Identity & Access Management

The right access, for the right time, with proof.

Sutura turns access requests, approvals, provisioning and access reviews into one governed workflow on top of Microsoft Entra ID, with every decision recorded.

Self-hosted · Your infrastructure, your data

Works with the systems you already run

  • Microsoft Entra ID
  • Active Directory / LDAP
  • Okta
  • ServiceNow
  • AWS IAM
  • OpenID Connect

Access sprawls. Audits find it.

Access is granted by email, kept long after it's needed, and rarely removed when people move or leave. When the auditor asks who approved what and why, the answers are scattered. Sutura gives every grant an owner, an approval, an end date and a record.

Sutura in 60 seconds

Read what the video shows

Jordan moved from Finance to Sales in 2023 and still holds eight grants, five of them with no owner, approval or end date. With Sutura, Alex requests the Finance Suite: Analyst role for 4 hours. Morgan, Alex's manager, approves, then the role owner; separation of duties is checked and nobody approves their own access. Sutura adds Alex to the Microsoft Entra ID group, the access is revoked automatically 4 hours later, and a quarterly review lets the Finance owners confirm or revoke who holds each role. Every step is recorded in the audit log. The video has music and no narration.

Features

Everything access governance needs, in one place

Self-service requests & approvals

Employees request roles from a catalog. Requests route to their manager, then to the role owner, who are emailed and reminded, with delegation when approvers are away.

Joiner, mover, leaver automation

HR events grant birthright access to new hires, adjust it when people change roles, and remove it when they leave, including account disablement and offboarding tasks.

Temporary & break-glass access

Grant access for hours instead of forever. It expires on schedule and is removed from target systems automatically. Emergency access is logged and time-boxed.

Access reviews

Run certification campaigns on every role, on a schedule (quarterly, for example) or on demand. Owners or managers confirm or revoke; a revoke removes the access and its directory groups. Nobody reviews their own access.

Provisioning & connectors

Approved access is granted automatically in Microsoft Entra ID and Active Directory groups, and in Okta, ServiceNow and AWS IAM through connectors, then removed the same way when it ends. Any other system's owner gets a task with a deadline.

Tamper-evident audit trail

Every request, approval, grant and removal is recorded with who, what and when, in a chain that exposes any change. Verify it in one click and hand auditors an evidence pack for a person or a quarter.

How it works

From request to removal, governed end to end

  1. 1

    Request

    An employee, their manager or an HR event asks for a role, permanently or for a set time.

  2. 2

    Approve

    The manager and role owner approve. Sutura blocks self-approval and routes around absences through delegation.

  3. 3

    Provision

    Sutura grants the access in Entra ID, Active Directory, Okta, ServiceNow or AWS IAM, or the system's owner gets a task with a deadline.

  4. 4

    Review & remove

    Temporary access expires, leavers are offboarded and periodic reviews confirm the rest.

Security

Built to be trusted with access

An access platform is a high-value target. Sutura is designed so a misconfiguration fails closed instead of opening the door.

  • Self-hosted. Runs on your servers or cloud account; your directory and audit data stay with you.
  • Single sign-on. Microsoft Entra ID or any OpenID Connect provider. No separate passwords to manage.
  • Separation of duties. Nobody approves, certifies or provisions their own access, and rules keep conflicting roles (create and pay vendors) from landing on one person.
  • Fails closed. The server refuses to start with an unsafe production configuration.
  • Tamper-evident records. Each audit entry carries a SHA-256 fingerprint of itself and the entry before it, and the database refuses edits and deletions.
  • Encrypted secrets. Connector credentials are encrypted at rest.
  • Encrypted backups. Nightly backups are copied off the server encrypted, and a full restore is one command.
  • Watches itself. Every part of Sutura is checked each minute. Admins see what is wrong and how to fix it, and failures reach your monitor.
  • Emergency sign-in. If Entra ID is down, one named admin can sign in for a few hours. It is turned on from the server and recorded in the audit trail.
  • Least-privilege admin. Separate Super Admin, IT, HR, audit and manager roles.

Live demo

See it working

The live demo runs the full product with sample data: an employee requests access, their manager approves, IT provisions, and administrators follow it all in the audit trail. Sign-in uses Microsoft Entra ID, so ask us for a demo account first.

FAQ

Common questions

How is Sutura deployed?

Sutura runs as containers (API, background workers, web app) with PostgreSQL and Redis, on a single server or in your cloud. Database migrations run automatically on upgrade.

Which identity providers are supported?

Microsoft Entra ID out of the box, and any standards-based OpenID Connect provider such as Okta, Auth0 or Keycloak.

Where is our data stored?

Wherever you run it. Sutura is self-hosted, so access records, approvals and audit logs stay in your own database.

Can it work alongside our HR system?

Yes. HR systems send signed joiner, mover and leaver events, and Sutura applies role rules to grant, change or remove access automatically.

How is it priced?

Get in touch and we'll walk you through options for your organization.

Ready to take control of access?

Book a walkthrough and see Sutura with your own scenarios.