Self-service requests & approvals
Employees request roles from a catalog. Requests route to their manager, then to the role owner, who are emailed and reminded, with delegation when approvers are away.
Identity & Access Management
Sutura turns access requests, approvals, provisioning and access reviews into one governed workflow on top of Microsoft Entra ID, with every decision recorded.
Self-hosted · Your infrastructure, your data
Works with the systems you already run
Access is granted by email, kept long after it's needed, and rarely removed when people move or leave. When the auditor asks who approved what and why, the answers are scattered. Sutura gives every grant an owner, an approval, an end date and a record.
Sutura in 60 seconds
Jordan moved from Finance to Sales in 2023 and still holds eight grants, five of them with no owner, approval or end date. With Sutura, Alex requests the Finance Suite: Analyst role for 4 hours. Morgan, Alex's manager, approves, then the role owner; separation of duties is checked and nobody approves their own access. Sutura adds Alex to the Microsoft Entra ID group, the access is revoked automatically 4 hours later, and a quarterly review lets the Finance owners confirm or revoke who holds each role. Every step is recorded in the audit log. The video has music and no narration.
Features
Employees request roles from a catalog. Requests route to their manager, then to the role owner, who are emailed and reminded, with delegation when approvers are away.
HR events grant birthright access to new hires, adjust it when people change roles, and remove it when they leave, including account disablement and offboarding tasks.
Grant access for hours instead of forever. It expires on schedule and is removed from target systems automatically. Emergency access is logged and time-boxed.
Run certification campaigns on every role, on a schedule (quarterly, for example) or on demand. Owners or managers confirm or revoke; a revoke removes the access and its directory groups. Nobody reviews their own access.
Approved access is granted automatically in Microsoft Entra ID and Active Directory groups, and in Okta, ServiceNow and AWS IAM through connectors, then removed the same way when it ends. Any other system's owner gets a task with a deadline.
Every request, approval, grant and removal is recorded with who, what and when, in a chain that exposes any change. Verify it in one click and hand auditors an evidence pack for a person or a quarter.
How it works
An employee, their manager or an HR event asks for a role, permanently or for a set time.
The manager and role owner approve. Sutura blocks self-approval and routes around absences through delegation.
Sutura grants the access in Entra ID, Active Directory, Okta, ServiceNow or AWS IAM, or the system's owner gets a task with a deadline.
Temporary access expires, leavers are offboarded and periodic reviews confirm the rest.
Security
An access platform is a high-value target. Sutura is designed so a misconfiguration fails closed instead of opening the door.
Live demo
The live demo runs the full product with sample data: an employee requests access, their manager approves, IT provisions, and administrators follow it all in the audit trail. Sign-in uses Microsoft Entra ID, so ask us for a demo account first.
FAQ
Sutura runs as containers (API, background workers, web app) with PostgreSQL and Redis, on a single server or in your cloud. Database migrations run automatically on upgrade.
Microsoft Entra ID out of the box, and any standards-based OpenID Connect provider such as Okta, Auth0 or Keycloak.
Wherever you run it. Sutura is self-hosted, so access records, approvals and audit logs stay in your own database.
Yes. HR systems send signed joiner, mover and leaver events, and Sutura applies role rules to grant, change or remove access automatically.
Get in touch and we'll walk you through options for your organization.
Book a walkthrough and see Sutura with your own scenarios.