Identity & Access Management

One identity. Every system. Full accountability.

Iraje IAM decides who gets access to what, for how long, and on whose approval — then proves it. Joiners are productive on day one, movers lose what they no longer need, and leavers are cut off across every connected system the moment HR marks them exited.

Deploys

On-prem, private cloud or hybrid

Converges with

Iraje PAM and EPM

Evidence for

DPDP, RBI, SEBI, IRDAI, ISO 27001

The problem

Access is easy to grant and almost never taken back

Most breaches don’t start with a broken firewall. They start with a valid login that should have been switched off months ago — a contractor who finished, a developer who changed teams, a shared service account nobody owns. Identity is now the control plane, and spreadsheets can’t govern it.

Day 1

New joiners should have exactly the access their role needs before they open a laptop — not a week of raised tickets and borrowed credentials.

Role change

Internal moves are where entitlements pile up. Old access is rarely revoked, so privilege quietly accumulates across every year of service.

Exit

An orphaned account is a live credential with no owner and no one watching it. Auditors look for these first — and so do attackers.

Identity lifecycle

Joiner, mover, leaver — driven by HR, not by tickets

Iraje IAM treats your HR system as the source of truth. A record changes there, and entitlements across every connected system change with it. No manual provisioning queue, no forgotten revocation.

JOIN

Before day one

Joiner

Birthright access is derived from the role, department and location on the HR record, then provisioned automatically.

  • Role-based access templates
  • Automated account creation via SCIM / LDAP
  • Manager notified with the full grant list
MOVE

On role change

Mover

The new role’s entitlements are added and the old role’s are removed in the same transaction, so privilege never quietly accumulates.

  • Delta calculated against the new role
  • Segregation-of-duties conflicts flagged
  • Time-boxed handover access, auto-expiring
LEAVE

Within minutes of exit

Leaver

Disable first, delete later. Sessions are terminated, tokens revoked and accounts suspended across every connected system, with data retained for audit.

  • Active sessions killed, refresh tokens revoked
  • Owned service accounts reassigned, not orphaned
  • Signed revocation record kept for evidence

The gap Iraje closes: in most organisations, joiner automation gets built first and leaver automation never gets finished. Iraje IAM ships both on the same policy engine, and reports on the difference between what HR says and what your systems actually allow.

See a lifecycle walkthrough

Capabilities

What’s in the platform

Everything you need to run identity as a control, delivered as one product rather than four integrations you maintain yourself.

Single sign-on

SAML 2.0, OAuth 2.0 and OpenID Connect federation, so one authenticated session carries across web, cloud and internal applications.

Adaptive MFA

Step-up authentication that reacts to device, location, network and time — strong where risk is high, invisible where it isn’t.

Lifecycle automation

HR-driven joiner, mover and leaver workflows with automated provisioning and de-provisioning across connected systems.

Role & attribute policy

RBAC for the stable 80% of access, ABAC for the rest — evaluated against live attributes rather than a static group membership.

Access request & approval

A self-service catalogue with multi-level approval chains, business justification capture and automatic expiry on temporary grants.

Access certification

Scheduled recertification campaigns that put entitlement lists in front of the right manager and revoke whatever isn’t confirmed.

Segregation of duties

Conflict rules that block toxic entitlement combinations at request time, instead of surfacing them in an audit finding later.

Just-in-time access

Elevated entitlements granted for a defined window and withdrawn automatically, so standing privilege stops being the default.

Audit & reporting

Immutable records of every grant, approval, denial and revocation, exportable as regulator-ready evidence packs.

Authentication

Verify the person, not just the password

Iraje evaluates each sign-in against context before it decides how much proof to ask for. A finance controller opening the ERP from the office at 10am is not the same event as the same account authenticating from an unmanaged device at 3am.

  • TOTP, push approval, hardware token and biometric factors
  • Device posture and managed-endpoint checks before session start
  • Impossible-travel and unfamiliar-network detection
  • Self-service password reset with verified recovery paths
  • Session timeouts and re-authentication on sensitive actions

How a sign-in is decided

  1. 01

    Identify

    The account is resolved against the directory and its current HR status is checked. Suspended records never reach a password prompt.

  2. 02

    Score the context

    Device, network, geography, time of day and recent behaviour are evaluated against the user’s baseline.

  3. 03

    Choose the challenge

    Low risk clears with SSO. Elevated risk triggers step-up MFA. High risk is blocked and raised to the security team.

  4. 04

    Authorise the entitlement

    Policy decides what this session may actually reach — not simply whether the login succeeded.

  5. 05

    Record it

    The decision, its inputs and its outcome are written to the audit trail, ready for the next review.

Reports your auditor asks for

Orphaned and ownerless accounts

Dormant accounts by days inactive

Entitlements granted outside the approval workflow

Segregation-of-duties conflicts, open and resolved

Privileged entitlement holders by system

Certification completion by business unit

Governance

Recertification that managers actually complete

Certification campaigns fail when reviewers are handed a thousand rows of raw entitlements. Iraje presents access in business language, pre-flags what looks wrong, and turns a manager’s decision into an executed revocation rather than a spreadsheet comment.

  • Quarterly, annual or event-triggered campaigns
  • Outliers highlighted — access nobody else in the role holds
  • Dormant entitlements surfaced from real usage data
  • Revoke decisions executed automatically, with rollback
  • Sign-off certificates produced for the audit file

One platform

IAM, PAM and EPM on a single policy engine

Identity governance stops at the standard user in most stacks — administrators and endpoints get bolted on separately. Iraje runs all three from the same directory, the same policy model and the same audit trail, so a leaver loses their application access, their privileged sessions and their local elevation rights in one action.

You are here

IAM

Governs standard workforce identity — lifecycle, SSO, entitlements, certification and access requests.

Explore IAM

Privileged access

PAM

Vaults credentials, brokers privileged sessions, records and watermarks activity, and enforces command-level control on servers, databases and network devices.

Explore PAM

Endpoint privilege

EPM

Removes local admin rights, elevates approved applications just in time, and audits what runs on every managed endpoint.

Explore EPM

Integrations

Connects to what you already run

Iraje IAM federates with your existing directory rather than replacing it, and provisions outward through open standards. Where an application has no modern connector, connectors can be built against its API or database — including the older core systems that usually get left out of governance.

Active DirectoryAzure AD / Entra IDLDAP directoriesSAML 2.0OAuth 2.0 / OIDCSCIM 2.0RADIUSKerberosHR systemsITSM & ticketingSIEM & log forwardingREST API

Compliance

Evidence, not assurances

Indian and global frameworks all ask variations of the same three questions: who had access, who approved it, and when was it last reviewed. Iraje IAM answers them from the audit trail rather than from a reconstructed spreadsheet.

FrameworkWhat it expectsHow Iraje IAM supports it
DPDP Act, 2023Access to personal data limited to what the purpose requires, with accountability for processing.Purpose-bound entitlements, approval records against every grant, and revocation logs on exit.
RBI cyber-security frameworkRole-based access, periodic review of user rights, and strong authentication for critical systems.RBAC policy model, scheduled certification campaigns, adaptive MFA on sensitive applications.
SEBI CSCRFLeast privilege, segregation of duties, and auditable trails of access changes.SoD conflict rules at request time, immutable change history, exportable review evidence.
IRDAI guidelinesControlled onboarding and offboarding of users with documented authorisation.HR-triggered joiner and leaver automation with signed approval and revocation records.
ISO/IEC 27001:2022Annex A controls on identity, authentication information and access rights.Identity register, entitlement catalogue and review cycles mapped to the relevant controls.
SOC 2 & PCI-DSSLogical access controls, unique IDs, and evidence of periodic access review.Per-user identifiers, no shared accounts, and campaign reports ready for the auditor’s sample.
NIST SP 800-53 / Zero TrustContinuous verification and least-privilege enforcement across every access decision.Context-scored authentication, just-in-time entitlements, and policy re-evaluation per session.

Next step

Find out what your systems are actually allowing

Most conversations start with a review of orphaned and dormant accounts across your environment. It takes about an hour, and it usually surprises people. Bring your last audit finding and we’ll show you how the platform closes it.