Compliance
Mapped to the controls your auditor already checks.
Every automated action AccessRevoke takes maps to a specific ISO 27001 or SOC 2 control, listed below.
ISO 27001:2022 (Annex A)
| What AccessRevoke does automatically | Control | Why it matches |
|---|---|---|
| Detects Joiner/Mover/Leaver events | A.5.16: Identity management | Full identity lifecycle: registration, provisioning, maintenance, de-registration |
| Grants access on join, via pre-defined role mapping | A.5.18: Access rights | Role mapping is the approval, defined once and applied consistently |
| Removes old access + grants new on internal role change | A.5.18: Access rights (modification) | Directly prevents privilege creep |
| Revokes access on departure | A.5.18 + A.5.15: Access control | HR oversight of the leaver process, built in |
| Cleans up orphaned OAuth tokens | A.5.17: Authentication information | Credential and secret management, not just passwords |
| Immutable log of every action | A.8.16: Monitoring activities | Direct evidence for security event correlation and audits |
SOC 2 (Trust Services Criteria: Security)
| What AccessRevoke does automatically | Control | Why it matches |
|---|---|---|
| Access granted only via pre-defined, least-privilege role mapping | CC6.1 | The mapping is the formal authorization, set once per role and applied consistently |
| Access removed immediately on Leaver/Mover events, no manual step | CC6.2 | CC6.2 requires prompt removal on departure or role change, exactly where auditors most often find gaps at companies doing this manually |
| Continuous (not periodic) visibility into who has what access | CC6.3 | Stronger evidence than a quarterly manual review |
| Immutable, timestamped log of every grant/revoke | CC7.2 | What auditors sample directly: provisioning and termination events with a full trail |
Get the full compliance mapping.
ISO 27001 and SOC 2, control by control. Free, no email required.