Offer · Operate Early access

You know how many people work here.
Nobody knows how many accounts do.

Service accounts, keys, secrets, certificates, privileged accounts, agent identities. They outnumber your employees, most of them answer to nobody, and everyone is afraid to turn one off. Identity Hygiene builds the list, finds each one a named owner, keeps them rotating, and retires what nothing uses — after proving nothing uses it.

Five steps, on repeat

1

Inventory

Every source you connect is read into one list, and a source that could only be read halfway is reported — never counted as small.

2

Own

Each identity gets a request in your own service desk, aimed at the team the estate says it belongs to, asking for one named person.

3

Rotate

What is past your policy age is batched by system and window, with the consumers listed, the order fixed and a way back written down.

4

Re-certify

Each owner confirms, on your cycle, that what they own is still needed, still theirs and still at the right level of access.

5

Retire

Only after every system holding it has reported your whole quiet period without seeing it used — and only by disabling it, never deleting.

Turning off the wrong account is an outage

What breaks is almost never the thing on the label. It is a nightly job, a partner's connection, a monitoring probe — something nobody wrote down. So an identity is never retired because it looks quiet. Four verdicts, and three of them stop the work.

Safe to propose

Every system holding it reported your whole quiet period and none of them saw it used. That earns a proposal to a person — not an action.

Still in use

Something used it inside the window. It stays, and we propose narrowing what it can reach instead.

Not enough evidence

A gap in the window, a log that only goes back so far, or a system nobody checked. Missing evidence is not evidence of non-use.

Never touched

Break-glass accounts and anything with a declared dependency are excluded whatever the evidence says.

And when a proposal does turn out to be wrong: the action was a disable with a restore path, so it is undone in a minute — and the reversal is recorded as evidence that the evidence was wrong. Nothing on this team deletes an identity.

What the agents may not do when they start

Never, at entry

  • Delete an identity — under any policy, at any level of trust
  • Disable anything without a person approving that exact identity
  • Act outside an authorised change, or outside its window
  • Read the value of a secret, or put a key in a ticket
  • Rotate a credential whose consumers nobody could list
  • Treat a missing log as a quiet account
  • Accept a team, a group or a mailbox as an owner

Always

  • Only one agent can change an identity, and only reversibly, one at a time
  • The agent that builds the list cannot act on it; the one that can act cannot build it
  • Coverage is stated before any count — which sources were read, and how completely
  • Every proposal carries what would break if it is wrong, and how to undo it
  • Every reading, verdict and action leaves a record

Autonomy earned per class

A class is one kind of identity, in one system, at one level of privilege. Each climbs on its own record and drops back on its first failure.

Inventory & reports

Runs on its own from day one. It reads and reconciles; it changes nothing.

Owner campaigns

Requests and reviews are raised and chased automatically in your service desk — a ticket commits nothing and is reversible.

Rotation

Planned by the team, executed by your platform or your people. Execution moves to the team one pre-approved class at a time, non-production first.

Disabling

A person approves each one at entry. A class earns a standing approval only on a verified record: nothing reversed for being wrong, every action backed by evidence covering the full period, and a restore drill passed.

Deletion

Never. It is irreversible and it destroys the trail that justified it, and a disabled identity is restored in a minute.

One reversal caused by a wrong verdict, or one identity touched outside its change, and the class drops back the same day.

What is live, what early access adds

Live on the platform today

  • Read connectors to identity providers, identity governance, privileged-access vaults and secret stores
  • A distinct cryptographic identity for every agent you run here, with its own signing key
  • Requests, reviews and change records raised in your own service-management tool
  • Tamper-evident audit trail of every reading, verdict and action
  • Autonomy earned on measured results
  • Installation on your premises

Built with early-access customers

  • Cross-source reconciliation with ownership, rotation and use verdicts per identity
  • Evidence-based revocation judgement over your quiet period
  • Cloud identities — access keys, roles and cloud service accounts need a read we do not have yet, and until then they are reported as outside the list
  • Rotation carried out by the team rather than planned for your platform

Priced per band of governed identities, plus per identity brought under ownership. Your own identity and operations teams run it. Rotations and revocations can take the same governed path as every other production change through Change Guard, and the agents in your estate are governed by Agent Fleet Guardian. For a one-off proof that each agent's identity, delegation chains and human accountability hold up, see Agent Identity & Delegation Assurance — that is the assessment; this is the running service.

See every offer