Avertari watches your HR system and identity provider for joiners, movers and leavers, then tells you exactly what access should change, and why. It works alongside the tools you already run.
Read-only connectorsNothing changes without approvalUK-hosted
event streamacme.avertari.io
Leaver
Dana Okafor's last day is Friday 3 October
BambooHR · employment.terminated · 2 min ago
Suggested actions · 3
−Suspend Okta account at 17:30 on 3 OctTimed to end of last working dayReview
⇄Transfer Google Drive ownership to manager412 files owned, 38 shared externallyReview
−Revoke 2 GitHub personal access tokensNot covered by SSO: survives account suspensionReview
Mover
Priya Shah moved from Sales to Finance
Workday · worker.job_changed · 9 min ago
Suggested actions · 3
−Remove Salesforce · Sales AdminNo one else in Finance holds this roleReview
+Request NetSuite · AP ClerkHeld by 9 of 11 peers in FinanceReview
!Separation of duties: raise and approve paymentsWould hold both roles for 1 day if timed badlyReview
Joiner
Tom Reyes starts Monday as a Platform Engineer
HiBob · employee.created · 21 min ago
Suggested actions · 3
+Create Entra ID account on FridayReady before day one, not afterReview
+Add to group eng-platformMatches the 6 other Platform EngineersReview
+GitHub · platform team, AWS · read-onlyLeast-privilege baseline for the roleReview
Illustrative example · names and data are fictional
Building connectors for
Microsoft Entra IDOktaGoogle WorkspaceBambooHRWorkdayHiBobPersonioGitHubSlack
The problem
Your HR system knows the moment someone leaves. Your identity provider finds out when somebody remembers to tell it.
01 / Leavers
Access outlives employment
Accounts, tokens and shared files stay active after the last day. Nobody is watching the gap between HR and IT.
02 / Movers
Access only ever grows
People get new access when they change roles and rarely lose the old. After a few moves, someone has access that no single role would allow.
03 / Joiners
Day one starts with tickets
New starters wait on access requests, or get a copy of someone else's access "to be safe". Either way, it's guesswork.
Joiners, movers, leavers
Every people change, turned into the right access change.
Avertari connects HR events to real identities and accounts, compares them with what similar people hold, and suggests exactly what should change. Every suggestion comes with the reason for it.
Joiner
Ready on day one, and no more than the role needs
A suggested baseline built from the access held by people in the same role, not a copy of whoever sits nearby.
Accounts created before the start date
Groups matched to role and team
Anything unusual flagged for review
Mover
New access in, old access out
Role changes suggest what to add and what to remove, so access doesn't keep piling up with each move.
Leftover access from the old role, flagged
Conflicting roles caught before the change
Hand-offs suggested to the new manager
Leaver
Everything closed off, including what SSO misses
A complete checklist for each leaver, timed to their last day, including the access that SSO doesn't cover.
Accounts suspended at end of last day
Personal tokens and keys identified
Data ownership handed over, not lost
How it works
Connect in minutes. Stay in control.
01
Connect, read-only
Grant Avertari read-only access to your HR system and identity provider. Wherever the vendor supports it, you approve access through their own admin-consent screen, so you don't paste passwords or long-lived keys.
02
Detect
Avertari matches HR events to the identities and accounts they affect, the moment they happen, and compares them with what similar people hold.
03
Suggest & approve
You get a clear, explained list of access changes. Approve them, send them to your ticketing tool or dismiss them. Nothing changes without a person deciding.
Security
Read-only by design.
We're asking to see your identity data, so we've built Avertari to keep what it holds, and what it could do, to a minimum.
Connectors ask only for read scopes. Avertari can't change anything in your systems, so a compromise of Avertari can't either.
Consent, not keys
We use admin consent or signed-key authentication wherever vendors support it. Where a vendor only offers API keys, they're encrypted with a key unique to your organisation.
Isolated per customer
Each organisation's data and credentials are separated at the database and encryption-key level, not just in application code.
Hosted in the UK
Customer data is stored and processed in the United Kingdom. Where it lives is enforced by cloud organisation policy.
Design partners
Help shape Avertari from the first release.
We're working with a small group of IT and security teams on the first connectors. You get early access, direct input on what we build and design-partner pricing. We get your honest feedback.