Governance

Policy for every identity.Evidence for every decision.

Governance for people is built on joiners, movers, leavers and reviews. Trustivan gives machine identities the same discipline: policy that states what is expected, certification that confirms it, requests and remediation that change it, and evidence that proves it.

Availableownership, access requests, certification and audit

Available: ownership, certification (API), access requests, audit · Future capability: provider-side remediation, SIEM and ITSM

Machine identity certification · Q3

312 identities · 5 reviewers · due in 9 days

Open
  • Certified 77%
  • Revoked 4%
  • Pending 19%
  • PLPlatform team92/104
  • DSData services55/71
  • MLML platform28/52
  • STSecurity tooling37/47
  • ?Unowned identitiesassign an owner first0/38

Illustrative · certification campaigns are API only today

The problem

Governance stopped at the human directory.

The discipline exists — reviews, approvals, audit trails. It was simply never applied to the identities that now outnumber the people it was built for.

Reviews stop at people

Quarterly access reviews cover humans; the service accounts they created are out of scope

Fixes live elsewhere

Findings sit in one console and remediation happens in five others, with nothing linking them

Evidence by hand

Audit time means screenshots and spreadsheets instead of records with timestamps

How it works

Policy. Certify. Request. Remediate.

One loop for every identity type, running on the inventory, ownership and risk context the platform already holds — with evidence written at every step.

  1. Policy

    Tune the thresholds of built-in policies for ownership, staleness, rotation and exposure

  2. Certify

    Run certification campaigns (API) that ask a named reviewer to certify or revoke; record every decision

  3. Request

    Route time-bounded access and policy exceptions through requests another person approves

  4. Remediate

    Assign an owner or quarantine from the finding, propose provider changes for approval, and write the result to the audit trail

What you get

The controls an auditor recognizes, applied to machines.

Each control is labelled by availability, so a governance program can be planned against what exists today and what does not yet.

Policy

Tune the thresholds of 26 built-in posture policies and scope exceptions with second-person approval and expiry

Available

Certification campaigns

Ask a named reviewer to certify or revoke identities, credentials, tools and teams — API only, no console screen yet

Available

Access requests

Request time-bounded access of up to seven days, approved by someone other than the requester, and recorded

Available

Remediation workflows

Propose actions from a finding, require a second person’s approval and record the outcome; execution at a provider is not built

Available

Audit and evidence export

Export hash-chained audit records with a manifest, verifiable offline, for auditors and incident reviews

Available

SIEM and ITSM handoff

Send findings, incidents and evidence to your SIEM and ticketing workflows

Future capability
Remediation

Remediate from the finding.

A finding that cannot be acted on is a report. Trustivan attaches the available actions to the finding itself — assign an owner or quarantine in the platform today; propose rotation, scoping or revocation for a second person's approval; hand-off to SIEM or ticketing systems is a future capability — and writes every action to the audit trail.

  • Owner first: almost every remediation needs a human decision, so attribution is the first action offered.
  • Labelled by availability, so a workflow is never promised before it exists.
  • Audit trail by default: actor, time, evidence and outcome on every action, exportable on request.

Availableassign owner · quarantine in platform · audit

Future capabilityrotate · scope · revoke at the provider · SIEM and ITSM handoff

Explore NHI risk
HighUnowned identity

svc-billing-exportlong-lived key · reachable production data

  1. Assign ownerAssign the team accountable for it; the change is written to the audit trailevidence: owner record · actor · time
    Available
  2. Quarantine in platformMark the identity quarantined; the runtime gate then denies every action it attemptsevidence: lifecycle change · actor · time
    Available
  3. Record a ticketRecord a ticket or an owner notification against the finding; no ITSM or SIEM integration yetevidence: ticket record · actor · time
    Available
  4. Rotate credentialReplace the 611-day access key at the provider — proposal and second-person approval are recorded today; execution is notevidence: proposal · approval · no provider executor
    Future capability
  5. Scope roleReduce export-admin at the provider; which permissions are used is not observedevidence: proposal · effective access re-evaluated
    Future capability
  6. Revoke at providerDisable the key at AWS when compromise is suspectedevidence: proposal · approval · no provider executor
    Future capability
Every action is written to the audit trail with actor, time and evidenceIllustrative · sample environment

Govern every machine identity with evidence.

A demo walks through a time-bounded access request, a policy exception and a remediation proposed from a finding — and the evidence each one leaves behind.