RapidValue IGA — Documentation
Concept reference for Identity Governance & Administration (IGA) builders, and for the security, IT and procurement audiences evaluating RapidValue. These pages explain the product's model and the reasoning behind it — not click-by-click instructions. They state what the product does not do as deliberately as what it does.
Choose your path
Four readings, in the order each one needs. The sidebar is a shelf; this is the route.
Evaluating how governance is modelled
You want to know how the product thinks, not which buttons exist.
- Reconciliation engine — Expected versus Actual access, and why that comparison is the engine rather than a report
- How the product is organized — the shape of the thing, and the rule that keeps it coherent
- JML flows — what a joiner, mover and leaver actually trigger
- Access reviews — one review engine, three trigger types
- Approver chains — multi-step and quorum, one canonical shape
- Roles and role mining — how roles get built without a consultancy project
- Separation of duties and risk — toxic combinations, and risk as a sum you can audit
- Non-human identities and ownership — who answers for the machines, and what "unowned" actually means
- Filter DSL — the single syntax behind triggers, conditions and SoD rules
- Tier-3 hybrid architecture — where it runs and what crosses the wire
Implementing it for a client
The configuration path, end to end.
- Onboarding wizard walkthrough — zero to an active system
- Imports and schedules — how data arrives, and the cadence floor
- Account types and account rules — how accounts are categorised and correlated
- Provisioning mappings — the write path
- Read/write parity — what happens when the read and write halves drift apart
- The connector reference for the systems you are connecting
Running a security or procurement review
What is isolated, what can be proven, and what we refuse to claim.
- Tenant isolation — application scoping as the primary control, row-level security as the database-enforced backstop, and the canary that proves it
- Evidence and signed exports — why an auditor should believe what the product reports, and how to verify a pack without us
- What we don't claim — the published register: measurement honesty, the assurances we do not hold, and the functional edges
- Tier-3 hybrid architecture — deployment modes; secrets never travel from the control plane to the agent
- Governing API access — scoped machine credentials, secret-once storage, per-request enforcement
- Governing AI agents — agents as governed identities, and the kill-switch's real boundary
- Unstructured data visibility — what we can and cannot see on file shares
Keeping it healthy in year three
Maintainability is a product claim, so here is the surface that has to back it.
- Operating rhythm — what to actually check weekly, monthly and quarterly, and what "healthy" looks like
- Platform health — sweep health, backup status, and an honest health surface
- Failed Jobs queue — where provisioning failures land, and the retry gate that stops "click until it works"
- Platform Advisor — the detector framework that finds problems before you do
- Environments and staged config — dev, acceptance and production without drift
- Webhooks and notifications — getting events out to where your people already are
Recently updated
-
2026-08-02 — The whole reference re-verified against the code. Twelve pages carried a claim that had stopped being true: the approvals page described a decide surface that moved to the inbox, the wizard page listed a step deleted in July, the LDAP page documented the generic vendor under an AD title, and the JML page said access empties the moment somebody is terminated — which the grace window made only half true. Generic REST and LDAP / Active Directory were rewritten outright.
-
2026-08-02 — External onboarding: how contractors and partner staff get in, and why no intake path can skip the gates.
-
2026-08-02 — Operating rhythm, environments and staged config and a glossary — the year-three shelf, and one place to check a word.
-
2026-08-02 — The governance model is complete: roles and role mining, separation of duties and risk, access requests, and reconciliation rewritten around the engine it has become.
-
2026-08-02 — Governing AI agents: the register, the tier-driven attestation ladder, and what the kill-switch does not reach.
-
2026-08-02 — Privileged access and non-human identities and ownership join the shelves the marketing site was already pointing at.
-
2026-08-02 — Three new pages open the Architecture & trust shelf: tenant isolation, evidence and signed exports, and what we don't claim — the pages a security review asks for first.
-
2026-08-02 — How the product is organized rewritten: it described a navigation retired in July. The portal is also re-shelved into six groups by reader intent instead of one alphabetical concept bucket.
All pages
Architecture & trust — Tenant isolation · Tier-3 hybrid · Evidence and signed exports · What we don't claim · Governing API access
The governance model — Reconciliation engine · How the product is organized · Non-human identities and ownership · Governing AI agents · Roles and role mining · Separation of duties and risk · Filter DSL
Lifecycle & decisions — JML flows · Access requests · External onboarding · Access reviews · Approvals workbench · Approver chains · Privileged access
Systems & data — Onboarding walkthrough · Imports and schedules · Account types · Account rules · Provisioning mappings · Read/write parity · Unstructured data visibility
Running it — Operating rhythm · Platform health · Failed Jobs queue · Platform Advisor · Webhooks and notifications · Environments and staged config · Workflow packages · POC mode
Connector reference — Microsoft Entra ID · LDAP / Active Directory · Salesforce · ServiceNow · Workday HCM · SCIM 2.0 · Generic REST
More — Glossary