For Highly Regulated FinTech & Healthcare Companies

Covierance IAM Compass – Automated Cross-System Permission Audits & Compliance

Zero-integration upload for unstructured identity exports, HR spreadsheets, and access policies — with client-side PII sanitization before any byte leaves your browser. Covierance bridges the disconnect between HR organizational models and IT infrastructure: Actual permissions across Okta, Entra ID / AD, and disconnected apps are deterministically verified against your SoD rules, eliminating audit spreadsheet chaos with tamper-proof Evidence Packs.

Security & Compliance

  • GDPR & CCPA by design
  • ISO 27001 in preparation
  • SOC 2 Type II readiness initiated
  • Designed for NIS-2
  • Designed for DORA

Covierance is in its founding phase. Certifications are on our 2026/27 roadmap – not yet granted.

Live preview

IAM Compass Demo

The dashboard with IAM objects, SoD classes, open decisions and evidence coverage – open the interactive preview.

Open preview

No login required

The biggest effort isn't the audit itself – it's the preparation.

The status quo

  • HR org structures and IT directories drift apart – native syncs get disabled with every reorganization
  • Weeks of spreadsheet reconciliation before every audit because Okta, Entra ID / Local AD and legacy apps don't match
  • Historically grown folder permissions and apps without an API stay unreviewed
  • Approvals without context (“rubber stamping”) – generic reports without a traceable decision chain

Complement, don't replace

Covierance IAM Compass

  • No replacement for Okta, Entra ID or SailPoint – the missing governance and evidence layer in between
  • Start on day one with a CSV upload, move to API step by step – no months-long integration project
  • Deterministic separation-of-duties checks; AI only translates into plain language
  • Tamper-proof evidence packs for auditors, DORA and NIS-2

What we ingest

Four data sources. One consistent picture.

01

HR systems (e.g. Workday, Personio)

Start with CSV exports, move to API later. Departments, cost centers and movers stay consistently mapped to Entra ID / Local AD – even after reorganizations.

02

IdP & IGA (e.g. Okta, Entra ID / Local AD, SailPoint)

Recertification of birthright permissions, roles and historically grown folder permissions.

03

GRC & authorization concepts

ServiceNow GRC, OneTrust or your role and SoD matrices in Word/Excel – as the target model for reconciliation.

04

CSV exports & legacy systems

Unstructured exports from business apps and legacy systems without an API – ingested in a clean structure.

Compliance engine

From raw data upload to audit-ready evidence pack

Every phase is privacy by design: personal data is sanitized in your browser before processing – while auditors still receive understandable evidence.

  1. Zero integration

    Upload & sanitization

    01/06

    Upload exports from Okta, Entra ID / Local AD, SAP or HR – personal data is sanitized right in your browser.

    PII maskedCSV · no API neededHR · AD · SAP
  2. Guardrails & ZDR

    AI agent (LLM + Python)

    02/06

    Your personal AI agent: a skill set the LLM executes strict guardrails with zero data retention (ZDR). Python supplies the mathematical evidence layer – so checks are computed, not guessed, which prevents hallucinations.

    JML: 3 movers detectedSoD: 1 conflictSAP_FIN_0815 → Invoice approval
  3. Smart dropdowns

    Human-in-the-loop

    03/06

    When assignments are ambiguous, the engine asks the business owner – you confirm via dropdown.

    Department?Finance
  4. SoD readiness

    Dashboard & review

    04/06

    The clean, audit-ready status across all directories and applications at a glance.

    1.248Identities27SoD94 %Evidence
  5. Approved deltas

    Controlled sync

    05/06

    No blind write access: only approved changes go back to Okta or Entra ID / Local AD – fully logged.

    Approved · +12 / −3Okta / Entra IDImmutable log
  6. eSign approval

    Audit-ready evidence pack

    06/06

    Management report for auditors plus a sealed technical evidence pack – approved via eSign.

    eSign 3/3NIS-2 · DORA · ISO 27001

Live data flow · Sample identity

John Doe passes through all six engine phases

Continuous loop active

Upload & Sanitization

01

John Doe

[PERSON_01]

Sanitized in browser

Python Decision Engine

02

SAP_FIN_0815

SoD: 1 Conflict

Deterministically checked

HUMAN-ON-THE-LOOP

03

Department? → Finance

Question resolved

Owner confirmed

Dashboard & Review

04

John Doe · Finance

SoD-Readiness ✓

Reviewed in plain text

Controlled sync

05

Approved +12 / −3

Okta / Entra ID

Fully logged

Evidence Pack

06

Evidence_0926.pdf

eSign 3/3

NIS-2 · DORA · ISO 27001

Continuous monitoring · next identity

Human-in-the-loop

The engine asks instead of guessing

Ambiguous columns or missing owners are never guessed. IAM Compass asks a concrete question – you decide via dropdown.

iam-compass / clarifications
IdentityQuestionAnswer
John DoeSource: FIN-OPS-2Clarify column 'Department'Finance
Sofia MillerSource: —Who is the deputy?Select…
Jonas Ferreira
Mara Brandt
No deputy
Jonas FerreiraSource: SAPMap role 'SAP_FIN_0815'Invoice approval
2 / 3 resolvedApply

Actionable error handling

A task checklist instead of cryptic error logs

If an Okta push fails, you get clear tasks in plain language – with cause, affected users and a one-click fix.

iam-compass / okta-push / tasks
Okta Push #09262 open
  • Group 'Finance-Approvers' missing in Okta

    Group created · 4 users

  • Mara Brandt is deactivated in Okta

    Skip leaver revoke or reactivate

    Resolve
  • Rate limit while pushing 12 changes

    Auto-retry in 2 min

    Resolve

Scalable compliance without draining resources

40+ hrs

Saves IT 40+ hours of manual work before every audit.

10–50×

A single failed audit costs 10 to 50 times as much as our platform.

ISO 27001

Foundation for ISO 27001: no transparent permission table, no certificate.

Early Adopter Program

Join early. Shape it. Benefit for good.

IAM Compass is a proof of concept we are growing into an enterprise platform together with our early adopters. You only pay the software license – we invest all the engineering in your requirements.

01

Software license

Your only cost: a fixed, discounted early-adopter license for ongoing operation.

02

Feature requests & co-engineering

Connectors, SoD rules, report formats: we build your prioritized requirements at no development cost to you – straight into the product standard.

03

Lifetime updates & price protection

All future releases and standard modules are included without upgrade fees. Your license price stays contractually capped as the platform grows.

PoC & validation

Pilot Partner

  • Offline CSV/JSON upload – no API needed
  • One source system, e.g. Okta or Entra ID
  • SoD conflict check & audit-ready evidence pack
  • One feature request committed to the roadmap
Apply as pilot partner
Enterprise rollout

Strategic Co-Innovation Partner

  • API connection to Okta, Entra ID, HR and ERP systems
  • Multi-system SoD & automated access reviews
  • Joint roadmap prioritization
  • Dedicated module engineering for your governance
Request co-innovation

Our security promise

Every feature request runs through our secure software development lifecycle: strict tenant isolation, automated SAST/DAST scans, four-eyes code review and privacy by design. Your identity data stays 100 % under your control and never leaves the EU.

Become an early adopter

Help shape IAM Compass.

Tell us which IAM or audit process costs you the most time today. Together we'll check whether an early-adopter partnership is a fit.

A CONVERSATION BETWEEN PEERS.

Dennis Kast

Fractional CISO & Founder

You speak directly with a certified IT security manager with senior experience in IGA, access reviews and regulatory audits – confidential and at C-level.

  • TÜV® IT Security Manager
  • TÜV® Information Security Officer (ISB)
  • CISM in progress
  1. 01Submit feature request
  2. 02Expert call with our CISO (30 min)
  3. 03Early-adopter agreement
  4. 04Co-engineering & lifetime updates

Partnership model

Contact us directly

Your details are used only to process your request. See the privacy policy for details.

Which topics matter most to you?