Identity & Access Management

The right access, for the right time, with proof.

Sutura turns access requests, approvals, provisioning and access reviews into one governed workflow on top of Microsoft Entra ID, with every decision recorded.

Self-hosted · Your infrastructure, your data

Works with the systems you already run

  • Microsoft Entra ID
  • OpenID Connect
  • Active Directory / LDAP
  • Okta
  • AWS IAM
  • ServiceNow

Access sprawls. Audits find it.

Access is granted by email, kept long after it's needed, and rarely removed when people move or leave. When the auditor asks who approved what and why, the answers are scattered. Sutura gives every grant an owner, an approval, an end date and a record.

Sutura in 60 seconds

Read what the video shows

Jordan moved from Finance to Sales in 2023 and still holds eight grants, five of them with no owner, approval or end date. With Sutura, Alex requests the Finance Suite: Analyst role for 4 hours. Morgan, Alex's manager, approves, then the role owner; separation of duties is checked and nobody approves their own access. A connector adds Alex to the Microsoft Entra ID group, the access is revoked automatically 4 hours later, and a quarterly review confirms or revokes the rest. Every step is recorded in the audit log. The video has music and no narration.

Features

Everything access governance needs, in one place

Self-service requests & approvals

Employees request roles from a catalog. Requests route to their manager, then to the role owner, with delegation when approvers are away.

Joiner, mover, leaver automation

HR events grant birthright access to new hires, adjust it when people change roles, and remove it when they leave, including account disablement and offboarding tasks.

Temporary & break-glass access

Grant access for hours instead of forever. It expires on schedule and is removed from target systems automatically. Emergency access is logged and time-boxed.

Access reviews

Run certification campaigns where owners confirm or revoke access. Revocations are carried out, not just recorded, and nobody reviews their own access.

Provisioning & connectors

Provision automatically through connectors for Entra ID groups, LDAP, Okta, AWS IAM and ServiceNow, or route tasks to the people who own manual systems.

Audit trail & reporting

Every request, approval, grant and revocation is recorded with who, what and when. Look up any user's access and export compliance reports.

How it works

From request to removal, governed end to end

  1. 1

    Request

    An employee, their manager or an HR event asks for a role, permanently or for a set time.

  2. 2

    Approve

    The manager and role owner approve. Sutura blocks self-approval and routes around absences through delegation.

  3. 3

    Provision

    Connectors grant the access, or the system's provisioner gets a task with an SLA.

  4. 4

    Review & remove

    Temporary access expires, leavers are offboarded and periodic reviews confirm the rest.

Security

Built to be trusted with access

An access platform is a high-value target. Sutura is designed so a misconfiguration fails closed instead of opening the door.

  • Self-hosted. Runs on your servers or cloud account; your directory and audit data stay with you.
  • Single sign-on. Microsoft Entra ID or any OpenID Connect provider. No separate passwords to manage.
  • Separation of duties. Nobody approves, certifies or provisions their own access.
  • Fails closed. The server refuses to start with an unsafe production configuration.
  • Encrypted secrets. Connector credentials are encrypted at rest.
  • Least-privilege admin. Separate Super Admin, IT, HR, audit and manager roles.

Live demo

See it working

The live demo runs the full product with sample data: an employee requests access, their manager approves, IT provisions, and administrators follow it all in the audit trail. Sign-in uses Microsoft Entra ID, so ask us for a demo account first.

FAQ

Common questions

How is Sutura deployed?

Sutura runs as containers (API, background workers, web app) with PostgreSQL and Redis, on a single server or in your cloud. Database migrations run automatically on upgrade.

Which identity providers are supported?

Microsoft Entra ID out of the box, and any standards-based OpenID Connect provider such as Okta, Auth0 or Keycloak.

Where is our data stored?

Wherever you run it. Sutura is self-hosted, so access records, approvals and audit logs stay in your own database.

Can it work alongside our HR system?

Yes. HR systems send signed joiner, mover and leaver events, and Sutura applies role rules to grant, change or remove access automatically.

How is it priced?

Get in touch and we'll walk you through options for your organization.

Ready to take control of access?

Book a walkthrough and see Sutura with your own scenarios.