Tier 2 · Set policy once

Role-based access control that runs your reviews for you.

Govern adds role-based access control to everything in Insight. You define what each role should have. From then on, Provision uses that policy to generate reviews and to run onboarding and offboarding across every system, delivered to your team as clear tasks and recorded with proof.

What Govern adds

Set access policy once. Let it drive the work.

Define the access each role should have, and keep it current over time. That one policy generates reviews and lifecycle tasks, so your program runs from intent instead of from memory.

  • RBAC policy you set and manage onceDefine the access each role should have, and keep it current over time.
  • Policy-based reviewsRBAC-driven reviews across identities and entitlements, generated from your policy rather than built by hand.
  • Onboarding and offboarding workflowsWhen someone is hired, changes roles, or leaves, Provision issues the right tasks to grant or remove access per policy.
  • Task and proof executionYour team completes each task and attaches evidence, which produces the same defensible, timestamped record Insight is known for, now driven by policy.
# Role: Branch Teller I
role: branch_teller_i
description: "Teller line, cash & deposits only"
entitlements:
  - system: CoreBank
    perm: TELLER_DEPOSIT  risk: 3
  - system: CoreBank
    perm: CASH_DRAWER    risk: 4
  - system: LoanOS
    perm: LOAN_READ_ONLY risk: 2
review_cadence: quarterly
approvers: [branch_manager, ciso]
# Generates reviews + JML tasks for 214 identities
Tasks, not tickets

Policy issues the work. Your team closes it with proof.

When someone is hired, changes roles, or leaves, Provision issues the exact tasks to grant or remove access per policy. Your team completes each one and uploads evidence, which produces a timestamped, examiner-ready record.

  • Joiner, mover, and leaver tasks generated from policy
  • Each task assigned to the right owner, closed with proof
  • Guided tasks apply your policy across every system
Mover · Priya Anand → Loan Officer II
3 tasks generated
Grant: LoanOS · LOAN_ORIGINATE
completed by IT · proof attached
Done
Revoke: CoreBank · TELLER_DEPOSIT
completed by branch manager · proof attached
Done
Revoke: Cash drawer access
assigned to branch manager · awaiting proof
Open

Coverage across every system, from day one.

Govern covers every system from the start. Reviews and lifecycle actions are delivered as guided tasks, so your policy applies across all of your systems immediately. When you are ready for hands-off execution, Automate adds it across your connected systems.

See Automate →
Who Govern is for

Institutions moving to a policy-based program

Institutions ready to move from item-by-item reviews to a policy-based program. You standardize access by role, tighten onboarding and offboarding, and reduce review effort.

Questions

Govern, answered.

How does Govern cover systems we have not connected?
Reviews and lifecycle actions are delivered to your team as guided tasks, so policy applies to every system from the start. Hands-off execution is added at Automate.
Where do our roles come from?
Many institutions start at Insight to see current access, then use that picture to model roles here. See also what RBAC is.

Govern access by policy.

We will map your roles and show how policy-driven reviews and lifecycle tasks work for your institution.