HR systems (e.g. Workday, Personio)
Start with CSV exports, move to API later. Departments, cost centers and movers stay consistently mapped to Entra ID / Local AD – even after reorganizations.
Zero-integration upload for unstructured identity exports, HR spreadsheets, and access policies — with client-side PII sanitization before any byte leaves your browser. Covierance bridges the disconnect between HR organizational models and IT infrastructure: Actual permissions across Okta, Entra ID / AD, and disconnected apps are deterministically verified against your SoD rules, eliminating audit spreadsheet chaos with tamper-proof Evidence Packs.
Security & Compliance
Covierance is in its founding phase. Certifications are on our 2026/27 roadmap – not yet granted.
Live preview
The dashboard with IAM objects, SoD classes, open decisions and evidence coverage – open the interactive preview.
Open previewNo login required
The status quo
Complement, don't replace
Covierance IAM Compass
What we ingest
Start with CSV exports, move to API later. Departments, cost centers and movers stay consistently mapped to Entra ID / Local AD – even after reorganizations.
Recertification of birthright permissions, roles and historically grown folder permissions.
ServiceNow GRC, OneTrust or your role and SoD matrices in Word/Excel – as the target model for reconciliation.
Unstructured exports from business apps and legacy systems without an API – ingested in a clean structure.
Compliance engine
Every phase is privacy by design: personal data is sanitized in your browser before processing – while auditors still receive understandable evidence.
Zero integration
Upload exports from Okta, Entra ID / Local AD, SAP or HR – personal data is sanitized right in your browser.
Guardrails & ZDR
Your personal AI agent: a skill set the LLM executes strict guardrails with zero data retention (ZDR). Python supplies the mathematical evidence layer – so checks are computed, not guessed, which prevents hallucinations.
Smart dropdowns
When assignments are ambiguous, the engine asks the business owner – you confirm via dropdown.
SoD readiness
The clean, audit-ready status across all directories and applications at a glance.
Approved deltas
No blind write access: only approved changes go back to Okta or Entra ID / Local AD – fully logged.
eSign approval
Management report for auditors plus a sealed technical evidence pack – approved via eSign.
Live data flow · Sample identity
John Doe passes through all six engine phases
Upload & Sanitization
01John Doe
Sanitized in browser
Python Decision Engine
02SAP_FIN_0815
Deterministically checked
HUMAN-ON-THE-LOOP
03Department? → Finance
Owner confirmed
Dashboard & Review
04John Doe · Finance
Reviewed in plain text
Controlled sync
05Approved +12 / −3
Fully logged
Evidence Pack
06Evidence_0926.pdf
NIS-2 · DORA · ISO 27001
Human-in-the-loop
Ambiguous columns or missing owners are never guessed. IAM Compass asks a concrete question – you decide via dropdown.
| Identity | Question | Answer |
|---|---|---|
| John DoeSource: FIN-OPS-2 | Clarify column 'Department' | Finance |
| Sofia MillerSource: — | Who is the deputy? | Select… Jonas Ferreira Mara Brandt No deputy |
| Jonas FerreiraSource: SAP | Map role 'SAP_FIN_0815' | Invoice approval |
Actionable error handling
If an Okta push fails, you get clear tasks in plain language – with cause, affected users and a one-click fix.
Group 'Finance-Approvers' missing in Okta
Group created · 4 users
Mara Brandt is deactivated in Okta
Skip leaver revoke or reactivate
Rate limit while pushing 12 changes
Auto-retry in 2 min
40+ hrs
Saves IT 40+ hours of manual work before every audit.
10–50×
A single failed audit costs 10 to 50 times as much as our platform.
ISO 27001
Foundation for ISO 27001: no transparent permission table, no certificate.
Early Adopter Program
IAM Compass is a proof of concept we are growing into an enterprise platform together with our early adopters. You only pay the software license – we invest all the engineering in your requirements.
Software license
Your only cost: a fixed, discounted early-adopter license for ongoing operation.
Feature requests & co-engineering
Connectors, SoD rules, report formats: we build your prioritized requirements at no development cost to you – straight into the product standard.
Lifetime updates & price protection
All future releases and standard modules are included without upgrade fees. Your license price stays contractually capped as the platform grows.
Our security promise
Every feature request runs through our secure software development lifecycle: strict tenant isolation, automated SAST/DAST scans, four-eyes code review and privacy by design. Your identity data stays 100 % under your control and never leaves the EU.
Become an early adopter
Tell us which IAM or audit process costs you the most time today. Together we'll check whether an early-adopter partnership is a fit.
A CONVERSATION BETWEEN PEERS.
Dennis Kast
Fractional CISO & Founder
You speak directly with a certified IT security manager with senior experience in IGA, access reviews and regulatory audits – confidential and at C-level.
Partnership model
Contact us directly
Your details are used only to process your request. See the privacy policy for details.