Discover. Review. Remediate.
Every access review ends the same way: sealed, tamper-evident evidence a named human can stand behind — not a spreadsheet, not a screenshot.
A review happening is not proof that it worked.
Most access review tools stop at the export. Three questions break them, and every one of them comes from your auditor.
“Who decided, exactly?”
A spreadsheet or a PDF export is not evidence. When the question is who decided, when, under which rules, and whether the record can be altered, most tools have no answer.
“Did the revocation take effect?”
Access marked “removed” is still there at the next campaign. Nothing tells you the decision had no effect — until an incident does it for you.
“Could your AI have approved this?”
Give an assistant enough context and eventually it decides. Under the AI Act you will be asked to prove yours never could — not that it was told not to.
Four things a dashboard cannot give you.
Proof that stands up, a guarantee that a human decided, an engine built for the whole estate, and the jurisdiction it all lives in.
Proof, not screenshots
Each campaign closes into a sealed evidence record: decisions, reviewers, timestamps, sign-off and scope, chained into a tamper-evident audit trail segmented per scope. Auditors get read-only access to the evidence, never to the decisions.
How SEAL and the audit trail work →A human decided. Guaranteed.
No decision action exists in RITA's contract, so the assistant cannot approve, revoke or sign. The platform never signs on anyone's behalf. Every AI turn is ledgered to the audit trail with the tools it actually invoked.
Meet RITA, and its guarantee →Built for the whole estate
A seven-step campaign wizard, perimeter conditions, quorum and policy rules in cascade, run across a growing catalogue of platforms — from Microsoft 365 and Entra to SAP, Salesforce and your own systems. Certification that scales with what you actually own.
The campaign engine →Sovereign by design
For public bodies and regulated organisations in any jurisdiction: data and keys where your law applies, no standing access for the publisher, proof your auditor verifies without us.
How sovereignty is built in →One loop, three acts.
Nothing is certified until it has been discovered. Nothing is closed until the decision is sealed.
Connect, collect, see.
Bind your solutions through their own identity, probe their health, scope what is collected. A growing catalogue of solutions, workloads and resource types, an identity directory collected from your providers, and a boundary per workspace. You cannot certify what you have not seen.
How discovery works →A named human decides.
Campaigns on who has access, who owns what, and whether a resource complies with your policies: privacy, sharing, inactivity, privileged access, your own rules. Named humans decide. The system never signs. Every closed occurrence is sealed into evidence.
The campaign engine →Close the loop, or it did not happen.
A revocation is worth nothing until it is applied. Temporary exceptions expire on a date. Deletion requests are tracked to execution. Your SOC sees every decision through BEACON, your tooling reads it through the API, and INSIGHTS tells you, campaign after campaign, whether a revocation took effect. Remediation actions written back to your systems are the next step.
What INSIGHTS finds →Each role gets exactly its surface.
Reviewers decide. Workspace managers run campaigns. Subscription administrators delegate governance and keep the boundaries. Auditors read and verify. No console approves anything on a reviewer's behalf.
Review Manager
The reviewer portal: a dense work queue, bulk decisions, contextual evidence, delegation in traced cycles, challenge and escalation, and a personal dashboard of what is due.
Workspace Manager
Campaign wizard, policy extensions, mail templates, reminders, reports, alert centre, audit trail and INSIGHTS. Guided onboarding on every screen, delivered as product data.
Subscription Manager
Workspaces as delegated governance with boundaries, features and credits. Entitlements, branding, retention, identity directory and security posture.
Delegated governance →Auditor
A read-only role with a banner and an expiry. Audit posture, audit trail, audit dossier with digest, evidence verification. Never a decision, never a campaign.
A fourth console, Cloud Manager, is operated by REVIEWIT only. It never takes a customer's colours, so operators always know whose estate they are acting on.
Reports prove the review happened. INSIGHTS tells you whether it worked.
The second campaign on the same scope should not cost the same and teach nothing. INSIGHTS forms series from campaign occurrences that share a workspace, resource key, policy and perimeter, then reconciles two closed occurrences object by object.
- Series. Which campaigns are comparable, ordered by arming date, with excluded terms and their reason.
- Differential. Kept, revoked, exception, divergent: every change of family between two occurrences, in numbers.
- Revocation without effect. Objects revoked last time and presented again. The module names the fact and both possible causes.
- Findings. Revocation effort, decision delays, concentration on a single reviewer, all from governed definitions.
An assistant that explains everything and can decide nothing.
Everyone has an AI in 2026. RITA's difference is underneath: its response contracts contain no decision action at all, its outputs are allow-listed, and every turn is written to the audit trail with the tools it really invoked. In front of the AI Act, or an auditor: our AI never could decide, and here is the proof.
- Context on demand. Why is this resource flagged, who owns it, what happened last campaign.
- Every role. Reviewers, workspace managers and subscription administrators get guidance scoped to what they may see.
- Multilingual. Answers in the reviewer's language, from the catalogue's governed definitions.
Built for the people who will ask for the proof.
A sealing authority
Sealing authority with a hardware-backed vault, per-subscription caller identities, revocation and renewal. The application host never issues its own credentials.
Audit trail
Hash-chained segments per scope, sealed at closure, purged only by segment and never by row. Read by subscription, exported for your auditors.
Identity broker
Identity broker in front of every console. Entra ID, Google and generic OIDC providers, MFA step-up on administrative surfaces, freshness checks.
SIEM streaming
Streams audit events to your SIEM, with a lease per destination and egress protection. Your security operations see what your reviewers did.
Public API
Automate campaigns, read outcomes and evidence from your own tooling. Review decisions themselves are never exposed to the API, by design.
Retention & holds
Declared retention per data category, contractual DPA clause, legal holds that suspend purge, deletion requests tracked to execution.
Pay for a campaign, or for an estate. Never for a feature.
Both editions run the same platform. The difference is how you consume it, and whether you want the platform to learn from one campaign to the next.
For a regulatory deadline, a first certification, or an audit finding to close. Credits are consumed per decision, per campaign.
- Every policy, every console, every connector
- Sealed evidence and audit trail included
- RITA included
- Credits purchased by card or invoice, valid for two years
For an estate under continuous certification. Tiered by governed identities, with unlimited campaigns and decisions across the term.
- Everything in OneShot, without counting decisions
- INSIGHTS: series, differential, revocation without effect
- Tier changes applied at term start, credits for exceptional needs
- Multiple workspaces with delegated governance
An open platform. Your estate is the catalogue.
REVIEWIT is not a fixed list of connectors. It is a connection model: any solution that can be bound through an identity, probed and collected becomes a set of workloads and resource types the certification engine reviews like any other. The catalogue grows with every customer, and the systems below are where it started, not where it stops.
One connection model
Identity, health probe, scope per channel, planned collection. Bind a system once; every policy applies.
Solutions, workloads, resources
Each system is described as workloads and resource types with their attributes, so campaigns and INSIGHTS treat them alike.
Your systems, on request
Internal applications, file shares, on-premise platforms, business systems: brought in through the same model, on your schedule.
Import and API
Manual import is an executor like any other. The public API reads what the platform holds. Nothing is locked to a vendor.














The questions your estate can be asked — and the one only you can write.
A policy is a campaign extension with its own settings, not a hard-coded mode. The same engine, the same evidence, whichever question you put to the estate.
Ready to certify with proof?
A tailored walkthrough on your real scope: access, ownership, external sharing, privileged access, or your own policy. Leave with a clear view of the evidence you would hand your auditor.


