CyberTrustWorks — One Platform. Total Trust.

Fussion_GRC domain 10 of 15

Access Control & Identity

Connect HR and identity systems to govern joiners, movers, leavers, access reviews, MFA and privileged access with evidence.

Fussion_GRC consumes data from your existing tools. It does not perform security scanning.

The problem

What problem this domain solves

Identity governance ensures people have only the access their role needs, that access is reviewed, that strong authentication is enforced and that leavers lose access promptly.

Leavers whose accounts remain active for weeks.
Access reviews done in spreadsheets and rubber-stamped.
MFA gaps on privileged or legacy accounts.
No single view of who has privileged access.

For the CISO

Why this matters to the CISO

Stolen and excessive access drive most breaches. Access reviews and leaver controls are among the most frequently failed audit items.

Leaver timeliness, review completion and MFA coverage, with exceptions.

How it works

How Fussion_GRC works in this domain

Fussion_GRC consumes data from your existing tools. It does not perform security scanning. It connects to the tools that already hold identity data, then does the following:

  1. 01Matches HR events with identity changes to detect late leavers.
  2. 02Runs access reviews with managers and application owners.
  3. 03Measures MFA and privileged access coverage.
  4. 04Produces evidence of each review decision.

Data in

Exactly where the data comes from

Source toolData receivedTypical sync
HRIS (Workday, Darwinbox)Joiner, mover, leaver eventsDaily
Identity provider (Entra ID, Okta)Accounts, groups, MFA statusEvery 4 hours
PAM (CyberArk, BeyondTrust)Privileged accounts and sessionsDaily
Key applicationsApplication entitlementsDaily

Typical frequencies; exact intervals depend on each tool's API limits and your configuration. Connector availability varies — see integrations.

Data flow

From your tools to the boardroom

Your existing tools
HRIS (Workday, Darwinbox)
Identity provider (Entra ID, Okta)
PAM (CyberArk, BeyondTrust)
Key applications
Fussion_GRC
  1. 1. HRIS
  2. 2. Entra / Okta
  3. 3. Fussion_GRC
  4. 4. Access review
  5. 5. MFA / PAM
  6. 6. Evidence
Outputs
Controls & evidence
Risk updates
Owner workflows
Executive reporting
Fussion_GRC consumes data from your existing tools. It does not perform security scanning.

Automation

Automation and workflows

Workflows created

  • HRIS + Entra/Okta → joiner/mover/leaver → access review → MFA → privileged access → control evidence → audit readiness
  • Access review → manager decision → revocation ticket
  • Late leaver → escalation

Actions for leaders

  • Approve or revoke access in a review
  • Escalate late leaver removals
  • Review accounts without MFA

Controls & evidence

Controls and evidence

Controls are defined once and mapped across frameworks. See supported frameworks.

Controls

  • Leaver access removed within 24 hours
  • Quarterly access reviews
  • MFA for all users
  • Privileged access management

Evidence generated

  • Joiner/mover/leaver reconciliation
  • Signed access review results
  • MFA coverage report
  • Privileged account list

AI assistance

How Fussion AI helps

Answers come from your own Fussion_GRC data, with sources. Learn about Fussion AI.

Questions you can ask

  • "Which leavers still have active accounts?"
  • "Which privileged accounts lack MFA?"
  • "Summarise this quarter's access review results."
Fussion AIIllustrative
Which leavers still have active accounts?
Based on the latest data from HRIS (Workday, Darwinbox) and Identity provider (Entra ID, Okta), here is what needs attention:
  • Leavers whose accounts remain active for weeks.
  • Access reviews done in spreadsheets and rubber-stamped.
  • MFA gaps on privileged or legacy accounts.

Every point links to its source record. Recommendation only — a named owner approves decisions.

Dashboard

Dashboard example

Roles

Who uses this domain

CISO

Stolen and excessive access drive most breaches. Access reviews and leaver controls are among the most frequently failed audit items.

CIO

Sees how identity affects IT services, investment priorities and the systems the business depends on.

Security Manager

Runs day-to-day identity operations from one queue instead of separate tool consoles.

GRC Manager

Maps identity controls to frameworks, tracks evidence freshness and prepares audits.

Control Owner

Managers and application owners get their review tasks.

Auditor

Reconciled leaver evidence and signed access review decisions.

Technical Owner

Receives specific, prioritised tasks in Jira or ServiceNow with the context needed to fix them.

Executive

Leaver timeliness, review completion and MFA coverage, with exceptions.

Integrations

Tools you can connect

  • Microsoft Entra ID
  • Okta
  • Workday
  • Darwinbox
  • CyberArk
  • BeyondTrust
  • SailPoint

Named tools show typical sources; availability may be planned, roadmap or custom connector. Confirm during a demo.

See all integrations

Outcomes

Business outcomes

Leaver timeliness, review completion and MFA coverage, with exceptions.
Reconciled leaver evidence and signed access review decisions.
Managers and application owners get their review tasks.
Less manual effort: 4 processing steps and 3 workflows run automatically instead of in spreadsheets.

Example

Example workflow

  1. 1
    System

    New signal from HRIS (Workday, Darwinbox)

  2. 2
    Fussion_GRC

    Matches HR events with identity changes to detect late leavers.

  3. 3
    Control owner

    HRIS + Entra/Okta → joiner/mover/leaver → access review → MFA → privileged access → control evidence → audit readiness

  4. 4
    GRC manager

    Evidence attached: Joiner/mover/leaver reconciliation

  5. 5
    CISO

    Approve or revoke access in a review

FAQ

Frequently asked questions

Do we need an IGA product?

Not necessarily. Fussion_GRC covers review governance and evidence; if you already run SailPoint or similar, it reads from it.

Does it change access directly?

It raises revocation tasks in your ITSM or identity workflow; changes are made by your existing systems.

Does Fussion_GRC scan our environment?

Fussion_GRC consumes data from your existing tools. It does not perform security scanning.