Skip to content
Rivitan Platform

Access Reviews & Certification

Reviews that end in revoked access, not a signed spreadsheet.

Schedule or launch review campaigns, route them to the people who actually own the access, let an auditor verify the outcome, then remove the access that was revoked — in Active Directory and Entra ID.

The problem

Most access reviews stall at the evidence stage. Owners tick boxes, an auditor files the export, and the accounts that should have lost access keep it until the next audit finds them again. The certification is complete on paper and meaningless in the directory.

What the platform does

  • Rule-based recurring campaigns or immediate, ad-hoc reviews
  • Owner review experience with per-member keep, revoke, or flag decisions
  • Separate auditor verification step before anything is applied
  • Dry-run preview showing exactly which memberships would be removed
  • One-click apply that removes membership from AD and Entra ID
  • Guard rails on privileged groups (Domain Admins and similar) that require an explicit override
  • Partial-failure handling — the campaign stays open until every revocation lands
  • Full audit trail and CSV export for the audit file

Who this is for

Teams facing SOX, SOC 2, or internal ITGC access-review obligations across AD and Entra.

See Access Reviews against your own environment

Book a walkthrough and we will show this capability end to end, then talk about what a pilot would look like for your estate.

Book a Call