Engineering & Data

Who still has access to what,
reviewed on a schedule, not forgotten about

Access accumulates and rarely gets cleaned up: a contractor's account from a project that ended months ago, a permission granted for one task that nobody removed after. An access and permissions agent tracks who has access to what across your systems, flags what looks stale or over-broad, and prepares a revocation list, it never revokes anything itself, your team approves every change.

from$2,000
Timeline2 to 3 weeks
What is includedAgent wired into your identity provider and HR rosterScheduled review of every account against who should still have accessFlags for stale accounts, over-broad permissions and offboarded staffRevocation list prepared for human approval, never auto-executedEvery recommendation logged with its reasoning
8agents under one governed, access-scoped team on a marketplace we run
0access revoked without explicit human approval
quarterlyreview cadence built in by default, not left to whenever someone remembers

The role today

Offboarding a contractor or an employee usually covers the obvious systems, email, the main app, and quietly misses the smaller ones, an analytics dashboard, a shared drive folder, an admin panel for a tool nobody thinks of as sensitive. That access just stays open, not because anyone decided it should, but because nobody runs the full checklist every time.

The second cost is permission creep: someone gets elevated access for a specific task, finishes the task, and keeps the access because removing it was never anyone’s job. Multiply that across a team over a year and the actual access map looks nothing like the org chart.

The third is that access reviews, when they happen at all, happen reactively, after an audit requirement or a security scare, rather than on a schedule that would have caught the problem months earlier.

What the agent takes over

The agent cross-references your identity provider, your HR roster, and the admin panels of your key systems to build a picture of who has access to what, and checks that against who should, based on current role and recent activity. It flags stale accounts, people who left months ago but still have a login, over-broad permissions, access well beyond what someone’s current role needs, and prepares a clear revocation list with the reasoning behind each item.

A quarterly review cadence runs by default, so this does not depend on someone remembering to ask for it, while still waiting for a human to approve before anything actually changes.

Typical scope: identity provider accounts, key system admin panels, and cross-referencing against HR status. It surfaces the picture; your team decides what to do with it.

What stays with humans

Approving the revocation list, every single item, stays a human action. Granting new access, and deciding on exceptions where someone genuinely needs broader permissions than their role suggests, is a judgment call that belongs with your team, not the agent.

Guards

The agent never revokes access on its own, under any configuration, it only recommends. Every recommendation is logged with the specific reasoning behind it, so an approver can check the logic, not just the conclusion. The review runs on a fixed schedule by default, quarterly, so it does not silently lapse.

Price and timeline

Option Price What it covers Timeline
Agency runs it from $2,000 + support plan Agent built and run by us, quarterly review delivered to your team for approval 2 to 3 weeks
Full control, handover-ready from $3,400 Same agent on your own identity provider, documented process, your team runs and approves it 3 to 4 weeks

Running cost is usually $10 to $40 a month in model usage.

See the AI agents service page and automation-everything for the surrounding build. Within this group: security monitoring agent and AI policy and guardrails agent cover adjacent governance ground. For a related one-time setup, see automate access reviews and offboarding. Real governance discipline behind this page: the ProBay AI agent team case study, where every agent’s access is scoped and reviewed, not assumed.

Not sure who still has access to what, after the last few people who left? Get in touch and we will map your current access first.

FAQ

How much does an access and permissions agent cost?

From $2,000 to wire into one identity provider and HR roster, live in 2 to 3 weeks. Multiple systems with separate access models usually run $3,000 to $4,500.

How long before the first real review?

2 to 3 weeks: connecting to your identity provider and HR data takes about a week, then the first full review runs and gets checked by your team before the quarterly cadence starts.

Which tools does it work with?

Your identity provider (Google Workspace, Okta, or similar), admin panels for key systems, and your HR roster or offboarding checklist, to cross-reference who should still have access against who does.

What if it flags the wrong account, or misses one?

Every recommendation is logged with its reasoning, so a wrong flag is easy to spot and correct, and a miss gets added to its checks the same review cycle. Nothing is revoked until your team reviews the list.

Can it actually remove someone's access?

No. It prepares a reviewed list; a person on your team approves and executes every revocation. This is deliberate, access changes are exactly the kind of irreversible action that should never run on an agent's own judgment.

Start here

Tell us the problem.
We bring the system.

A 30-minute call, a written plan with numbers within 48 hours, no obligation. If we are not the right fit, we will say so and point you to someone who is.