- Automated onboarding checklists: training, policy acceptance, MFA enrollment, device compliance
- Quarterly access reviews with reviewer assignments, deadlines, and escalation
- Offboarding workflows that verify access revocation across every connected system
- Security awareness training tracking with completion evidence
- Role-based access provisioning tied to your identity provider
- Periodic access recertification with documented reviewer decisions
- Timely deprovisioning verification on termination
- Onboarding completion records per employee with timestamps
- Access review campaigns with decisions mapped to SOC 2 CC6 and ISO A.5/A.8
- Offboarding verification logs proving revocation within policy SLA
Okta · Google Workspace · Microsoft Entra · Rippling · BambooHR
Access control failures are the most commonly cited finding in first-time audits, and they’re almost never technical — they’re procedural. The offboarding that happened four days late. The access review that skipped the finance system. The contractor nobody re-certified. This module makes the procedures self-executing.
SOC 2 Compliance Services — Hands-on SOC 2 compliance services: gap assessment, control implementation, evidence collection, and audit support — platform included, experts driving.
What do auditors sample from people management?
New-hire and termination samples are near-universal: auditors pick employees who joined or left during the period and ask for onboarding records, training completion, and proof access was revoked on time. The module produces exactly those artifacts.
Can access reviews cover systems outside our SSO?
Yes. Connected systems populate automatically; long-tail tools are covered through structured manual review tasks so the campaign record stays complete.