Platform / Layer 4
Layer 4

Revoking access should be one act, not a hopeful tour of six consoles.

When an account is compromised, the question is not whether you can disable it. It is whether you can be sure that everything which trusted it has stopped — and in most estates that answer is assembled by hand, product by product, while the incident is still running.

The argument
Access is decided in one place and enforced at every machine. The decision and the enforcement are deliberately separate: a central policy says who may do what, and the agent on each machine applies it locally — so enforcement keeps working when the network does not, and revoking something is a single act rather than a hope that six products all honoured it.

The second idea here is that a live session is not a standing permission. Releasing a held containment action requires proving who you are again, at that moment — so a stolen session, however valid, still cannot approve anything that changes your world.
Ask the access record
authored example, not live data

Reports here answer questions in plain language, and every sentence they return carries the evidence behind it. Pick a question an auditor actually asks.

The answer
Nine identities could reach billing-db in August. Two of them belong to people who left the company during the month — one lost access the same day, and one kept it for eleven days after their last working day.
access.grant · billing-db · 9 identities · 2026-08-01 → 08-31
Six people and three service accounts. The service accounts are named on the full report.
identity.departed · s.iyer · last-day 08-06 · access-ended 08-06T18:20Z
Removed the same day, by the joiner-mover-leaver rule.
identity.departed · r.khan · last-day 08-09 · access-ended 08-20T09:14Z
Eleven days. The gap is the finding, and it is what this question exists to surface.
The honest limits
We can only revoke what we are the authority for
Where another identity provider issues the credential, we can tell you it exists and stop it reaching your machines — we cannot end its session inside a third party's product.
An unmapped machine cannot enforce a decision
Enforcement happens where the agent runs. Somewhere with no agent is not covered by it, and coverage is reported as a count of machines rather than a percentage that flatters us.
A permission we never read is not enforced
If a policy declares something nothing consumes, the platform says so rather than accepting it quietly. Desired state you believe is in force but isn't is worse than a gap you know about.
Some questions have no answer, and get none
Where a field was never recorded, a report says it was never measured rather than returning a zero. A confident number is worth less than a stated gap.
What this layer deliberately does not do
It does not become your identity provider. If you already have one, this layer reads from it rather than asking you to migrate — replacing a working directory is a two-year project nobody asked for in the middle of a security purchase.

It also does not let a permission be granted permanently and quietly. Access to the most sensitive material is requested, approved by a second person, and used — with all three recorded — rather than sitting on an account indefinitely because someone needed it once.
Words this page introduced
Full glossary →
Standing — whether an identity may do a particular thing right now, rather than whether it signed in successfully.
Step-up — proving who you are again at the moment of a consequential act, not at the start of the day.
Second person — someone other than the requester approving. The requester can never be their own approver.
Evidence link — the record behind a sentence in a report. No uncited claim ships.
This layer's capabilities
All 88 →
Authentication and step-up
per seat
Enterprise sign-on and provisioning
flat
Privileged access and sessions
per seat
Non-human identity inventory
included
Policy declaration and assurance
included
Reports and evidence export
per report
← Floor below
Doing something
The gate whose holds this layer's step-up releases.
The loop closes
Back to the floor
Every decision on this floor becomes an event on the first one — including ours.
The platform
All 88 capabilities Capability atlas Anatomy of an event Integrations Platform support
Commercial
Pricing Sizing your estate Trial licences
Evidence
Proof Honest limits Trust Security Changelog
Who it is for
For partners For auditors Working here
Learn
Resources Research Coverage gates Academy Glossary Essays
Tools
Check a message Stop a report