Access reviews, joiners and leavers, the service desk queue, the runbook only one person can run. IT gains the most from this, and has to approve it first. This page covers both.
| Principal | Grant | Granted | Last used | Recommendation |
|---|---|---|---|---|
| j.okafor | db · read-write | 14 mo | 9 mo | Revoke — moved to Support in Q1 |
| deploy-bot | registry · push | 8 mo | 2 h | Keep — in the release path |
| a.lindqvist | admin console | 22 mo | never | Revoke — granted for a migration |
| support-agent | helpdesk · read | 3 mo | 11 m | Keep — scoped, read only |
IT work fits this well. It is procedural, it is already written down somewhere, and nobody notices it was skipped until an audit or an incident.
The mover case is where it earns its keep. A joiner gets a checklist and a leaver gets urgency; someone changing team quietly keeps both sets of access forever. A scheduled session finds those and drafts the revocations.
Who has what, how long they have had it, and when they last used it. It produces the review with a proposed action per row rather than a spreadsheet that gets forwarded twice and approved unread.
It reads the ticket, classifies it, finds whether your own documentation already answers it, and drafts the reply with the article linked. The ones it cannot answer get routed with the diagnosis already attached.
Write it down as a skill file and a session can execute it. That is the durable version of "ask Marta" — it survives Marta being on holiday, and improving it is a change request rather than a corrected memory.
What you pay for against what is assigned against what was opened this quarter. It writes the reclaim list per tool with the last-used date on every row.
It compares what your documentation says is configured against what is actually configured, and reports the difference. Reporting drift is safe and useful. Silently correcting it is neither, and it will not.
What IT needs is not a dashboard. It is a list, with a defensible reason on every line, in a form where approving it does something.
| Principal | Grant | Granted | Last used | Recommendation |
|---|---|---|---|---|
| j.okafor | db · read-write | 14 mo | 9 mo | Revoke — moved to Support in Q1 |
| deploy-bot | registry · push | 8 mo | 2 h | Keep — in the release path |
| a.lindqvist | admin console | 22 mo | never | Revoke — granted for a migration |
| support-agent | helpdesk · read | 3 mo | 11 m | Keep — scoped, read only |
SingulaComp has a real account, member, group and role model with per-resource permissions for people and for agents. An access review that covers your humans and not your automation is half a review.
Revoke because they moved team. Keep because it is in the release path. A review you can approve in ten minutes is one where the reasoning is on the line, not in a separate document.
Revocation is a write, and writes are where you set a gate. The default configuration for a review session should be read-everything, change-nothing, and propose.
IT stacks are the least uniform in the company. Connect what is in the catalogue and define the rest yourself. Either way, credentials never enter the machine.
Easy connect covers 3,000+ apps through their own OAuth screens. We are not going to claim your identity provider, your MDM and your network vendor are all in it — for an IT estate the direct connector types are usually the real path, and they take about the same three minutes.
Three ways to start the same session. Scheduled runs help IT most, because the work that gets skipped is the work with no deadline attached.
Someone mentions the bot in the IT channel. The thread becomes a session, the session reads your documentation, and the answer lands back in the same thread with the source quoted.
Set every write against an identity or an entitlement to Ask. The run holds at the call with the exact change in front of you, and resumes from that point when you approve. Set the irreversible ones to Block instead.
A cron trigger opens the quarterly access review and the monthly licence reconciliation. Triggers name the agent they run as, so the unattended session has exactly the reach the attended one has — no more.
You are also the team that has to approve this. Here are the answers, including the ones that are less flattering than usual.
One project, one set of connectors, one memory that compounds. Each team writes the skills for its own work; nobody stands up a second system.