Apex Steward

Stop maintaining IAM governance in spreadsheets.

Identity governance, finally tracked end to end: an implementation plan built from your environment, live compliance coverage across six frameworks, AI conflict detection against your vendor's own deployment guide, and board-ready reporting on one click.

We configure your workspace and walk your team through it.

The compliance dashboard: six frameworks, coverage computed live from the same evidence engine. Illustrative demo data.

At a glance

Your plan, your vendor's methodology, and your compliance obligations, in one place.

Six compliance frameworks computed live: NIST CSF 2.0, ISO/IEC 27001:2022, SOC 2 CC6, SOX ITGC, HIPAA Security Rule, PCI DSS v4.0
Implementation plan generated from your environment, with every step mapped to the controls it evidences
Four-dimension maturity model, six levels, tracked over time
AI conflict detection against your vendor's actual deployment guide, with page citations
One-click executive PDF, footnoted and versioned
Platform agnostic: SailPoint, Saviynt, Okta IG, Entra ID Governance, One Identity, Oracle IAM
Who it's for

Three people who live in different parts of the product.

Mid-market security teams, roughly 250 to 2,500 employees. Too big for spreadsheets, too small or too fast-moving for a six-figure enterprise IGA rollout.

IAM program manager

Owns the day-to-day rollout. Lives in the implementation plan and the maturity assessments. Needs to know what is done, what is next, and what the next step is worth.

Security and compliance owner

Lives on the compliance dashboard. Exports the executive report for auditors, the board, or a parent company. Needs coverage they can defend, with the gaps stated honestly.

Implementation consultant

Internal or external. Runs many client workspaces from one account as a shared source of truth: uploads vendor docs, reviews conflict analysis, and hands the client a plan that matches the vendor's own methodology.

What it does

Eight modules that make up a working IAM governance practice.

Every module below is live in the application today. Apex Steward is the structural pieces of an IGA program, modeled in software, kept in sync, and backed by one evidence engine.

Module 01

Onboarding: intake plus discovery

One combined flow. Intake captures the environment: deployment model, directory topology, IGA platform, HR or ERP system of record, joiner, mover and leaver scope, governance features, regulated-data flags, audit posture. Discovery goes deeper across six sections, from compliance obligations to architecture and helpdesk readiness, with save-as-you-go and per-section completion marks. Plan generation is gated server side until intake, discovery, and the vendor guide are in. Glossary cards explain IGA, JML, SoD, RBAC versus ABAC, and birthright access on every jargon-heavy page.

Module 02

Maturity assessment

Six levels, 0 Non-existent through 5 Optimized, across four dimensions: Lifecycle Events, Application Onboarding, Access Request Process, and Access Reviews and Certification Campaigns. A quick path gives a single overall score in under a minute; a detailed per-dimension path feeds the compliance evidence engine. Every assessment is saved with its timestamp and taker, a history chart shows progression, and results tie back to the plan steps that would move the weakest dimension.

Module 03

Implementation plan

Generated from onboarding and tailored to scope: ordered phases and steps, no dates, because every organization moves at its own pace. Each step carries a status, completion stamps, notes, and a 'Maps to N controls' chip strip tying it to the exact NIST, ISO, SOC 2, SOX, HIPAA, or PCI subcategories it evidences. Upload a vendor guide and adopt its plan wholesale or blend specific phases in. Stable step keys mean check-offs survive regeneration, and plans are versioned with a diff between candidate and live.

Module 04

Compliance dashboard

Six frameworks out of the box, all driven by one evidence engine: the latest maturity assessment plus current plan-step statuses. Coverage is computed live, partial credit is given honestly, and unmapped controls are surfaced rather than hidden.

See the coverage detail
Module 05

Applications and roles

An application inventory with owner, criticality, onboarding status, and type. Roles bundle the applications they grant through many-to-many links carrying free-form entitlements, because every platform names its entitlement fields differently. A Boolean eligibility rule builder with row-level AND, OR, and NOT, type-aware operators, and a plain-English live preview: 'Eligible when Department is Finance AND Country is US AND NOT Job Title contains Intern.' AI-assisted drafting turns 'all US-based finance managers' into reviewable rule rows. Nothing is saved until a human approves it.

Module 06

Vendor documents and AI conflict detection

Upload the deployment guide for SailPoint, Saviynt, Okta IG, Entra ID Governance, One Identity, or Oracle. Apex Steward ingests the PDF or DOCX, embeds it, and unlocks three AI surfaces: vendor plan extraction with page citations and verbatim quotes; conflict analysis returning four to ten severity-coded divergences, each citing the exact user-side field and vendor-side page; and a per-step reference panel that answers free-form questions with cited passages.

How conflict analysis works
Module 07

Executive reports

One click produces a PDF for the CISO, the board, a SOC 2 auditor, or a parent company: cover and executive summary, maturity scorecard with trend, critical gaps ranked by severity, a 90/180/360 day roadmap, risk callouts, and a footnoted citation on every claim. Each report snapshots its inputs and is versioned per workspace. Re-rendering an earlier version does not re-run the AI.

See a report page
Module 08

Steward, the conversational assistant

A chat layer over the program. It answers IAM and implementation questions grounded in the workspace, and turns a stated change in reality ('they are on Oracle, not Workday') or a roadblock ('the connector will not authenticate') into a structured accept-or-reject proposal. It never silently changes the live plan. An admin applies the change, and it is audit-logged: who asked, who committed. The whole trail is downloadable.

The differentiator

Extraction finds the plan. Conflict analysis tells you where you diverge.

Act one: extraction

Upload the vendor deployment guide.

Apex Steward ingests it, embeds it, and extracts the vendor's own prescribed phase and step plan, with page citations and verbatim quotes. Adopt it wholesale or blend specific phases into your plan.

Act two: conflict analysis

Compare your reality to their methodology.

It then compares your intake, your discovery answers, your maturity scores, and your live plan against that prescribed methodology and returns severity-coded divergences. Each one cites the exact field on your side and the exact page on the vendor's side.

Apex Steward implementation plan page showing a 95% context confidence banner and an AI conflict analysis summary with five critical conflicts, four warnings, and one note.
Implementation plan with conflict analysis.A Context Confidence banner states how complete the picture is. Below it, the AI conflict analysis ranks criticals, warnings, and notes against the vendor's guide. Demo workspace.

Bring a vendor deployment guide and watch the conflict analysis surface real divergences in under a minute.

Compliance

Six frameworks, one engine.

NIST CSF, ISO 27001, SOC 2 CC6, SOX ITGC, HIPAA, and PCI DSS, all driven by the same maturity and plan-step evidence model. Coverage is computed live against the latest maturity assessment and the current plan-step statuses. No manual attestation spreadsheet.

Apex Steward compliance page with NIST CSF, ISO 27001, SOC 2, and SOX tabs, a context confidence bar, and coverage tiles for the NIST Cybersecurity Framework.
The compliance dashboard.Framework tabs, live coverage, and covered, partial, not covered, and mapped counts per framework. Demo workspace.
Always on

NIST CSF 2.0

Govern, Identify, Protect, and Detect, with the PR.AA identity and access control subcategories mapped in full.

Always on

ISO/IEC 27001:2022

Annex A.5 and A.8, with ISO 27002 implementation guidance and an ISO 27018 overlay for personal data in cloud services.

Always on

AICPA SOC 2

Trust Services Criteria CC6, logical and physical access.

Always on

SOX IT General Controls

The access-relevant subset.

Suggested by context

HIPAA Security Rule

§164.308 administrative safeguards and §164.312 technical safeguards, suggested when the workspace indicates it handles PHI.

Suggested by context

PCI DSS v4.0

Requirement 7 (access by business need to know) and Requirement 8 (identify and authenticate users), suggested when the workspace handles cardholder data.

Partial credit given honestly. A half-implemented control reads as half implemented.
Unmapped controls surfaced, not hidden.
Context-aware suggestion banners ('you handle PHI, enable HIPAA?') keep the workspace owner in control. Nothing is auto-enrolled.
Maturity scoring

Four dimensions. Six levels. Tracked over time.

Level 0 Non-existent through level 5 Optimized, scored across Lifecycle Events, Application Onboarding, Access Request Process, and Access Reviews and Certification Campaigns. A quick assessment gives one overall score in under a minute; the detailed assessment feeds the compliance evidence engine.

Apex Steward maturity page with a current level of 0.0 out of 5, four dimension tiles, a radar chart of the latest assessment, and a scores-over-time chart.
Maturity.Current level, the four-dimension profile, and score progression over time. Every assessment is saved with its timestamp and taker. Demo workspace.
Executive reports

One click to a board- and auditor-ready PDF.

Every claim carries a footnoted citation: a vendor document page, a plan step key, or a compliance subcategory identifier. Each report snapshots its inputs and is versioned per workspace, so re-rendering an earlier version reproduces exactly what was true then.

Executive report · v3Demo workspace

IAM governance program: state of the program

Executive summary

The program is at maturity level 2 of 5 overall, with Access Reviews and Certification Campaigns the weakest dimension.1 NIST CSF 2.0 coverage stands at 71%, with four PR.AA subcategories not yet evidenced.2 The vendor's methodology requires a monthly privileged-account review; the current plan schedules one annually.3

Maturity scorecard
Lifecycle Events3 / 5
Application Onboarding2 / 5
Access Requests2 / 5
Access Reviews1 / 5
Critical gaps, ranked
  1. No service-account or machine-identity governance in scope.3
  2. Certification cadence diverges from vendor policy.3
  3. Helpdesk training plan absent from Phase 2.4
1Detailed maturity assessment, 2026-08-30, taker: program manager2Compliance engine, NIST CSF 2.0 PR.AA-01 through PR.AA-063Vendor deployment guide, pages 42 and 1184Plan step key phase-2.helpdesk-readiness

Illustrative report page with demo data.

Inside the workspace

The rest of the day-to-day.

Apex Steward workspace overview showing a get-started checklist with five of six steps complete.
Workspace overview.A get-started checklist and a first-run tour take a new workspace from intake to a generated plan.
Apex Steward chat view with example prompts and tabs for proposals and plan history.
Steward, the assistant.Ask about the plan or tell it what changed. It proposes; an admin approves. Proposals and plan history sit beside the chat.
Apex Steward applications inventory listing AWS, GitHub, Okta, SAP S/4HANA, Salesforce, ServiceNow, and Workday with criticality and status columns.
Applications.The inventory roles reference: type, owner, criticality, and onboarding status per application.
Apex Steward roles page listing Finance Analyst, Account Executive, HR Business Partner, Help Desk Analyst, and IAM Engineer with application and eligibility rule counts.
Roles.Each role defines application access, entitlements, and Boolean eligibility rules.
Why Apex Steward

Disciplined defaults, transparent AI, honest scores.

Soft gates, not hard locks. Context-aware honesty. AI grounded in the source.

Six frameworks, one engine

The same evidence model drives all six. Toggle per workspace. Coverage computed live, not attested by hand.

Grounded AI, always cited

Every AI claim traces back to its source: a vendor document page, a plan step key, or a compliance subcategory. Never speculative.

AI proposes, humans approve

Plan changes and role rules arrive as reviewable proposals. Nothing mutates silently. Every applied change is audit-logged.

Honest about what it does not know

A Context Confidence banner on every output states how much of the picture the platform has, and what would raise it. Soft gates with explicit opt-out instead of hard blockers.

Boolean eligibility without the parentheses

Row-level AND, OR, NOT with a plain-English live preview. The 5% case that confuses 95% of users is simply not in the UI.

Progress survives regeneration

Stable step keys mean changing your environment does not reset your check-offs.

Cost and staleness controls

Every AI call is logged with model, token counts, and estimated cost. Per-user daily limits. 'Re-analyze' prompts when the inputs have moved on.

Built on

Production-grade, not vibe-coded.

FrontendReact 18, TypeScript, Vite, Tailwind CSS, TanStack Query, React Router, Recharts
BackendNode.js 20, Express, TypeScript (ESM), Zod validation, Prisma ORM
DatabasePostgreSQL in production; SQLite for local development only
AIClaude for generation, extraction, and reasoning; Voyage AI for embeddings
DocumentsPDF and DOCX ingestion, embedding, and retrieval; server-side PDF rendering for reports
AuthEmail and password, bcrypt, JWT in an httpOnly Secure cookie, email verification
HostingAWS Elastic Beanstalk on Amazon Linux 2023, Nginx
SecretsAWS SSM Parameter Store
Security posture

What buyers actually ask about.

Multi-tenant isolation at the workspace boundary
Role-based access within a workspace: owner, admin, member
Passwords hashed with bcrypt, sessions as JWT in an httpOnly Secure cookie, email verification required
Environment-driven CORS allowlist; secrets held in AWS SSM Parameter Store, never in the repository
AI call audit log with model, token counts, and estimated cost per call, plus per-user daily AI rate limits
Change audit trail on the assistant: who proposed, who committed, downloadable
Context Confidence disclosure as a stated product principle
SOC 2 Type II is on the roadmap, not attained
How you get started

We configure it around your environment before your team ever logs in.

An IGA program is specific to one organization's directory topology, HR system, vendor platform, and regulatory obligations, so the platform is set up around those facts first. Not a trial you have to assemble. A program that is accurate on day one.

01

Talk to us. A short call about your environment: directory, HR system of record, IGA platform, and what your auditors are asking for.

02

We set up your workspace. We provision the tenant, run the onboarding and discovery capture with your team, and load your vendor deployment guide.

03

Your plan is generated. The implementation plan, compliance baseline, and maturity baseline are in place on day one, built from your actual environment.

04

You run the program. Your team works the plan. We stay available for configuration changes and new workspaces.

Frequently asked

Questions buyers ask before a demo.

Which IGA platforms does Apex Steward work with?
SailPoint, Saviynt, Okta Identity Governance, Entra ID Governance, One Identity, and Oracle IAM. It is platform agnostic, and 'undecided' is a valid answer during onboarding, so teams can start before they have signed with a vendor.
Which compliance frameworks does Apex Steward support?
Six: NIST CSF 2.0, ISO/IEC 27001:2022, SOC 2 CC6, SOX ITGC, HIPAA Security Rule, and PCI DSS v4.0. The first four are always on. HIPAA and PCI DSS are suggested based on the data your organization handles and enabled only when you confirm.
Does it replace my IGA platform?
No. It governs the program around the platform: the rollout, the evidence, the maturity trend, and the reporting. It is the layer your auditors and your board actually ask about.
What does the AI actually do?
It extracts your vendor's prescribed plan from their own deployment guide, flags where your approach diverges from it, answers questions against those documents, drafts role eligibility rules, and proposes plan changes. Every output cites its source, and every change is approved by a person before it applies.
Is Apex Steward SOC 2 certified?
SOC 2 Type II is on our roadmap. The platform helps you evidence SOC 2 CC6 controls for your own program today.
Can I sign up and try it myself?
Not today, and that is deliberate. Apex Steward is configured around your directory topology, your HR system of record, your IGA platform, and your regulatory obligations before anyone logs in. We provision the workspace and run the setup with your team, so the plan and the compliance baseline are accurate from day one rather than something you assemble yourself.
How long does setup take?
A working call to capture the environment, then onboarding and discovery with your team. Your implementation plan and compliance baseline exist at the end of it.
How is it priced?
Custom, based on workspace count and scope. Talk to us.

Book a walkthrough.

We set up the workspace, load your environment, and walk your team through the plan, the compliance baseline, and the report. One call to start.