Rivitan Platform
Identity governance and operations for hybrid Microsoft environments
Govern access across Active Directory and Microsoft Entra ID, run access reviews that actually remove access, and operate the identity estate from one console — without a year-long IGA programme.
A review that ends in revoked access
Most access reviews produce evidence and nothing else. The decisions are recorded, the export is filed, and the access stays exactly where it was. Rivitan Platform closes that loop: after an auditor verifies the campaign, you preview the removals and then apply them to Active Directory and Entra ID.
Privileged groups such as Domain Admins are blocked unless an administrator explicitly overrides the guard, and every applied change lands in the audit log.
How access reviews work- 1
Campaign
A review is created on a schedule or on demand, scoped to the groups that matter.
- 2
Owner decides
The people who own the access keep, revoke, or flag each member — with context, not just a list of names.
- 3
Auditor verifies
A separate auditor step confirms the campaign before anything is allowed to touch the directory.
- 4
Dry run
A preview shows the exact set of memberships that would be removed. Nothing has changed yet.
- 5
Apply
Removals are executed in Active Directory and Entra ID, each one written to the audit log.
Eight areas, one platform
Governance and operations in the same product, because in a hybrid Microsoft estate they are usually the same team.
What operators and auditors actually see
The console is built for the people doing the work — dense where it needs to be, and explicit about what a destructive action will do before it does it.
Access review campaigns
The auditor view: every campaign, its progress, and what is waiting on verification.
/public/platform/access-review-dashboard.pngDry run, then apply
A preview of exactly which memberships would be removed, before anything touches the directory.
/public/platform/access-review-remediation.pngOne person, both directories
On-premises and Entra ID attributes, group membership, and account state on a single screen.
/public/platform/directory-user.pngRequests and approvals
A request moving through its approval stages, with SLA state and notification history.
/public/platform/requests-and-approvals.pngApp registration lifecycle
Registrations with real owners, and secrets flagged well before they expire.
/public/platform/app-registrations.pngInfrastructure operations
DNS, DHCP, and domain controller health across the estate, refreshed on a schedule.
/public/platform/infrastructure-dashboard.pngChosen on depth, not connector count
A straight answer about what this product is for, and what it is not.
Compared with cloud-only governance tools
The modern SaaS-first governance platforms are strong on cloud applications and thin where Active Directory, file shares, and Windows infrastructure live. If your estate is still substantially on-premises, that gap is the part you most need covered.
Compared with the large IGA suites
The enterprise suites are deep and defensible, and they ask for a multi-phase programme, a dedicated team, and a six-figure budget before you see value. Rivitan Platform is scoped to prove itself in a matter of weeks.
What we do not claim
This is not a catalogue of hundreds of SaaS connectors, and it is not an identity provider — it governs and operates the estate you already run on Microsoft. We would rather tell you that now than during a proof of concept.
Runs where your directory data already lives
The questions a security review asks first, answered before you have to ask them.
Runs in your environment
Deployed on infrastructure you control. Your directory data is not pooled into a shared multi-tenant service alongside other organisations.
Entra ID single sign-on
Operators sign in with Entra ID SSO, restricted to the groups you nominate, with a local break-glass account for installation.
Role-based authorisation
Admin, auditor, and operator roles gate both pages and API calls, so people and integrations get only what they need.
Encrypted credentials
Integration credentials are encrypted at rest with a key unique to your deployment. API keys are stored hashed, never in clear text.
Destructive actions are deliberate
Removals preview first, privileged groups are blocked unless explicitly overridden, and every applied change is written to the audit log.
No public exposure required
The console is normally reachable over your private network or VPN. It does not need to be published to the internet to work.
A 8-week pilot with a decision at the end
Fixed scope, agreed success criteria, and a written readout. No open-ended programme.
Install and connect
Weeks 1–2Stand up the platform on your host, connect one Active Directory domain and one Entra ID tenant, and configure single sign-on and roles.
Configure and load
Weeks 3–4Load the groups in scope, set owners, and configure the two or three additional capabilities that matter most to you.
Run a real review cycle
Weeks 5–7Take a campaign end to end: owner decisions, auditor verification, dry run, then applied removals with evidence retained.
Readout and decision
Week 8Written readout against the success criteria agreed at kickoff, admin handover documentation, and a go or no-go on an annual licence.
- Installation on your host, or a dedicated environment we prepare for you
- One Active Directory domain and one Entra ID tenant connected
- Single sign-on, roles, and branding configured for your organisation
- One complete access review campaign, ending in applied remediation
- Two or three further capabilities configured, chosen by you
- Up to two administrator training sessions plus a written runbook
- Weekly progress checkpoints and a written pilot readout
Pilots are quoted per environment once we know the scope. Tell us what you run and you will get a fixed number, not a range.
Request a pilot quoteBeing built next — and not shipped yet
These are on the plan, prioritised by what early customers actually need. They are listed here so nothing on this page reads as a promise it is not.
- Broader application provisioning and reconciliation through the connector framework
- HR-driven joiner, mover, and leaver automation from systems such as Workday
- Separation of duties policy evaluation at request time and during certification
- SCIM server and client, and further multi-forest productisation
Platform FAQ
The practical questions that come up on every first call.
You host it, on a server or virtual machine you control. That keeps directory data inside your boundary, which is usually the deciding factor for security review. For a pilot we can also prepare a dedicated environment so you can evaluate before installing anything.
See it against your own environment
Book a walkthrough and we will show the review loop end to end, then talk about what a pilot would look like for your estate.