Access Governance

Know who has access.
Know why they have it.

A live platform for tracking which staff, vendors, and contractors have access to what, mapped against role, clearance level, and business justification. Built for the access sprawl that accumulates quietly and only surfaces during an investigation.

Access Risk Register

Your full user access inventory, with risk scoring built in.

The Access Risk Register maps every user account across your systems, matched to the person's role, department, and approved access scope. Access that falls outside defined role boundaries is flagged automatically for review.

Each record carries a live risk score based on access scope, last review date, and any unresolved flags. The register is the foundation every other module in the platform builds on.

Features
Complete user-to-system access inventoryAutomated out-of-scope access flaggingLive risk scoring per user recordBulk import from directory and HR systems

Departure Risk Log

Capture what leaves with an employee before the door closes.

When someone resigns, is dismissed, or transitions roles, the window between their last productive day and full access revocation is when most insider exfiltration happens. The Departure Risk Log creates a structured record for each departure, covering access revocation status, device returns, and activity review.

Upload final-day activity reports, email archives, or cloud storage exports for AI-assisted review. The AI surfaces what may warrant further attention. A reviewer confirms or dismisses each finding before anything is escalated. No automated accusations.

Features
Structured off-boarding record per departureAI-assisted document upload for activity reviewAccess revocation tracking against timelineReview workflow with sign-off capture
Departure Risk Log
Departure Risk Log showing a flagged employee departure record with AI-surfaced document findings awaiting reviewer confirmation

Providers and Vendors

Third-party access is often the largest unmanaged risk in an organisation.

Vendors, contractors, and service providers often hold access that outlasts the engagement, is broader than needed, and is rarely reviewed. The Providers and Vendors module maintains a dedicated inventory of every third-party entity with system access, with the same risk-scoring logic applied to internal users.

Each provider record captures the scope of access, the business owner who approved it, the review date, and the contractual access period. Access nearing expiry or already overdue generates a review prompt automatically.

Features
Dedicated third-party access inventoryAccess scope and approval documentationAutomated review prompts on access expiryVendor risk scoring alongside internal users

Privileged Access Management Log

Admin accounts are your highest-value target. Treat them that way.

Privileged accounts, administrators, superusers, and service accounts with elevated permissions, carry disproportionate risk. The PAM Log maintains a separate, tightly controlled inventory of all privileged access within the organisation.

Every privileged account is tracked against its owner, the business justification for the privilege level, and the last review date. The log integrates with the Access Risk Register and generates priority review queues for any account with an elevated risk score.

Features
Dedicated privileged account inventoryBusiness justification documentation per accountPriority review queue for high-risk accountsIntegration with the main Access Risk Register

Staff Vetting

Know what checks were done before access was granted.

Access governance is not only about what people currently have. It is about what was verified before they received it. The Staff Vetting module attaches pre-employment and ongoing vetting records to the user profile in the Access Risk Register.

Verification types, reference checks, background screening, right-to-work confirmation, role-specific clearances, are documented and linked to the access scope granted. This creates an auditable chain from vetting to access grant to ongoing review.

Features
Vetting record attachment to user profilesMultiple verification type supportAccess-to-vetting gap reportingAudit-ready vetting trail export
Platform Dashboard
Access Governance Tracker main dashboard showing the access risk register with live risk scores across user accounts

Evidence Library

Store, organise, and retrieve access governance evidence in one place.

Access governance generates a significant volume of evidence: review sign-offs, approval emails, revocation confirmations, vetting reports. The Evidence Library provides a structured document store linked to the specific records they support.

Every document uploaded to the Evidence Library is tagged to a user, vendor, or system record. Retrieval for audit or investigation is a search rather than a folder hunt. Signed access reviews, approval chains, and departure records are all surfaced from a single location.

Features
Linked document storage per record typeFull-text search across uploaded evidenceAudit-package export for regulatory submissionsVersion control on updated documents

The Review Queue

Everything the platform flags waits for a human before it becomes a finding.

Automated tools produce noise. The Review Queue exists to ensure that nothing the Access Governance Tracker surfaces becomes a fact in the record without a human reviewer confirming it.

Risk flags, AI-assisted departure document findings, access-scope alerts, and expiry prompts all flow into the Review Queue before they are written to the relevant record. Reviewers see the flagged item, the reason it was flagged, and a clear accept or dismiss action. Accepted items become part of the audit record. Dismissed items are logged with the reviewer's notes. No automated decision stands without sign-off.

Features
Centralised triage point for all automated flagsAccept or dismiss workflow with note captureFull audit trail of reviewer decisionsEscalation path for items requiring senior review
Pricing

Simple, transparent pricing.
No hidden fees.

Starter
NGN49,900
per month
Start Free Trial
What's Included
Up to 3 team membersAccess Risk RegisterDeparture Risk LogProviders and Vendors modulePrivileged Access Management LogStaff VettingEvidence LibraryReview Queue
Most Popular
Growth
NGN99,900
per month
Start Free Trial
What's Included
Unlimited team membersAccess Risk RegisterDeparture Risk LogProviders and Vendors modulePrivileged Access Management LogStaff VettingEvidence LibraryReview QueueRegulatory UpdatesHistorical risk trend chart
Enterprise
NGN199,900
per month
Start Free Trial
What's Included
Unlimited team membersAccess Risk RegisterDeparture Risk LogProviders and Vendors modulePrivileged Access Management LogStaff VettingEvidence LibraryReview QueueRegulatory UpdatesHistorical risk trend chart
Questions

Frequently asked

Most institutions have access data scattered across a cloud console, a spreadsheet, and someone's memory. The Tracker pulls it into one place with a real governance score, so the answer to who has access to what is always ready, not reconstructed under pressure.

It is read automatically and lands as a draft, never live instantly. A person reviews and confirms it before it becomes part of your real record. Nothing automated ever becomes fact on its own.

Yes, a free trial with no card required.

The platform has been through independent security testing, and every account and organisation is fully isolated from every other client on the platform.

Companion Platform

Already managing access governance? Add compliance tracking with Vironix Comply.

Vironix Comply works alongside the Access Governance Tracker. Connect the two platforms and compliance evidence links directly to the relevant access records. No manual cross-referencing.

Explore Vironix Comply
Insider risk doesn't wait.
Neither should your defences.

Book a confidential 30-minute consultation. No obligation, no sales pitch.

Book a Consultation