When employees leave, their access leaves too. Automatically. On your servers.

AccessRevoke is an IAM security agent that removes OAuth gaps and employee access to Microsoft Entra ID, Google Workspace, Slack and GitHub the moment someone leaves or changes role. It runs entirely inside your own infrastructure — we never see, store or host your access data.

accessrevoke.internal.yourcompany.com / dashboard

Total Employees

247

+3 today

Active Risks

4

↑ 2 new

Revoked (30d)

18

↓ 6 pending

Apps Monitored

4

All connected

Access Monitor

6 of 247 shown
EmployeeStatusRisk

Milica Jovanović

Sr. Engineer

active
Low

Stefan Ilić

Product Manager

offboarded
Critical

Ana Kovačević

Data Analyst

active
Low

Nikola Perić

Sales Lead

offboarded
High

Jelena Stanković

DevOps Eng.

active
Medium

Marko Babić

Designer

revoked
Clean

Revoke Failed

Stefan Ilić still has Slack access. Offboarded 3 days ago.

Integrations

E

Entra

4 min ago

G

GW

2 min ago

S

Slack

1 min ago

G

GH

8 min ago

Why should you trust AccessRevoke

Trust by architecture, not by promise.

Most access-governance tools ask you to hand over your identity data. AccessRevoke is built the other way around: the agent runs on your servers, so there is nothing to hand over.

100%

of your access data stays in your network

15 min

maximum detection window for JML events

0

external data processors added to your stack

Audit-ready

timestamped logs, generated in-house

Now in pilot — a limited number of founding-customer slots for 2026.

Pilot partners get hands-on deployment support and founding-customer pricing that ends when the pilot cohort is full.

Book a Call

The Problem

Manual offboarding is a security liability.

Your company runs on dozens of workspace and identity tools. When employees leave, IT teams manually check each admin panel. OAuth tokens and app access survive. Audits require proof that never gets collected.

63%

of businesses still have former employees with active access to corporate data through unrevoked SaaS accounts.

Wing Security · 2024

5+ hrs

average time IT teams spend manually deprovisioning a departing employee's cloud and SaaS access.

Nudge Security · 2023

$4.7M

average cost of a data breach where stolen or compromised credentials were the initial attack vector.

IBM / Ponemon · 2025

Tap or hover stats to verify · industry research

How AccessRevoke Handles It

HR Change

Employee offboarded in HRIS

AR Scan

AccessRevoke detects the change

Detection

Orphaned access identified

Revoke

Access revoked across all apps

Audit Log

Timestamped record created

Self-Hosted Architecture

Your access data never leaves your network.

AccessRevoke is not a cloud service you send data to. It is an agent you install inside your own infrastructure — a Docker container or VM behind your firewall. We ship the software; you keep the data.

Your infrastructure

AccessRevoke Agent

Docker / VM, behind your firewall

Microsoft Entra ID
Google Workspace
Slack
GitHub

Tokens, access records and audit logs are stored and encrypted here — and only here.

Outside your network

AccessRevoke (the company) provides software updates and support. We have no access to your environment and no copy of your data.

No new third-party processor

AccessRevoke never touches your identity data, so there is no data-processing agreement to negotiate and no new entry in your vendor-risk register for your access data.

Audit log available, always

Every revoke, grant and failed action is logged inside your perimeter — audit evidence your compliance team can export without asking anyone for it.

Platform

Everything a security team needs.

Purpose-built for access governance. Not a bolt-on feature of a larger platform.

Visibility

Unified Access Visibility

One dashboard showing every employee's access state across all connected workspace and identity tools. No more tab-switching between admin panels.

  • Live access inventory across every connected provider
  • Role-based access grouping and filtering
  • Cross-app orphan detection in a single view
Automation

Automated JML

Detect joiner, mover and leaver events and automatically apply access policies. AccessRevoke acts within 15 minutes of an offboarding event.

  • HR change detection via webhook or polling
  • Configurable approval gates before revoke
Compliance

Audit Logs

Every revoke, grant and failed action is recorded with full timestamps and actor attribution — evidence that supports NIS2, ISO 27001 and SOC 2 audit preparation.

  • Immutable audit trail with timestamps
  • CSV and JSON export for auditors
Integrations

Native Integrations

Deep, native integrations with the four platforms where orphaned access hurts most — plus a REST API and webhooks to connect your HR system or internal tools. The connector roadmap is driven by our pilot partners.

Microsoft Entra IDGoogle WorkspaceSlackGitHubOther integrations on request

How It Works

From install to automated offboarding in a day.

Four steps from zero visibility to fully automated access governance — all inside your own network.

Deploy the agent in your infrastructure

Docker Compose or VM image. Our engineers join the install call — typical deployment fits in a working day.

01

Deploy the agent in your infrastructure

02

Connect your identity & workspace tools

03

The agent monitors JML events

04

Access reviewed & revoked

01

Deploy the agent in your infrastructure

Install AccessRevoke as a Docker container or VM inside your own network, behind your firewall. From day one, everything the agent sees stays on your servers.

Docker Compose or VM image. Our engineers join the install call — typical deployment fits in a working day.

02

Connect your identity & workspace tools

Authorize the agent to read and manage access in Microsoft Entra ID, Google Workspace, Slack and GitHub. Your HR system can push joiner/mover/leaver events via webhook or REST API.

OAuth 2.0 and service accounts, minimal scopes per provider. Credentials are encrypted and stored only on your servers.

03

The agent monitors JML events

Every 15 minutes, the agent scans for HR events, compares access states, and flags discrepancies. Alerts are sent to your security inbox or Slack channel.

Configurable scan intervals. Slack, email, and webhook alerting supported.

04

Access reviewed & revoked

Based on your policy, access is automatically revoked or queued for manual approval. Every action is logged with actor, timestamp, and outcome — inside your perimeter.

Fully automated, approval-gated, or alert-only per integration and role level.

Who We Are

Engineers who lived this problem.

We built AccessRevoke because we know how much hours have been spent manually auditing access after employees left. We know what security teams actually need.

Team Member 1

Radomir Malobabić

Co-Founder | Software Engineer

Engineer with hands-on experience in many different projects such as AirPulse and Sizif AI. Striving with continuous efforts to upgrade and give most to AccessRevoke. Promising up and coming software engineer with 2 National Competition participations in Serbia under his belt.

Team Member 2

Stefan Sofronijević

Co-Founder | Business Development

Main person responsible for the business development and sales. Also responsible for the overall strategy and direction of the company. Shared experience with Radomir and David at Airpulse, WeFinance, GeoQuest etc. Participated in many Erasmus projects.

Team Member 3

David Koloski

Co-Founder | Marketing & PR

Marketing and PR person responsible for the general outreach and branding of the company. Brings stability and consistency to the company. Shared experience with Stefan and Radomir on all projects such as WeFinance, GeoQuest and AirPulse.... Participated in volunteering and Erasmus projects.

FAQ

Common questions.

Pilot Program

See what access still exists after employees leave.

Book a 30-minute call with our engineers. We'll walk through the self-hosted architecture, scope the deployment for your environment, and answer the questions your security team will ask. Founding-customer pricing applies while pilot slots last.

30-minute technical call
Deployment scoping included
Runs in your infrastructure
No obligation