For Highly Regulated FinTech & Healthcare Companies

Covierance IAM Compass – Automated Cross-System Permission Audits & Compliance

End the loss of control over cross-system access rights. Our SaaS platform untangles identities from Okta and Entra ID, explains SoD conflicts with AI and generates audit-ready evidence packs for ISO 27001, NIS-2 and B3S.

Security & Compliance

  • CCPA & GDPR Compliant
  • Audit-ready for SOC 2 Type II
  • Enterprise-grade Encryption

Live preview

IAM Compass / Overview

The dashboard with IAM objects, SoD classes, open decisions and evidence coverage – open the interactive preview.

Open preview

No login required

The biggest effort isn't the audit itself – it's the preparation.

The status quo

  • Fragmented permission data in spreadsheets without clear ownership
  • Undocumented scripts and individual know-how as a single point of failure
  • Projects stall before go-live due to complex API integrations
  • Resource-intensive, manual audit preparation lasting weeks

The SaaS solution

Compliance-with-Content

  • Compliance-with-content: verifiable evidence instead of empty documents
  • Industry-specific healthcare templates from the first upload
  • Automated collection, assessment and versioning of audit evidence
  • Integrated ChatOps for decisions in your familiar workflow

The four pillars of the platform

A governance platform that grows with your maturity

01

Zero integration to API

Start on day one with an offline CSV/JSON upload – no API required. Scale seamlessly to our 24/7 API monitoring.

02

AI translation in plain language

Our parsing engine untangles nested groups and the AI translates cryptic permissions into plain language for your auditors.

03

GitOps & ChatOps automation

One-click approvals and revocations directly in Slack or MS Teams. Changes are versioned audit-proof via GitOps.

04

Regional compliance

Strong European focus: NIS-2, DORA, GDPR segregation of duties, ISO 27001.

Compliance engine

From raw data upload to audit-ready evidence pack

Every phase is privacy by design: personal data only leaves your infrastructure as irreversible hashes – while auditors still receive understandable evidence.

  1. Zero data retention

    Upload & sanitization

    01/06

    PII masking runs in the background. Raw data is not retained after processing.

    PII masked0 days retentionCSV · JSON
  2. Deterministic

    AI & Python engine

    02/06

    Python calculates rules precisely, the LLM writes readable output – without hallucinations.

    JML: 3 movers detectedSoD: 1 conflictSAP_FIN_0815 → Invoice approval
  3. Plain-text view

    Dashboard & review

    03/06

    You review the clean, unmasked data in a clear dashboard.

    1.248Identities27SoD94 %Evidence
  4. Smart dropdowns

    Human-in-the-loop

    04/06

    When data is ambiguous, the engine asks a targeted question – you clarify via dropdown.

    Department?Finance
  5. Delta to IdP

    API push

    05/06

    Only changes are pushed to your IdP (e.g. Okta) – with immutable audit logs.

    Okta · +12 / −3Immutable log
  6. eSign approval

    Audit-ready reports

    06/06

    Reports are generated and approved by stakeholders via eSign.

    eSign 3/3NIS-2 · DORA · ISO 27001

Live data flow · Sample identity

John Doe passes through all six engine phases

Continuous loop active

Upload & Sanitization

01

John Doe

User_8f92a

Zero data retention

AI & Python engine

02

JML: Mover

SoD: 1 Conflict

Deterministically checked

Dashboard & review

03

John Doe · Finance

Plain-text view

Reviewed unmasked

Human-in-the-Loop

04

Department? → Finance

Question resolved

Smart dropdown

API-Push

05

Okta Delta +12 / −3

Immutable log

Deltas only

Audit-Ready Reports

06

Report_0926.pdf

eSign 3/3

NIS-2 · DORA · ISO 27001

Continuous monitoring · next identity

Human-in-the-loop

The engine asks instead of guessing

Ambiguous columns or missing owners are never guessed. IAM Compass asks a concrete question – you decide via dropdown.

iam-compass / clarifications
IdentityQuestionAnswer
John DoeSource: FIN-OPS-2Clarify column 'Department'Finance
Sofia MillerSource: —Who is the deputy?Select…
Jonas Ferreira
Mara Brandt
No deputy
Jonas FerreiraSource: SAPMap role 'SAP_FIN_0815'Invoice approval
2 / 3 resolvedApply

Actionable error handling

A task checklist instead of cryptic error logs

If an Okta push fails, you get clear tasks in plain language – with cause, affected users and a one-click fix.

iam-compass / okta-push / tasks
Okta Push #09262 open
  • Group 'Finance-Approvers' missing in Okta

    Group created · 4 users

  • Mara Brandt is deactivated in Okta

    Skip leaver revoke or reactivate

    Resolve
  • Rate limit while pushing 12 changes

    Auto-retry in 2 min

    Resolve

Scalable compliance without draining resources

40+ hrs

Saves IT 40+ hours of manual work before every audit.

10–50×

A single failed audit costs 10 to 50 times as much as our platform.

ISO 27001

Foundation for ISO 27001: no transparent permission table, no certificate.

Pricing

Land first, then expand

Land

Readiness audit scan
$1,500one-time
  • Offline CSV/JSON upload – no API needed
  • Deterministic SoD conflict check
  • Audit-ready PDF with evidence pack
  • Results workshop with our IAM team
Start pilot scan

Expand

Continuous Governance
$3per identity / month
  • API connection to Okta and Entra ID
  • 24/7 monitoring with drift alerts
  • Automated access reviews
  • ChatOps in Slack & MS Teams
  • Auto-remediation with GitOps history
Book a platform demo

All plans include evidence archive, GDPR-compliant EU hosting and data processing agreement.