Access Risk Register
Your full user access inventory, with risk scoring built in.
The Access Risk Register maps every user account across your systems, matched to the person's role, department, and approved access scope. Access that falls outside defined role boundaries is flagged automatically for review.
Each record carries a live risk score based on access scope, last review date, and any unresolved flags. The register is the foundation every other module in the platform builds on.
Departure Risk Log
Capture what leaves with an employee before the door closes.
When someone resigns, is dismissed, or transitions roles, the window between their last productive day and full access revocation is when most insider exfiltration happens. The Departure Risk Log creates a structured record for each departure, covering access revocation status, device returns, and activity review.
Upload final-day activity reports, email archives, or cloud storage exports for AI-assisted review. The AI surfaces what may warrant further attention. A reviewer confirms or dismisses each finding before anything is escalated. No automated accusations.
Providers and Vendors
Third-party access is often the largest unmanaged risk in an organisation.
Vendors, contractors, and service providers often hold access that outlasts the engagement, is broader than needed, and is rarely reviewed. The Providers and Vendors module maintains a dedicated inventory of every third-party entity with system access, with the same risk-scoring logic applied to internal users.
Each provider record captures the scope of access, the business owner who approved it, the review date, and the contractual access period. Access nearing expiry or already overdue generates a review prompt automatically.
Privileged Access Management Log
Admin accounts are your highest-value target. Treat them that way.
Privileged accounts, administrators, superusers, and service accounts with elevated permissions, carry disproportionate risk. The PAM Log maintains a separate, tightly controlled inventory of all privileged access within the organisation.
Every privileged account is tracked against its owner, the business justification for the privilege level, and the last review date. The log integrates with the Access Risk Register and generates priority review queues for any account with an elevated risk score.
Staff Vetting
Know what checks were done before access was granted.
Access governance is not only about what people currently have. It is about what was verified before they received it. The Staff Vetting module attaches pre-employment and ongoing vetting records to the user profile in the Access Risk Register.
Verification types, reference checks, background screening, right-to-work confirmation, role-specific clearances, are documented and linked to the access scope granted. This creates an auditable chain from vetting to access grant to ongoing review.
Evidence Library
Store, organise, and retrieve access governance evidence in one place.
Access governance generates a significant volume of evidence: review sign-offs, approval emails, revocation confirmations, vetting reports. The Evidence Library provides a structured document store linked to the specific records they support.
Every document uploaded to the Evidence Library is tagged to a user, vendor, or system record. Retrieval for audit or investigation is a search rather than a folder hunt. Signed access reviews, approval chains, and departure records are all surfaced from a single location.
The Review Queue
Everything the platform flags waits for a human before it becomes a finding.
Automated tools produce noise. The Review Queue exists to ensure that nothing the Access Governance Tracker surfaces becomes a fact in the record without a human reviewer confirming it.
Risk flags, AI-assisted departure document findings, access-scope alerts, and expiry prompts all flow into the Review Queue before they are written to the relevant record. Reviewers see the flagged item, the reason it was flagged, and a clear accept or dismiss action. Accepted items become part of the audit record. Dismissed items are logged with the reviewer's notes. No automated decision stands without sign-off.
Simple, transparent pricing.
No hidden fees.
Frequently asked
Already managing access governance? Add compliance tracking with Vironix Comply.
Vironix Comply works alongside the Access Governance Tracker. Connect the two platforms and compliance evidence links directly to the relevant access records. No manual cross-referencing.


