See it in action
A walk through the real product: real screens against a real dev tenant, the end-to-end flow it actually runs, and why it matters before a certification programme can mean anything.
The real flow, screen by screen
Every screen below is the actual tool, against a real dev tenant, not a mockup.
The real end-to-end flow
This is the actual sequence a finding goes through today, worth following in order, since each step answers the objection the previous one raises.
Sync
Pulls real users and groups straight from Microsoft Graph into a local shadow copy: nothing hypothetical, this is the organisation's actual directory.
Evaluate
Hygiene rules run against that data and open (or close) findings: user missing surname, privileged group has no description, group has no owner, user has no manager, and more.
Resolve
The "who do I even ask" problem, automated: check the live directory, check a connected HR system, email the most plausible person, then fall back to a manual pick: one chain, used the same way whether you're on Findings or the Directory Map.
Propose
A specific fix is drafted (the exact field, the exact new value) and saved as a pending proposal. Nothing has touched the real directory yet.
Sign off & approve
A reviewer approves: in-app, with an optional digital sign-off (typed name, or a real WebAuthn device signature), or via a real one-click email link that still enforces the same sign-off, no login required.
Execute & record
Only now does the one real Graph write happen, immediately mirrored back into the app so it's reflected without waiting on the next sync, and logged permanently to an audit trail: who, when, what changed, what it was before.
Why it matters
- Audit-ready by construction
Every change carries who approved it, when, and what it replaced, not reconstructed after the fact for an auditor. - The triage work disappears, not the decision
Finding the right person to ask is automated; deciding whether a change is right stays with a reviewer, every time. - A real prerequisite for certification programmes
Clean ownership and attribute data underneath a certification decision, not assumed to already be there. - Consistency that holds over time
One rule set, one resolver chain, one approval model, applied the same way whether it's the first finding or the thousandth.
Not a replacement for your IGA platform: the prerequisite that makes one actually work. A full IGA platform assumes your directory data is already clean: a group with no owner can't be certified to anyone, a user with no manager breaks approval chains, regardless of which platform enforces them. Directory Hygiene is the layer underneath, getting your data ready for governance, not replacing the governance tool itself.
