Sovereign · Privileged access assurance

Failures made clear. Compliance you can prove. Work that stays visible.

Sovereign sits beside the privileged access platform. It turns each failure into an assessment an engineer can act on, checks platforms, accounts, safes and duties against your rules, and keeps the record an audit will ask for.

Sign inCorporate SSO or a local account.

What it covers

What it is for.

Audit & compliance

Compliance you can show, not assert

Platform settings, credential rotation, segregation of duties and safe classification are checked against the rules this team defines. Every finding is named, every accepted exception carries an owner, a reason and an expiry, and the audit log holds the lot.

Failures

Failures that explain themselves

Each privileged-account failure arrives as an assessment: what is known, what is missing, a likely cause with how sure it is, and the next check to make. Prioritised by rules, so the worst is at the top.

Workflow

Work that moves, and stays visible

An engineer reviews an assessment, hands the next step to whoever fixes it, or closes it with a reason. Whatever is yours says so; whatever is handed off is followed up. Nothing sits in a queue nobody owns.

Evidence

Built on evidence, on the record

Every assessment rests on what the estate actually reported, and says so. If an AI model is involved it is enabled deliberately and each disclosure is recorded. Demonstration data is labelled wherever it appears.

Who uses it

Three roles, each with its own pages.

Roles are held independently; a person can hold more than one. What each can open and do is fixed in code, not by a setting. A platform administrator sets the deployment up and keeps it running, but does not work in it day to day.

PAM analyst
Works the Failures list, reviews assessments, records handoffs and closures, accepts or withdraws compliance exceptions.
Configuration administrator
Names the environment, connects the vault, defines the compliance rules, runs checks on demand, manages local users.
Auditor
Reads the investigation record and the audit log, and exports them. Cannot act on anything.

How it works

Collect. Assess. Act. Record.

  1. Collect

    A scheduled sweep gathers what the estate reports: failures, platform policy, credential ages, safe membership.

  2. Assess

    Rules turn the evidence into findings and verdicts, each with its confidence, what supports it and what is still missing.

  3. Act

    An engineer reviews, hands off or closes; an analyst accepts an exception with a reason and an expiry.

  4. Record

    Every decision, handoff and exception is in the audit log with who, when and why, ready for the next audit.

The Failures list and the compliance pages show what the last sweep found and say when that was. A sweep runs on a schedule; an analyst can refresh on demand. Today the product reads and advises; what it does on the estate itself is a person’s action, and is recorded as theirs.