IT · Colleague: Ivy

Access that runs itself

Define your approval policies once and let BeforeQuery grant, revoke, and enforce least-privilege access across your identity providers — with time-boxed elevations, quarterly reviews, and an audit trail on every change.

Phase 2 · Q1
Capability 01

Just-in-time elevation

Chat request from Slack or Teams: role, justification, duration. Routed to the owning team lead and security per your Approval Policy. On approval, scoped role is granted with an auto-expiry edge in the Context Graph. When it expires, the revoke fires automatically. Every grant and revoke lands in the audit log.
grounded answer · sources
answer

Priya’s Okta lockout can be cleared via self-serve MFA challenge — no IT intervention required. If MFA fails, escalate to IT on-call.

cited from
01
IT · Okta account lockout policy
runbook · updated 4d ago
02
HR · Emergency access procedure
policy · updated 2w ago
03
Ticket #48211 · priya · resolved
past ticket · similar match
Capability 02

Grant and remove automatically

New hires provisioned on day 0 from your HRIS event: identity, SSO groups per role template, SaaS licences, MDM enrolment. Contractors revoked on their contract end date without a ticket. Role changes cascade to group memberships across every identity provider you use.
approvals · pending 4
unlock okta account
priya.sharma · self-serve · read-only
denyapprove
refund $128.40
stripe · ord_A4b2c · manager approval
denyapprove
revoke prod IAM role
aws · role/analyst · step-up MFA
denyapprove
reset zoom SSO
kiran.mehta · self-serve
denyapprove
Capability 03

Access reviews on schedule

Quarterly campaigns, or on any cadence you set. Reviewer packets are generated per manager — one row per employee they own, one column per entitlement — with an approve/revoke/delegate control. Auto-revoke on 'revoke' decisions and on missed deadlines. Evidence bundled for SOC 2.
context · priya.sharma
priyateamon-calloktagithubworkday
Capability 04

Grounded in your live directory

Reads Okta, Microsoft Entra ID, Google Workspace, GitHub, AWS IAM, GCP IAM, Salesforce, plus the SaaS licence catalogue. The Context Graph keeps ownership, group membership, and access grants live to the second, so every request runs against the current state — not last week's snapshot.
reports · this week
Auto-resolved
78.4%
+4.1 pt
Avg. loop time
11.4s
-2.1s
Approvals pending
12
-3
Coverage
94%
+1.2 pt
monsun
Capability 05

Import your access matrix

Start from a spreadsheet (which role gets which entitlements), from your existing IdP's group definitions, or from a JIT policy DSL. Once imported it's the source of truth for every new-hire template, JIT policy, and quarterly review.
grounded answer · sources
answer

Priya’s Okta lockout can be cleared via self-serve MFA challenge — no IT intervention required. If MFA fails, escalate to IT on-call.

cited from
01
IT · Okta account lockout policy
runbook · updated 4d ago
02
HR · Emergency access procedure
policy · updated 2w ago
03
Ticket #48211 · priya · resolved
past ticket · similar match
Capability 06

Step-up MFA on the reviewer

Sensitive grants — production role, prod database access, admin roles — require a fresh MFA challenge on the approver, not the requester. WebAuthn passkeys, hardware keys, TOTP. Every decision recorded with the device fingerprint of the reviewer.
approvals · pending 4
unlock okta account
priya.sharma · self-serve · read-only
denyapprove
refund $128.40
stripe · ord_A4b2c · manager approval
denyapprove
revoke prod IAM role
aws · role/analyst · step-up MFA
denyapprove
reset zoom SSO
kiran.mehta · self-serve
denyapprove
The BeforeQuery method

Visibility. Reasoning. Action.

Every playbook, every action, every answer follows the same three-beat rhythm — one that keeps every write behind evidence and every decision behind policy.

01

Visibility

Read the full context — who is asking, what they own, what they can access, what breaks if we touch it. Nothing acts on incomplete signal.

02

Reasoning

Match the request to a grounded answer or a playbook. Cite the source paragraph, weigh the risk tier, and route to the correct approver where policy demands it.

03

Action

Execute the write on your systems with an audit-log id, an entity list, and a rollback path. Confirm the outcome with the requester in the same thread.

How every request flows

From ask to resolution in one loop

Six stages every request travels. What changes is how many stages policy lets the agent execute without waiting on a human.

01
Request

In Slack, email, widget, MCP, or the helpdesk. Same voice, same context.

Slack · Teams · Zendesk · Widget · MCP
02
Retrieve

Grounded lookup against your knowledge with source paragraphs held aside.

Knowledge Studio
03
Reason

Read the Context Graph — who, what they own, what breaks if we touch it.

Context Graph
04
Approve

Route to the correct approver per policy. Reversible writes gated, destructive step-up.

Approval matrix
05
Execute

Act on Okta, Stripe, Workday, GitHub, or your own systems. Logged and attributable.

Actions runtime
06
Verify

Confirm the outcome with the requester. Feed the result back into future decisions.

Feedback loop
Enterprise-grade by default

The controls your security team is going to ask about

SOC 2 Type II
audited annually
GDPR
EU data residency
HIPAA-ready
BAA available
SSO / SAML
Okta · Entra · Google
SCIM 2.0
auto-provision
Audit log
every write, traceable
Bring your key
AES-256-GCM at rest
Bring your model
Anthropic · OpenAI · self-host
Zero training
your data stays yours
Rollback
every write reversible
TLS 1.3
in transit
99.9% uptime
SLA on Enterprise

Frequently asked questions

Common questions about Access Governance

Elevation writes an edge in the Context Graph with valid_from = now and valid_until = now + duration. The identity provider is called to grant the role. A scheduled task watches for expiring edges and calls the identity provider to revoke. Both writes land in the audit log with the approver's identity.
Okta, Microsoft Entra ID, Google Workspace, GitHub, AWS IAM, GCP IAM, Salesforce in Phase 2. Sailpoint added in Phase 6. Other providers via the NL integration builder or an HTTP action.
Yes — CSV, YAML, or a Terraform / Sailpoint export. The import maps roles to entitlements and creates the JIT policies. On subsequent syncs we detect drift between the matrix and the live IdP state and surface it for review.
Traditional IGA (Sailpoint, Saviynt) is heavy configuration and quarterly reviews. BeforeQuery is chat-native for the daily grants, event-driven for the lifecycle, and surfaces reviews only where policy demands. Fewer manual steps, faster grants, cleaner offboarding. We coexist with an IGA if you have one — treat us as the daily-driver layer above it.
Approval Policies support chains — sequential approvals, parallel approvals, delegates for out-of-office, deadline escalations. Configure once and reference from any JIT rule.

Run it on BeforeQuery

Book a demo and see what Access Governance does on your own data — usually within 45 days.