Concept reference rapidvalue.eu →

RapidValue IGA — Documentation

Concept reference for Identity Governance & Administration (IGA) builders, and for the security, IT and procurement audiences evaluating RapidValue. These pages explain the product's model and the reasoning behind it — not click-by-click instructions. They state what the product does not do as deliberately as what it does.

Choose your path

Four readings, in the order each one needs. The sidebar is a shelf; this is the route.

Evaluating how governance is modelled

You want to know how the product thinks, not which buttons exist.

  1. Reconciliation engine — Expected versus Actual access, and why that comparison is the engine rather than a report
  2. How the product is organized — the shape of the thing, and the rule that keeps it coherent
  3. JML flows — what a joiner, mover and leaver actually trigger
  4. Access reviews — one review engine, three trigger types
  5. Approver chains — multi-step and quorum, one canonical shape
  6. Roles and role mining — how roles get built without a consultancy project
  7. Separation of duties and risk — toxic combinations, and risk as a sum you can audit
  8. Non-human identities and ownership — who answers for the machines, and what "unowned" actually means
  9. Filter DSL — the single syntax behind triggers, conditions and SoD rules
  10. Tier-3 hybrid architecture — where it runs and what crosses the wire

Implementing it for a client

The configuration path, end to end.

  1. Onboarding wizard walkthrough — zero to an active system
  2. Imports and schedules — how data arrives, and the cadence floor
  3. Account types and account rules — how accounts are categorised and correlated
  4. Provisioning mappings — the write path
  5. Read/write parity — what happens when the read and write halves drift apart
  6. The connector reference for the systems you are connecting

Running a security or procurement review

What is isolated, what can be proven, and what we refuse to claim.

  1. Tenant isolation — application scoping as the primary control, row-level security as the database-enforced backstop, and the canary that proves it
  2. Evidence and signed exports — why an auditor should believe what the product reports, and how to verify a pack without us
  3. What we don't claim — the published register: measurement honesty, the assurances we do not hold, and the functional edges
  4. Tier-3 hybrid architecture — deployment modes; secrets never travel from the control plane to the agent
  5. Governing API access — scoped machine credentials, secret-once storage, per-request enforcement
  6. Governing AI agents — agents as governed identities, and the kill-switch's real boundary
  7. Unstructured data visibility — what we can and cannot see on file shares

Keeping it healthy in year three

Maintainability is a product claim, so here is the surface that has to back it.

  1. Operating rhythm — what to actually check weekly, monthly and quarterly, and what "healthy" looks like
  2. Platform health — sweep health, backup status, and an honest health surface
  3. Failed Jobs queue — where provisioning failures land, and the retry gate that stops "click until it works"
  4. Platform Advisor — the detector framework that finds problems before you do
  5. Environments and staged config — dev, acceptance and production without drift
  6. Webhooks and notifications — getting events out to where your people already are

Recently updated

All pages

Architecture & trustTenant isolation · Tier-3 hybrid · Evidence and signed exports · What we don't claim · Governing API access

The governance modelReconciliation engine · How the product is organized · Non-human identities and ownership · Governing AI agents · Roles and role mining · Separation of duties and risk · Filter DSL

Lifecycle & decisionsJML flows · Access requests · External onboarding · Access reviews · Approvals workbench · Approver chains · Privileged access

Systems & dataOnboarding walkthrough · Imports and schedules · Account types · Account rules · Provisioning mappings · Read/write parity · Unstructured data visibility

Running itOperating rhythm · Platform health · Failed Jobs queue · Platform Advisor · Webhooks and notifications · Environments and staged config · Workflow packages · POC mode

Connector referenceMicrosoft Entra ID · LDAP / Active Directory · Salesforce · ServiceNow · Workday HCM · SCIM 2.0 · Generic REST

MoreGlossary