Access Governance
Know who has access to what — and who shouldn’t. Access Governance (ISPM) correlates identities across your systems and anchors them to your workforce directory, so departed or over-privileged accounts can’t hide.
What it is
Cross-system identity correlation and access review. Vigil matches accounts in AWS, GitHub, and Claude to the people in your Microsoft 365 or Google Workspace directory, then flags the mismatches.
What you get
- Identity correlation across AWS, GitHub, and Claude, anchored to your M365 / Google Workspace directory
- Offboarding-gap detection — someone disabled in your directory but still active in a cloud or SaaS system
- Risky-access findings — no-MFA, orphaned, dormant, and stale-credential accounts
- Cross-system risk ranking — the riskiest access, ordered, plus a per-person access profile
- User Access Review export (CSV / PDF) — ready for SOC2 / ISO CC6.1–6.3 evidence
How to enable
An add-on that requires a Microsoft 365 or Google Workspace connector as its identity anchor — connect that first (see Microsoft 365 / Google Workspace). Then connect the systems you want reviewed (AWS, GitHub, Claude).
How to read it
- Risk list — cross-system access issues, ranked by severity.
- Per-person profile — everything a given person can access, across systems, in one place.
- Offboarding gaps — accounts that should have been removed when someone left.
- Access review export — generate a CSV/PDF to hand an auditor.
FAQ
Why do I need Microsoft 365 or Google Workspace connected? Your directory is the source of truth for who works here. Without it, Vigil can’t tell an orphaned account from a legitimate one.
Which systems can it review? AWS, GitHub, and Claude today, correlated against your workforce directory.
How does this help with audits? User Access Reviews are a core SOC2 / ISO control. The CSV/PDF export gives auditors the evidence directly.