Who has access to what — answered continuously.
Access reviews happen quarterly, in a spreadsheet, and are stale by the time they are signed. Meanwhile people change roles, contractors come and go, and privileged accounts accumulate rights nobody remembers granting.
NIS2 expects access-control policies, human-resources security and asset management — and multi-factor authentication where appropriate — as standing measures. TruSecure reads identity-provider and HR state through connectors and governs access as living controls: review cycles tracked, MFA coverage measured, leaver deprovisioning verified against what actually happened.
How it works
- Connect
Identity-provider, HR and MDM connectors read accounts, roles, group memberships and device state — the identity picture as it is, not as the last export saw it.
- Review
Access-review campaigns are scheduled and tracked per system. Completion is measured; an unsigned review is a visible gap, not a forgotten task.
- Verify
MFA coverage, privileged-account hygiene and leaver deprovisioning are checked continuously against source systems — the “did we actually disable that account?” question answers itself.
- Prove
Review sign-offs, coverage snapshots and deprovisioning records accumulate as evidence, approved by named people and sealed into the audit trail.
What an access review looks like
- Systems in scope
- 14
- Reviews complete
- 13 of 14
- MFA coverage
- 99.2% of workforce
- Leavers disabled
- 11 of 11 · ≤24 h
- Citations
- NIS2 21(2)(i)(j) · A.5.15–18
Which regulations it maps to
| Framework | What it expects | Citation |
|---|---|---|
| NIS2 | HR security and access-control policies; MFA where appropriate | Art. 21(2)(i) + (j) |
| ISO 27001 | Access control, identity management, authentication, access rights | A.5.15–A.5.18 |
| SOC 2 | Logical access restricted, provisioned and reviewed | CC6 |
The identity and HR connectors do the reading — your IdP and HR system stay the systems of record, and review campaigns run against live data instead of a stale extract.
“Who has access to what” is the question every breach investigation and every audit starts with. When the answer is continuously assembled from source systems — and every review decision is on the record — it stops being a quarterly fire drill.
The monitoring loop
continuous · every 6 hours- 01
01
Connect
Read-only connectors into AWS, Azure, GCP, on-premise.
AWSAzureGCPon-prem - 02
02
Collect
AI pulls compliance evidence every 6 hours — not at audit time.
every 6 h - 03
03
Detect
Gaps and control drift flagged the moment they appear.
24/7 - 04
04
Remediate
Routine fixes closed automatically; the rest routed to you.
auto - 05
05
Approve
A named person decides. The approval is the record.
logged
The 80/20 advantage. AI handles the tedium — evidence, testing, gap analysis, routine fixes. Your team keeps the interesting 20%: strategic decisions, policy exceptions, risk acceptance.