IDENTITY & ACCESS

Access that opens on day one and closes on the last.

Most breaches start with a login, not malware — a reused password, an admin right nobody took back, an account that outlived the employee. Cyfriq makes identity the strongest link.

STOPS: ACCOUNT TAKEOVER · PRIVILEGE ABUSE · LINGERING ACCESS
IN ONE LINE Log people in, decide what they can reach, prove who has access, and cut it off when they leave — in one place.
THE FEATURES
01
Identity Provider (IdP) — one authority every application trusts.

Cyfriq verifies every sign-in itself — or sits in front of your existing Microsoft/Google identity, giving one governed view of every login with no migration.

02
Single Sign-On (SSO) — in once, out everywhere.

One session opens every sanctioned app, with desktop SSO on managed Windows. If an account is compromised, revoke every session estate-wide in seconds — including sessions opened before you noticed.

03
Multi-Factor Authentication — a second proof, sized to each group.

Authenticator app, text message, one-time code by email, fingerprint or face, or a physical security key — different methods for different groups, one policy.

04
Adaptive MFA — silent until something looks wrong.

Ordinary logins flow through untouched; challenges fire only on anomalies — unfamiliar geography, odd hours, unknown device, out-of-character behaviour. Less prompt fatigue, not more.

05
Identity Governance (IGA) — the auditor's answer on one screen.

Who has access, who approved it, when it was last reviewed. Scheduled access reviews, rules that stop one person holding conflicting powers, access that expires on its own, and a fully logged emergency-access route.

06
Privileged Identity Management (PIM) — nobody holds admin permanently.

Rights are requested, approved, used and auto-expired, every privileged action recorded. "Who held admin last quarter?" answers: nobody, permanently.

07
Provisioning & Password Sync — day-one access, last-day shutdown.

Joiner-mover-leaver automated across email, storage and business apps via SCIM (the standard that auto-syncs staff accounts between systems); passwords sync; Cyfriq reads back actual current access, so reviews reflect reality, not a stale list.

08
Access Policies & Session Control — the right system, only in the right context.

Office-network-only, working-hours-only, managed-device-only, per system. Location-hiding connections flagged or blocked. Partners onboard themselves without ever seeing your admin consoles.

IN THE REAL WORLD

A developer's laptop is stolen at 2am.

Instead of resetting passwords across 30 systems one by one, the team cancels every session created after 2am in a single action — and because rights weren't standing, the stolen device opens nothing.

See it on your own network.

A 14-day pilot with success criteria you set. First findings in 7 days — yours to keep either way.

Book a demo Explore the platform