Access reconciliation · Sutura Suite

Prove that access is what it should be.

Sutura Drift compares who should have access, from Sutura, your IGA or HR, with what Microsoft Entra ID and your applications actually grant. Every night. It reports what never landed, what was granted outside the process, and who left but still has access.

Self-hosted · Read-only connections · Your data stays with you

Reads from the systems you already run

  • Sutura
  • Microsoft Entra ID
  • SCIM 2.0 applications
  • Any REST / JSON API
  • SailPoint and Saviynt exports
  • CSV

Your access system says one thing. Your applications say another.

A request is approved but the group change fails. An admin adds a colleague by hand "just for today". Someone leaves, and one application keeps their account. Each gap is invisible until an auditor or an attacker finds it. Drift finds it first, every night, and shows the gap closing when it is fixed.

What it finds

Three kinds of drift, ranked by risk

People who left, still with access

Your source of truth marks them terminated or suspended, but an application or group still grants access. Reported as critical.

Access granted outside the process

Accounts and group memberships nobody approved. Risk rises with the entitlement: an orphan administrator ranks above an orphan viewer.

Approved, never granted

Access your access system approved that never reached the application, including groups that are still empty. People are blocked, and the record says otherwise.

How it works

Connect, compare, fix, confirm

  1. 1

    Connect

    Read-only connectors pull expected access (Sutura, an IGA, HR) and actual access (Entra ID, SCIM applications, any JSON API). Credentials are encrypted.

  2. 2

    Compare

    A scheduled scan matches people, applications and entitlements, using each application's risk settings. A broken pull is held for review, never scanned.

  3. 3

    Fix

    Findings become remediation tasks with owners, due dates and email reminders, or ServiceNow tickets. Drift never changes access itself.

  4. 4

    Confirm

    The next scan marks fixed findings resolved. Every step is in a tamper-evident audit trail, ready for the auditor.

With Sutura, or on its own

An independent check of your access system

Sutura decides who should have access. Drift checks that it really happened, reading the applications directly, not through Sutura. If you use another access system, Drift checks that one instead.

  • Read-only. Drift needs read permissions only, and never grants or removes access.
  • Independent. It reads applications and directories itself, so the system being checked does not grade its own work.
  • Safe by default. A pull that suddenly returns half the usual records is held for review instead of closing findings.
  • Self-hosted. One server with Docker, Kubernetes or AWS; your data stays with you.
  • Tamper-evident. Every scan, finding and decision is in an append-only, hash-chained audit trail.
  • Single sign-on. Microsoft Entra ID or any OpenID Connect provider.

Live demo

See real findings

The live demo compares the Sutura demo with a real Microsoft Entra ID tenant every night, so the findings it shows are real. Ask us for a demo account to sign in.

FAQ

Common questions

Do we need Sutura to use Drift?

No. Drift can take expected access from Sutura, from an IGA export (SailPoint, Saviynt), from HR, or from a CSV file. With Sutura, the two connect with a read-only token.

What permissions does Drift need?

Read-only ones: for Microsoft Entra ID, reading users, group members and application assignments. Drift cannot change access anywhere.

How is it deployed?

Containers with PostgreSQL on one server (optional automatic HTTPS), Kubernetes with the Helm chart, or AWS ECS. Migrations run automatically on upgrade.

How is it priced?

Get in touch and we'll walk you through options, on its own or with Sutura.

Find the gaps before the auditor does.

See Drift with your own directory in a 30-day pilot.