Skip to main content
PLATFORM · ACCESS CONTROL

Who has access to what — answered continuously.

Access reviews happen quarterly, in a spreadsheet, and are stale by the time they are signed. Meanwhile people change roles, contractors come and go, and privileged accounts accumulate rights nobody remembers granting.

NIS2 expects access-control policies, human-resources security and asset management — and multi-factor authentication where appropriate — as standing measures. TruSecure reads identity-provider and HR state through connectors and governs access as living controls: review cycles tracked, MFA coverage measured, leaver deprovisioning verified against what actually happened.

How it works

  1. Connect

    Identity-provider, HR and MDM connectors read accounts, roles, group memberships and device state — the identity picture as it is, not as the last export saw it.

  2. Review

    Access-review campaigns are scheduled and tracked per system. Completion is measured; an unsigned review is a visible gap, not a forgotten task.

  3. Verify

    MFA coverage, privileged-account hygiene and leaver deprovisioning are checked continuously against source systems — the “did we actually disable that account?” question answers itself.

  4. Prove

    Review sign-offs, coverage snapshots and deprovisioning records accumulate as evidence, approved by named people and sealed into the audit trail.

What an access review looks like

Access review · quarterly campaignSample data
Systems in scope
14
Reviews complete
13 of 14
MFA coverage
99.2% of workforce
Leavers disabled
11 of 11 · ≤24 h
Citations
NIS2 21(2)(i)(j) · A.5.15–18

Which regulations it maps to

Access & identity obligations · by framework
FrameworkWhat it expectsCitation
NIS2HR security and access-control policies; MFA where appropriateArt. 21(2)(i) + (j)
ISO 27001Access control, identity management, authentication, access rightsA.5.15–A.5.18
SOC 2Logical access restricted, provisioned and reviewedCC6

The identity and HR connectors do the reading — your IdP and HR system stay the systems of record, and review campaigns run against live data instead of a stale extract.

“Who has access to what” is the question every breach investigation and every audit starts with. When the answer is continuously assembled from source systems — and every review decision is on the record — it stops being a quarterly fire drill.

The monitoring loop

continuous · every 6 hours
  1. 01

    Connect

    Read-only connectors into AWS, Azure, GCP, on-premise.

    AWSAzureGCPon-prem
  2. 02

    Collect

    AI pulls compliance evidence every 6 hours — not at audit time.

    every 6 h
  3. 03

    Detect

    Gaps and control drift flagged the moment they appear.

    24/7
  4. 04

    Remediate

    Routine fixes closed automatically; the rest routed to you.

    auto
  5. 05

    Approve

    A named person decides. The approval is the record.

    logged
90% less manual evidence work100% audit-ready, every day

The 80/20 advantage. AI handles the tedium — evidence, testing, gap analysis, routine fixes. Your team keeps the interesting 20%: strategic decisions, policy exceptions, risk acceptance.

Frequently Asked Questions

How does TruSecure govern access control?
Access reviews, MFA coverage and leaver deprovisioning are governed as living controls — answering who has access to what continuously, with evidence for NIS2 Art. 21(2)(i) and (j), ISO 27001 and SOC 2.
Where does access data come from?
From your identity and IAM tooling through read-only connectors — access policies, MFA enforcement status and privileged-access records land as evidence without manual collection.
Are access reviews scheduled?
Yes — reviews run on a governed schedule with recorded outcomes, and leaver deprovisioning is tracked as evidence so departures do not leave standing access behind.