Compliance

Mapped to the controls your auditor already checks.

Every automated action AccessRevoke takes maps to a specific ISO 27001 or SOC 2 control, listed below.

ISO 27001:2022 (Annex A)

What AccessRevoke does automaticallyControlWhy it matches
Detects Joiner/Mover/Leaver eventsA.5.16: Identity managementFull identity lifecycle: registration, provisioning, maintenance, de-registration
Grants access on join, via pre-defined role mappingA.5.18: Access rightsRole mapping is the approval, defined once and applied consistently
Removes old access + grants new on internal role changeA.5.18: Access rights (modification)Directly prevents privilege creep
Revokes access on departureA.5.18 + A.5.15: Access controlHR oversight of the leaver process, built in
Cleans up orphaned OAuth tokensA.5.17: Authentication informationCredential and secret management, not just passwords
Immutable log of every actionA.8.16: Monitoring activitiesDirect evidence for security event correlation and audits

SOC 2 (Trust Services Criteria: Security)

What AccessRevoke does automaticallyControlWhy it matches
Access granted only via pre-defined, least-privilege role mappingCC6.1The mapping is the formal authorization, set once per role and applied consistently
Access removed immediately on Leaver/Mover events, no manual stepCC6.2CC6.2 requires prompt removal on departure or role change, exactly where auditors most often find gaps at companies doing this manually
Continuous (not periodic) visibility into who has what accessCC6.3Stronger evidence than a quarterly manual review
Immutable, timestamped log of every grant/revokeCC7.2What auditors sample directly: provisioning and termination events with a full trail

Get the full compliance mapping.

ISO 27001 and SOC 2, control by control. Free, no email required.

Download the compliance mapping (PDF)