Intense-Systems

Identity governance

Every permission in your estate came from somewhere. Some of it came from nowhere.

Intense-Systems traces effective access back through nested groups to the approval that granted it — for hybrid Active Directory and Entra ID estates at regulated operators of 400 to 2,000 staff.

Thirty minutes, run against synthetic data.
No account created, nothing installed.

Trace — who holds this, and why

  • \\fs01\Finance$\Payment-Runs resource · read/write
    • Approved. SEC-Finance-Payments-RW security group · approved 2019-03-11 · CHG-4471
      • Approved. SEC-Ops-Shared nested group · approved 2021-11-04 · CHG-8820
        • No approval record. SEC-Contractor-Onboard-2019 nested group · no approval record
          • Orphaned. a.farrugia AD account disabled 2019-08-22 · Entra ID account still enabled
Effective access resolved through four levels of nesting. The grant at the third level has no approval record. The account at the fourth left in 2019 and still resolves through the hybrid join. Rendered from synthetic data.
  • Approved, with a record
  • No approval record
  • Orphaned or leaver

01 The problem

Access debt does not announce itself. It accumulates.

Nothing here is a hypothetical. If you have run a hybrid estate through a migration, a merger or a decade of staff turnover, you have at least three of these right now.

  1. 01

    The contractor who left in 2019

    Their Active Directory account was disabled on their last day. Their Entra ID account was created directly in the cloud during the 2021 migration and never linked to the on-premises object, so it was never touched. The mailbox still receives.

  2. 02

    The group nobody can explain

    A few hundred members, four other groups nested inside it, and a name that refers to a project which finished years ago. Nobody will delete it, because nobody can prove what stops working when they do.

  3. 03

    The access review that is a CSV export

    Twelve thousand rows go out to line managers every quarter. They come back approved in full, often the same day, because reading them properly is not a job anyone actually has. The auditor sees a completed review. You know what it was.

  4. 04

    The leaver process that stops at the sign-in

    Offboarding disables the account and everyone moves on. It does not remove the group memberships, the shared-mailbox delegations, or the site permissions that were granted to the person directly rather than through a group. Those survive the account.

None of this is negligence. It is what happens when the directory is the only system that remembers, and the directory has no opinion about whether a membership was ever meant to exist.

02 What it does

What you get, in the order you will use it

Discovery first, because you cannot govern access you cannot see. Everything after that depends on it.

  1. 01 / discover

    See access as it actually resolves

    Read the estate the way the directory reads it — through nested groups, inherited permissions and direct grants — and show who ends up holding what. Not what the group names imply. Not what the last spreadsheet said.

  2. 02 / baseline

    Work out what normal looks like for a role

    Take the access held by everyone doing the same job and intersect it. The overlap becomes the proposed role. Everything outside the overlap becomes an exception list worth reading, because it is short.

  3. 03 / approve

    Give every grant a record it has to answer to

    Each grant carries an approver, a date and a reason. Access with nothing behind it is displayed as access with nothing behind it, rather than sitting quietly in the middle of a group nobody opens.

  4. 04 / automate

    Move joiners, movers and leavers without a ticket

    Membership follows the HR record. A mover loses the access that belonged to the old role instead of accumulating both. A leaver loses their memberships, not only their ability to sign in.

  5. 05 / revert

    Undo a change without losing the audit trail

    Every change the platform makes is written down and every change can be rolled back. A role assignment that turns out to be wrong is a revert, with the record of both the change and the reversal intact.

Full capability detail →

03 Architecture

The agent runs inside your estate. Your directory credentials never leave it.

You install an agent on a domain-joined server you control. It reads the directory using a service account you create, hold and can revoke without telling us. It opens outbound connections to the platform on 443 and nothing else.

There is no inbound firewall rule to justify to your network team, no VPN tunnel, no site-to-site link, and no listener on your perimeter. We never receive your directory credentials, because there is no point in the design at which they would be sent.

Security and architecture in detail →

Direction of travel
Outbound only, TCP 443, agent to platform. Nothing is ever initiated towards your estate.
What we hold
Object names, group structure, membership and approval state. Not password hashes, not credentials, not file contents.
Where it is held
EU regions only, with each tenant separated at the data layer rather than by a filter in application code.
Turning it off
Stop the agent service and collection stops. Disable the service account and it stops whether or not we agree.

04 Direction

Where this is going, and where it is not yet

The longer plan is a single control plane over the systems an IT director is accountable for — cloud, virtualisation, procurement, service management — reading them through the same trace model that identity governance uses today. That is the Corporate Control Console, and most of it does not exist yet.

Platform modules and their current status
Module Status Note
Identity governance Available Hybrid AD and Entra ID. Multi-tenant.
Cloud entitlement view — AWS, Azure In development Reading IAM and RBAC through the same trace model.
VMware estate Planned Not started. No date offered.
Procurement and budget Planned Not started. No date offered.
ITSM integration In design Change records attached to grants.

Nothing on that list is sold as available until it is available. If a module matters to your decision, ask on the call and you will get a straight answer about whether it exists, rather than a date.

The platform in full →

05 Fit

Who this is for

A good fit

  • 400 to 2,000 staff, with an IT function of five to thirty people and no dedicated identity team.
  • A regulated sector — gaming and betting, iGaming platform providers, financial services, pharmaceuticals — where an auditor will ask who approved a grant and when.
  • A hybrid directory: Active Directory synchronised to Entra ID, usually with a decade of history and at least one migration behind it.
  • ISO 27001 held or in progress, or an equivalent certification with an access-control clause you have to evidence.
  • Multiple legal entities or brands under one IT team, often after an acquisition.

A poor fit

  • Under 200 staff. The access debt is not there yet. A spreadsheet and a careful leaver checklist will genuinely serve you, and we would rather say so.
  • Cloud-only and greenfield. If there has never been an Active Directory, the governance features in Entra ID cover most of what we would do.
  • Already running SailPoint or Saviynt with the staff to operate it. That is a bigger tool than this one and you have already paid for it.
  • Looking for a certification in a box. This produces evidence about real access. It will not make an unfit estate look fit, and it is quite good at showing you exactly how unfit it is.

See it run against a directory that looks like yours.

Thirty minutes with the person who built it. Synthetic data by default, or a scoped read-only trial against your own estate if you would rather see the real thing.