Directory Hygiene

See it in action

A walk through the real product: real screens against a real dev tenant, the end-to-end flow it actually runs, and why it matters before a certification programme can mean anything.

The demo

The real flow, screen by screen

Every screen below is the actual tool, against a real dev tenant, not a mockup.

How it actually runs

The real end-to-end flow

This is the actual sequence a finding goes through today, worth following in order, since each step answers the objection the previous one raises.

Step 1

Sync

Pulls real users and groups straight from Microsoft Graph into a local shadow copy: nothing hypothetical, this is the organisation's actual directory.

Step 2

Evaluate

Hygiene rules run against that data and open (or close) findings: user missing surname, privileged group has no description, group has no owner, user has no manager, and more.

Step 3

Resolve

The "who do I even ask" problem, automated: check the live directory, check a connected HR system, email the most plausible person, then fall back to a manual pick: one chain, used the same way whether you're on Findings or the Directory Map.

Step 4

Propose

A specific fix is drafted (the exact field, the exact new value) and saved as a pending proposal. Nothing has touched the real directory yet.

Step 5

Sign off & approve

A reviewer approves: in-app, with an optional digital sign-off (typed name, or a real WebAuthn device signature), or via a real one-click email link that still enforces the same sign-off, no login required.

Step 6

Execute & record

Only now does the one real Graph write happen, immediately mirrored back into the app so it's reflected without waiting on the next sync, and logged permanently to an audit trail: who, when, what changed, what it was before.

Why it matters

  • Audit-ready by construction
    Every change carries who approved it, when, and what it replaced, not reconstructed after the fact for an auditor.
  • The triage work disappears, not the decision
    Finding the right person to ask is automated; deciding whether a change is right stays with a reviewer, every time.
  • A real prerequisite for certification programmes
    Clean ownership and attribute data underneath a certification decision, not assumed to already be there.
  • Consistency that holds over time
    One rule set, one resolver chain, one approval model, applied the same way whether it's the first finding or the thousandth.

Not a replacement for your IGA platform: the prerequisite that makes one actually work. A full IGA platform assumes your directory data is already clean: a group with no owner can't be certified to anyone, a user with no manager breaks approval chains, regardless of which platform enforces them. Directory Hygiene is the layer underneath, getting your data ready for governance, not replacing the governance tool itself.

Wondering how this would look against your own directory?

Talk to us about a Directory Hygiene Review, or read what the engagement itself includes.

See the Review →
Talk to us

Talk to us

Tell us a little about what you need, and we'll reply within one business day.

Prefer to book a call directly? →