Fussion_GRC domain 10 of 15
Access Control & Identity
Connect HR and identity systems to govern joiners, movers, leavers, access reviews, MFA and privileged access with evidence.
Fussion_GRC consumes data from your existing tools. It does not perform security scanning.
- HRIS (Workday, Darwinbox)Daily
- Identity provider (Entra ID, Okta)Every 4 hours
- PAM (CyberArk, BeyondTrust)Daily
The problem
What problem this domain solves
Identity governance ensures people have only the access their role needs, that access is reviewed, that strong authentication is enforced and that leavers lose access promptly.
For the CISO
Why this matters to the CISO
Stolen and excessive access drive most breaches. Access reviews and leaver controls are among the most frequently failed audit items.
Leaver timeliness, review completion and MFA coverage, with exceptions.
How it works
How Fussion_GRC works in this domain
Fussion_GRC consumes data from your existing tools. It does not perform security scanning. It connects to the tools that already hold identity data, then does the following:
- 01Matches HR events with identity changes to detect late leavers.
- 02Runs access reviews with managers and application owners.
- 03Measures MFA and privileged access coverage.
- 04Produces evidence of each review decision.
Data in
Exactly where the data comes from
| Source tool | Data received | Typical sync |
|---|---|---|
| HRIS (Workday, Darwinbox) | Joiner, mover, leaver events | Daily |
| Identity provider (Entra ID, Okta) | Accounts, groups, MFA status | Every 4 hours |
| PAM (CyberArk, BeyondTrust) | Privileged accounts and sessions | Daily |
| Key applications | Application entitlements | Daily |
Typical frequencies; exact intervals depend on each tool's API limits and your configuration. Connector availability varies — see integrations.
Data flow
From your tools to the boardroom
- 1. HRIS
- 2. Entra / Okta
- 3. Fussion_GRC
- 4. Access review
- 5. MFA / PAM
- 6. Evidence
Automation
Automation and workflows
Workflows created
- HRIS + Entra/Okta → joiner/mover/leaver → access review → MFA → privileged access → control evidence → audit readiness
- Access review → manager decision → revocation ticket
- Late leaver → escalation
Actions for leaders
- Approve or revoke access in a review
- Escalate late leaver removals
- Review accounts without MFA
Controls & evidence
Controls and evidence
Controls are defined once and mapped across frameworks. See supported frameworks.
Controls
- Leaver access removed within 24 hours
- Quarterly access reviews
- MFA for all users
- Privileged access management
Evidence generated
- Joiner/mover/leaver reconciliation
- Signed access review results
- MFA coverage report
- Privileged account list
AI assistance
How Fussion AI helps
Answers come from your own Fussion_GRC data, with sources. Learn about Fussion AI.
Questions you can ask
- "Which leavers still have active accounts?"
- "Which privileged accounts lack MFA?"
- "Summarise this quarter's access review results."
- Leavers whose accounts remain active for weeks.
- Access reviews done in spreadsheets and rubber-stamped.
- MFA gaps on privileged or legacy accounts.
Every point links to its source record. Recommendation only — a named owner approves decisions.
Dashboard
Dashboard example
Roles
Who uses this domain
CISO
Stolen and excessive access drive most breaches. Access reviews and leaver controls are among the most frequently failed audit items.
CIO
Sees how identity affects IT services, investment priorities and the systems the business depends on.
Security Manager
Runs day-to-day identity operations from one queue instead of separate tool consoles.
GRC Manager
Maps identity controls to frameworks, tracks evidence freshness and prepares audits.
Control Owner
Managers and application owners get their review tasks.
Auditor
Reconciled leaver evidence and signed access review decisions.
Technical Owner
Receives specific, prioritised tasks in Jira or ServiceNow with the context needed to fix them.
Executive
Leaver timeliness, review completion and MFA coverage, with exceptions.
Integrations
Tools you can connect
- Microsoft Entra ID
- Okta
- Workday
- Darwinbox
- CyberArk
- BeyondTrust
- SailPoint
Named tools show typical sources; availability may be planned, roadmap or custom connector. Confirm during a demo.
See all integrationsOutcomes
Business outcomes
Example
Example workflow
- 1System
New signal from HRIS (Workday, Darwinbox)
- 2Fussion_GRC
Matches HR events with identity changes to detect late leavers.
- 3Control owner
HRIS + Entra/Okta → joiner/mover/leaver → access review → MFA → privileged access → control evidence → audit readiness
- 4GRC manager
Evidence attached: Joiner/mover/leaver reconciliation
- 5CISO
Approve or revoke access in a review
FAQ
Frequently asked questions
Do we need an IGA product?
Not necessarily. Fussion_GRC covers review governance and evidence; if you already run SailPoint or similar, it reads from it.
Does it change access directly?
It raises revocation tasks in your ITSM or identity workflow; changes are made by your existing systems.
Does Fussion_GRC scan our environment?
Fussion_GRC consumes data from your existing tools. It does not perform security scanning.
