Skip to content
FidarTrust fabric // boot

Initialising trust fabric

000

Human identity & governance

Identi5

A unified IAM and identity governance layer for workforce access — spanning SSO, phishing-resistant MFA, lifecycle, provisioning, access reviews and policy-driven governance.

EMP-20417

Finance analyst

PROVISIONED

  • SSO · EmailGrantedRole · Finance analyst
  • ERP · ReadGrantedRole · Finance analyst
  • Payments · ApproveGrantedApproved · Finance manager
  • Treasury · SignNo accessNot part of the role
  • Core banking · ReadNo accessNot part of the role
  • Vendor portalGrantedTime-bound · 30 days

Joined Finance · 4 entitlements provisioned by role

The scale of the problem

Too much access. Too little visibility.

of identity attacks are password-based.
97%

of identity attacks are password-based.

Source · Microsoft Digital Defense Report 2025 / Microsoft Security
of organizations say human identities have more access than their roles require.
96%

of organizations say human identities have more access than their roles require.

Source · Palo Alto Networks, 2026 Identity Security Landscape
of additional response time per identity incident, on average, linked to disconnected identity systems.
12 hours

of additional response time per identity incident, on average, linked to disconnected identity systems.

Source · Palo Alto Networks, 2026 Identity Security Landscape
Identity Governance & Administration


Bring approvals, entitlements, certifications and continuous review into the same identity operating model.

01 / 05 · PROVISIONprovisioningPOLICY-BASED
01

Access that arrives with the role

Joiner events provision exactly what the role defines — on day one, without a ticket someone has to remember to raise.

02

Access requests with a reason

Structured request and approval workflows for applications, roles and entitlements — every grant keeps the approval that produced it.

03

Continuous reviews

Revalidate access against role, risk, usage, ownership and business context — continuously, rather than once a year.

04

Segregation of duties

Detect and prevent toxic access combinations — the approver who can also pay — before they become control failures.

05

Access that leaves with the person

Mover and leaver events withdraw what the role no longer justifies, with the revocation recorded as evidence.

Identity & access management

  1. SSO

    SSO & IdP

    Centralize authentication across enterprise applications and reduce fragmented identity journeys — one place a workforce identity is established, rather than one per application.

  2. MFA

    Phishing-resistant MFA

    Apply stronger authentication where risk, policy or application sensitivity requires it, rather than applying the same friction everywhere and calling it a standard.

  3. LIFECYCLE

    Identity lifecycle

    Automate joiner, mover and leaver processes with policy-based provisioning and deprovisioning — so access arrives with the role and leaves with it.

  4. REVIEWS

    Certification & revocation

    Revalidate access against role, risk, usage and ownership. A review that cannot take an entitlement away is a report, not a control.

Entitlements with a reason

Approvals, certifications and revocations are recorded as they happen — so an audit reads the history instead of reconstructing it.

  1. 01Requested

    A person, a role or a system asks for access — through a structured workflow, not an email.

  2. 02Approved

    The owner and the policy agree, and the approval is attached to the grant it produced.

  3. 03Provisioned

    Access lands in the application automatically, bounded by role and, where it should be, by time.

  4. 04Used

    Usage is observed, so a review can tell access that is needed from access that is merely held.

  5. 05Reviewed

    Revalidated against role, risk, usage and ownership — continuously rather than once a year.

  6. 06Revoked

    When the reason ends, so does the access. Mover and leaver events withdraw it without waiting for a ticket.

  7. 07Evidenced

    Every step above, recorded as it happened and ready for audit.

One operating model


Lifecycle

Joiner, mover, leaver

Provisioning and deprovisioning driven by the role a person actually holds, not by a ticket someone remembered to raise.

Approvals

Entitlements with a reason

Every grant carries the policy and the approval that produced it, so a review has something to review against.

Elevation

Privileged access

Elevated rights treated as a state with an expiry rather than a permanent property of an account.

Non-employees

Vendors and contractors

Non-employee identities governed on the same plane, with the time bounds their engagements already have.

Audit

Audit-ready evidence

Approvals, certifications and revocations recorded as they happen, rather than reconstructed at audit.

Ecosystem

Integration-first

Work with the IdPs, HR systems, applications and SIEMs already in place instead of replacing the stack around them.

Cryptographic agility


Identi5 is designed around algorithm agility, so the enterprise can move toward post-quantum cryptographic standards without rebuilding the identity layer from scratch.

Book a Demo