Non-human identity cleanup · Sutura Suite

Every service account has an owner. Or a finding.

Service accounts, app registrations, bots and API identities outnumber people, and nobody leaves when they should. Sutura Hakika finds them all, checks who owns each one and what it can do, ranks the risk, and tracks every cleanup until someone else has verified it.

Self-hosted · Read-only discovery · Never stores a secret value

Builds the inventory from the systems you already run

  • Microsoft Entra ID (live)
  • Active Directory exports
  • Application and credential inventories
  • HR employee directory
  • Any CSV export

Nobody offboards a service account.

A script needed an account in 2019. An integration got an app registration with a secret that never expires. The engineer who created them left. They still sign in, some with rights over the whole directory, and nobody can say who would notice if they were misused. Hakika gives each one an owner, a purpose and a verdict.

What it finds

The identities that carry real risk

No owner, or an owner who left

Owners are checked against the employee directory: missing, terminated, on leave, or never confirmed. Entra ID owners are linked automatically.

Privileged and unused

Apps holding tenant-wide write permissions or admin roles, and identities with no sign-in for months: standing access nobody needs.

Credentials out of control

Secrets and certificates that expired, are about to, or never rotate. Hakika records their dates and identifiers, never their values.

How it works

Discover, own, score, fix, verify

  1. 1

    Discover

    A live, read-only Entra ID connector and CSV imports build one inventory. Duplicates across sources are matched and classified, with every rule explained.

  2. 2

    Own

    Each identity gets owners checked against the employee directory, and the systems that depend on it, so cleanup never breaks a payroll run.

  3. 3

    Score

    A weighted, capped risk score shows exactly which factors raised it. Findings open, close and reopen by themselves as the data changes.

  4. 4

    Fix and verify

    Remediation with evidence, verified by someone other than the person who did it. Accepted risks need an approver and an expiry date.

Built for security teams

Governance, not just a dashboard

Hakika runs on your own server and never needs write access to your tenant: it tells people what to fix and keeps the proof.

  • Read-only discovery. The Entra ID connector needs read permissions only.
  • No secret values. Credentials are tracked by dates and identifiers; passwords and keys never enter Hakika.
  • Separation of duties. Whoever fixes a finding cannot verify it.
  • Append-only audit trail. Enforced by the database itself, not just the application.
  • Single sign-on and MFA. OpenID Connect or SAML 2.0, authenticator apps, custom roles.
  • Reports. Executive and operations dashboards, exports to CSV, Excel and PDF.

Live demo

See it on a real tenant

The live demo pulls a real Microsoft Entra ID tenant every day, alongside sample data from other sources. Ask us for a demo account to sign in.

FAQ

Common questions

What counts as a non-human identity?

Service accounts, app registrations and service principals, managed identities, shared and emergency accounts, bots and RPA accounts, API, database and integration identities, and scheduled-task accounts.

What permissions does the Entra ID connector need?

Read-only application permissions: Application.Read.All and User.Read.All, plus optionally the ones for delegated permissions, admin roles and sign-in activity. Hakika never changes anything in your tenant.

Does Hakika rotate or disable credentials?

No. It is not a vault or a PAM tool. It finds the problem, assigns it, and keeps the evidence that it was fixed and verified.

How is it deployed?

On your own server with Docker Compose and automatic HTTPS, or Kubernetes with the Helm chart. Upgrades apply database changes automatically.

How is it priced?

Get in touch and we'll walk you through the options.

Know every identity that isn't a person.

Start with your own Entra ID tenant in a 30-day pilot.