Who still has access to what,
reviewed on a schedule, not forgotten about
Access accumulates and rarely gets cleaned up: a contractor's account from a project that ended months ago, a permission granted for one task that nobody removed after. An access and permissions agent tracks who has access to what across your systems, flags what looks stale or over-broad, and prepares a revocation list, it never revokes anything itself, your team approves every change.
The role today
Offboarding a contractor or an employee usually covers the obvious systems, email, the main app, and quietly misses the smaller ones, an analytics dashboard, a shared drive folder, an admin panel for a tool nobody thinks of as sensitive. That access just stays open, not because anyone decided it should, but because nobody runs the full checklist every time.
The second cost is permission creep: someone gets elevated access for a specific task, finishes the task, and keeps the access because removing it was never anyone’s job. Multiply that across a team over a year and the actual access map looks nothing like the org chart.
The third is that access reviews, when they happen at all, happen reactively, after an audit requirement or a security scare, rather than on a schedule that would have caught the problem months earlier.
What the agent takes over
The agent cross-references your identity provider, your HR roster, and the admin panels of your key systems to build a picture of who has access to what, and checks that against who should, based on current role and recent activity. It flags stale accounts, people who left months ago but still have a login, over-broad permissions, access well beyond what someone’s current role needs, and prepares a clear revocation list with the reasoning behind each item.
A quarterly review cadence runs by default, so this does not depend on someone remembering to ask for it, while still waiting for a human to approve before anything actually changes.
Typical scope: identity provider accounts, key system admin panels, and cross-referencing against HR status. It surfaces the picture; your team decides what to do with it.
What stays with humans
Approving the revocation list, every single item, stays a human action. Granting new access, and deciding on exceptions where someone genuinely needs broader permissions than their role suggests, is a judgment call that belongs with your team, not the agent.
Guards
The agent never revokes access on its own, under any configuration, it only recommends. Every recommendation is logged with the specific reasoning behind it, so an approver can check the logic, not just the conclusion. The review runs on a fixed schedule by default, quarterly, so it does not silently lapse.
Price and timeline
| Option | Price | What it covers | Timeline |
|---|---|---|---|
| Agency runs it | from $2,000 + support plan | Agent built and run by us, quarterly review delivered to your team for approval | 2 to 3 weeks |
| Full control, handover-ready | from $3,400 | Same agent on your own identity provider, documented process, your team runs and approves it | 3 to 4 weeks |
Running cost is usually $10 to $40 a month in model usage.
Related
See the AI agents service page and automation-everything for the surrounding build. Within this group: security monitoring agent and AI policy and guardrails agent cover adjacent governance ground. For a related one-time setup, see automate access reviews and offboarding. Real governance discipline behind this page: the ProBay AI agent team case study, where every agent’s access is scoped and reviewed, not assumed.
Not sure who still has access to what, after the last few people who left? Get in touch and we will map your current access first.
FAQ
How much does an access and permissions agent cost?
From $2,000 to wire into one identity provider and HR roster, live in 2 to 3 weeks. Multiple systems with separate access models usually run $3,000 to $4,500.
How long before the first real review?
2 to 3 weeks: connecting to your identity provider and HR data takes about a week, then the first full review runs and gets checked by your team before the quarterly cadence starts.
Which tools does it work with?
Your identity provider (Google Workspace, Okta, or similar), admin panels for key systems, and your HR roster or offboarding checklist, to cross-reference who should still have access against who does.
What if it flags the wrong account, or misses one?
Every recommendation is logged with its reasoning, so a wrong flag is easy to spot and correct, and a miss gets added to its checks the same review cycle. Nothing is revoked until your team reviews the list.
Can it actually remove someone's access?
No. It prepares a reviewed list; a person on your team approves and executes every revocation. This is deliberate, access changes are exactly the kind of irreversible action that should never run on an agent's own judgment.