Direction of travel
The Corporate Control Console
One control plane over the systems an IT director is accountable for, reading each of them through the same model that identity governance uses today. Most of it does not exist yet, and this page says which parts.
01 The idea
The same question, asked of every system
Identity governance answers one question well: who holds this access, and what approved it. That question is not specific to a directory. It is the same question you cannot currently answer about an AWS role, a vCenter permission, a software licence renewing next month, or a change that was approved in the service desk and then implemented differently.
Each of those lives in a different console, owned by a different person, exported to a different spreadsheet before each audit. The work of assembling them into a picture is done by hand, by you, about four times a year.
The console is the plan to stop doing that by hand. Identity governance is the first module because it is the one where the question bites hardest and the evidence is strongest.
02 Module status
What exists, and what is a plan
Written the way you would want a vendor to write it. One module is available. One is being built. Three are intentions.
-
Available
Identity governance
Effective-access discovery, role baselining, joiner/mover/leaver automation, group state, audit revert, across hybrid Active Directory and Entra ID.
This is the product. It is in use, it is what the demo shows, and it is what you would be buying.
-
In development
Cloud entitlement view
AWS IAM and Azure RBAC read through the same trace model, so a cloud role resolves to a person the same way a security group does.
Being built now. Read-only discovery first. Do not plan a control programme around it yet.
-
In design
ITSM integration
Change and approval records from your service desk attached to the grants they authorised, so the approval and the access point at each other.
Design only. No integration ships today, and the list of supported service desks is not fixed.
-
Planned
Virtualisation estate
vCenter permissions and role assignments alongside directory access, since in most estates the two have drifted apart entirely.
Not started. No date, and no date offered.
-
Planned
Procurement and budget
Licences, renewals and spend held against the same asset and owner records the rest of the platform uses.
Not started. This is the furthest out and the least certain.
03 How we sell it
Three commitments about the roadmap
-
One
You will never be quoted for a module that does not exist. Planned work is not on the price list, and it will not appear on a proposal as a line item with a discount against it.
-
Two
A roadmap item is never a reason to sign now. If identity governance on its own does not justify the spend, the honest answer is to wait, and you will get that answer on the call.
-
Three
Status on this page changes when the code does, not when the sales quarter does. If a module moves from planned to available, it is because you could use it that week.
Buy the module that exists. Judge the rest when it ships.
A demo covers identity governance, because that is what is real. If the console direction matters to your three-year plan, bring that to the call and you will get a candid answer about timing.