2

Configure and load

Weeks 3–4

Load the groups in scope, set owners, and configure the two or three additional capabilities that matter most to you.

3

Run a real review cycle

Weeks 5–7

Take a campaign end to end: owner decisions, auditor verification, dry run, then applied removals with evidence retained.

4

Readout and decision

Week 8

Written readout against the success criteria agreed at kickoff, admin handover documentation, and a go or no-go on an annual licence.

What the pilot includes
  • Installation on your host, or a dedicated environment we prepare for you
  • One Active Directory domain and one Entra ID tenant connected
  • Single sign-on, roles, and branding configured for your organisation
  • One complete access review campaign, ending in applied remediation
  • Two or three further capabilities configured, chosen by you
  • Up to two administrator training sessions plus a written runbook
  • Weekly progress checkpoints and a written pilot readout

Pilots are quoted per environment once we know the scope. Tell us what you run and you will get a fixed number, not a range.

Request a pilot quote
On the roadmap

Being built next — and not shipped yet

These are on the plan, prioritised by what early customers actually need. They are listed here so nothing on this page reads as a promise it is not.

  • Broader application provisioning and reconciliation through the connector framework
  • HR-driven joiner, mover, and leaver automation from systems such as Workday
  • Separation of duties policy evaluation at request time and during certification
  • SCIM server and client, and further multi-forest productisation
Questions

Platform FAQ

The practical questions that come up on every first call.

You host it, on a server or virtual machine you control. That keeps directory data inside your boundary, which is usually the deciding factor for security review. For a pilot we can also prepare a dedicated environment so you can evaluate before installing anything.

See it against your own environment

Book a walkthrough and we will show the review loop end to end, then talk about what a pilot would look like for your estate.

Book a Call