Engineering & Data

Who still has access to what,
reviewed on a schedule, not forgotten about

Access piles up and nobody cleans it out. A contractor's account from a project that ended months ago. A permission granted for one task, never removed after. This agent tracks who has access to what across your systems. It flags what looks stale or too broad, and prepares a revocation list for your review. It never revokes anything on its own. Your team approves every change.

from$2,000
Timeline2 to 3 weeks
What is includedAgent wired into your identity provider and HR rosterScheduled review of every account against who should still have accessFlags for stale accounts, over-broad permissions and offboarded staffRevocation list prepared for human approval, never auto-executedEvery recommendation logged with its reasoning
8agents under one governed, access-scoped team on a marketplace we run
0access revoked without explicit human approval
quarterlyreview cadence built in by default, not left to whenever someone remembers

Where access quietly outlives its reason

Offboarding a contractor or an employee usually covers the obvious systems: email, the main app. It quietly misses the smaller ones: an analytics dashboard, a shared drive folder, an admin panel for a tool nobody thinks of as sensitive. That access stays open. Not because anyone decided it should. Because nobody runs the full checklist every time.

Permission creep is the second leak. Someone gets elevated access for a specific task, finishes the task, and keeps the access because removing it was never anyone’s job. Multiply that across a team over a year and the actual access map looks nothing like the org chart.

Timing is the third problem. Access reviews, when they happen at all, happen reactively, after an audit requirement or a security scare. Not on a schedule that would have caught the problem months earlier.

What the agent checks, every cycle

The agent cross-references your identity provider, your HR roster, and the admin panels of your key systems. It builds a picture of who has access to what, and checks that against who should, based on current role and recent activity. It flags stale accounts (people who left months ago but still have a login) and over-broad permissions (access well beyond what someone’s current role needs). Then it prepares a clear revocation list with the reasoning behind each item.

A quarterly review cadence runs by default. This does not depend on someone remembering to ask for it, while it still waits for a human to approve before anything actually changes.

Typical scope: identity provider accounts, key system admin panels, and cross-referencing against HR status. It surfaces the picture. Your team decides what to do with it.

What your team still decides

Approving the revocation list, every single item, stays a human action. Granting new access is a judgment call that belongs with your team, not the agent. So is deciding on exceptions where someone genuinely needs broader permissions than their role suggests.

The safety rules behind it

The agent never revokes access on its own, under any configuration. It only recommends. Every recommendation is logged with the specific reasoning behind it, so an approver can check the logic, not just the conclusion. The review runs on a fixed schedule by default, quarterly, so it does not silently lapse.

Price and timeline

Option Price What it covers Timeline
Agency runs it from $2,000 + support plan Agent built and run by us, quarterly review delivered to your team for approval 2 to 3 weeks
Full control, handover-ready from $3,000 Same agent on your own identity provider, documented process, your team runs and approves it 3 to 4 weeks

Running cost is usually $10 to $40 a month in model usage.

See the AI agents service page and automation-everything for the surrounding build. Within this group: security monitoring agent and AI policy and guardrails agent cover adjacent governance ground. For a related one-time setup, see automate access reviews and offboarding. Real governance discipline behind this page: the ProBay AI agent team case study, where every agent’s access is scoped and reviewed, not assumed.

Not sure who still has access to what, after the last few people who left? Get in touch and we will map your current access first.

FAQ

How much does an access and permissions agent cost?

From $2,000 to wire into one identity provider and HR roster, live in 2 to 3 weeks. Multiple systems with separate access models usually run $3,000 to $4,500.

How long before the first real review?

2 to 3 weeks. Connecting to your identity provider and HR data takes about a week. Then the first full review runs. Your team checks it before the quarterly cadence starts.

Which tools does it work with?

Your identity provider (Google Workspace, Okta, or similar), admin panels for key systems, and your HR roster or offboarding checklist. It cross-references who should still have access against who actually does.

What if it flags the wrong account, or misses one?

Every recommendation is logged with its reasoning. A wrong flag is easy to spot and correct. A miss gets added to its checks the same review cycle. Nothing is revoked until your team reviews the list.

Can it actually remove someone's access?

No. It prepares a reviewed list. A person on your team approves and executes every revocation. That is deliberate. Access changes are exactly the kind of irreversible step that should never run on an agent's own judgment.

Start here

Tell us the problem.
We bring the system.

A 30-minute call, then a written plan with numbers within 48 hours. No obligation. If we are not the right fit, we will say so and point you to someone who is.

LIKE WHAT YOU SEE?

This site is our work.
Want one like it?

Ten languages, no page builder, launched in 2026 by a team working since 2015. We can build the same quality into your site.

  • 10 languages
  • Since 2015
Get a site like this →