Stop maintaining IAM governance in spreadsheets.
Identity governance, finally tracked end to end: an implementation plan built from your environment, live compliance coverage across six frameworks, AI conflict detection against your vendor's own deployment guide, and board-ready reporting on one click.
We configure your workspace and walk your team through it.
The compliance dashboard: six frameworks, coverage computed live from the same evidence engine. Illustrative demo data.
Your plan, your vendor's methodology, and your compliance obligations, in one place.
Three people who live in different parts of the product.
Mid-market security teams, roughly 250 to 2,500 employees. Too big for spreadsheets, too small or too fast-moving for a six-figure enterprise IGA rollout.
IAM program manager
Owns the day-to-day rollout. Lives in the implementation plan and the maturity assessments. Needs to know what is done, what is next, and what the next step is worth.
Security and compliance owner
Lives on the compliance dashboard. Exports the executive report for auditors, the board, or a parent company. Needs coverage they can defend, with the gaps stated honestly.
Implementation consultant
Internal or external. Runs many client workspaces from one account as a shared source of truth: uploads vendor docs, reviews conflict analysis, and hands the client a plan that matches the vendor's own methodology.
Eight modules that make up a working IAM governance practice.
Every module below is live in the application today. Apex Steward is the structural pieces of an IGA program, modeled in software, kept in sync, and backed by one evidence engine.
Onboarding: intake plus discovery
One combined flow. Intake captures the environment: deployment model, directory topology, IGA platform, HR or ERP system of record, joiner, mover and leaver scope, governance features, regulated-data flags, audit posture. Discovery goes deeper across six sections, from compliance obligations to architecture and helpdesk readiness, with save-as-you-go and per-section completion marks. Plan generation is gated server side until intake, discovery, and the vendor guide are in. Glossary cards explain IGA, JML, SoD, RBAC versus ABAC, and birthright access on every jargon-heavy page.
Maturity assessment
Six levels, 0 Non-existent through 5 Optimized, across four dimensions: Lifecycle Events, Application Onboarding, Access Request Process, and Access Reviews and Certification Campaigns. A quick path gives a single overall score in under a minute; a detailed per-dimension path feeds the compliance evidence engine. Every assessment is saved with its timestamp and taker, a history chart shows progression, and results tie back to the plan steps that would move the weakest dimension.
Implementation plan
Generated from onboarding and tailored to scope: ordered phases and steps, no dates, because every organization moves at its own pace. Each step carries a status, completion stamps, notes, and a 'Maps to N controls' chip strip tying it to the exact NIST, ISO, SOC 2, SOX, HIPAA, or PCI subcategories it evidences. Upload a vendor guide and adopt its plan wholesale or blend specific phases in. Stable step keys mean check-offs survive regeneration, and plans are versioned with a diff between candidate and live.
Compliance dashboard
Six frameworks out of the box, all driven by one evidence engine: the latest maturity assessment plus current plan-step statuses. Coverage is computed live, partial credit is given honestly, and unmapped controls are surfaced rather than hidden.
See the coverage detailApplications and roles
An application inventory with owner, criticality, onboarding status, and type. Roles bundle the applications they grant through many-to-many links carrying free-form entitlements, because every platform names its entitlement fields differently. A Boolean eligibility rule builder with row-level AND, OR, and NOT, type-aware operators, and a plain-English live preview: 'Eligible when Department is Finance AND Country is US AND NOT Job Title contains Intern.' AI-assisted drafting turns 'all US-based finance managers' into reviewable rule rows. Nothing is saved until a human approves it.
Vendor documents and AI conflict detection
Upload the deployment guide for SailPoint, Saviynt, Okta IG, Entra ID Governance, One Identity, or Oracle. Apex Steward ingests the PDF or DOCX, embeds it, and unlocks three AI surfaces: vendor plan extraction with page citations and verbatim quotes; conflict analysis returning four to ten severity-coded divergences, each citing the exact user-side field and vendor-side page; and a per-step reference panel that answers free-form questions with cited passages.
How conflict analysis worksExecutive reports
One click produces a PDF for the CISO, the board, a SOC 2 auditor, or a parent company: cover and executive summary, maturity scorecard with trend, critical gaps ranked by severity, a 90/180/360 day roadmap, risk callouts, and a footnoted citation on every claim. Each report snapshots its inputs and is versioned per workspace. Re-rendering an earlier version does not re-run the AI.
See a report pageSteward, the conversational assistant
A chat layer over the program. It answers IAM and implementation questions grounded in the workspace, and turns a stated change in reality ('they are on Oracle, not Workday') or a roadblock ('the connector will not authenticate') into a structured accept-or-reject proposal. It never silently changes the live plan. An admin applies the change, and it is audit-logged: who asked, who committed. The whole trail is downloadable.
Extraction finds the plan. Conflict analysis tells you where you diverge.
Upload the vendor deployment guide.
Apex Steward ingests it, embeds it, and extracts the vendor's own prescribed phase and step plan, with page citations and verbatim quotes. Adopt it wholesale or blend specific phases into your plan.
Compare your reality to their methodology.
It then compares your intake, your discovery answers, your maturity scores, and your live plan against that prescribed methodology and returns severity-coded divergences. Each one cites the exact field on your side and the exact page on the vendor's side.

Bring a vendor deployment guide and watch the conflict analysis surface real divergences in under a minute.
Six frameworks, one engine.
NIST CSF, ISO 27001, SOC 2 CC6, SOX ITGC, HIPAA, and PCI DSS, all driven by the same maturity and plan-step evidence model. Coverage is computed live against the latest maturity assessment and the current plan-step statuses. No manual attestation spreadsheet.

NIST CSF 2.0
Govern, Identify, Protect, and Detect, with the PR.AA identity and access control subcategories mapped in full.
ISO/IEC 27001:2022
Annex A.5 and A.8, with ISO 27002 implementation guidance and an ISO 27018 overlay for personal data in cloud services.
AICPA SOC 2
Trust Services Criteria CC6, logical and physical access.
SOX IT General Controls
The access-relevant subset.
HIPAA Security Rule
§164.308 administrative safeguards and §164.312 technical safeguards, suggested when the workspace indicates it handles PHI.
PCI DSS v4.0
Requirement 7 (access by business need to know) and Requirement 8 (identify and authenticate users), suggested when the workspace handles cardholder data.
Four dimensions. Six levels. Tracked over time.
Level 0 Non-existent through level 5 Optimized, scored across Lifecycle Events, Application Onboarding, Access Request Process, and Access Reviews and Certification Campaigns. A quick assessment gives one overall score in under a minute; the detailed assessment feeds the compliance evidence engine.

One click to a board- and auditor-ready PDF.
Every claim carries a footnoted citation: a vendor document page, a plan step key, or a compliance subcategory identifier. Each report snapshots its inputs and is versioned per workspace, so re-rendering an earlier version reproduces exactly what was true then.
IAM governance program: state of the program
Executive summary
The program is at maturity level 2 of 5 overall, with Access Reviews and Certification Campaigns the weakest dimension.1 NIST CSF 2.0 coverage stands at 71%, with four PR.AA subcategories not yet evidenced.2 The vendor's methodology requires a monthly privileged-account review; the current plan schedules one annually.3
Maturity scorecard
Critical gaps, ranked
- No service-account or machine-identity governance in scope.3
- Certification cadence diverges from vendor policy.3
- Helpdesk training plan absent from Phase 2.4
Illustrative report page with demo data.
The rest of the day-to-day.




Disciplined defaults, transparent AI, honest scores.
Soft gates, not hard locks. Context-aware honesty. AI grounded in the source.
Six frameworks, one engine
The same evidence model drives all six. Toggle per workspace. Coverage computed live, not attested by hand.
Grounded AI, always cited
Every AI claim traces back to its source: a vendor document page, a plan step key, or a compliance subcategory. Never speculative.
AI proposes, humans approve
Plan changes and role rules arrive as reviewable proposals. Nothing mutates silently. Every applied change is audit-logged.
Honest about what it does not know
A Context Confidence banner on every output states how much of the picture the platform has, and what would raise it. Soft gates with explicit opt-out instead of hard blockers.
Boolean eligibility without the parentheses
Row-level AND, OR, NOT with a plain-English live preview. The 5% case that confuses 95% of users is simply not in the UI.
Progress survives regeneration
Stable step keys mean changing your environment does not reset your check-offs.
Cost and staleness controls
Every AI call is logged with model, token counts, and estimated cost. Per-user daily limits. 'Re-analyze' prompts when the inputs have moved on.
Production-grade, not vibe-coded.
What buyers actually ask about.
We configure it around your environment before your team ever logs in.
An IGA program is specific to one organization's directory topology, HR system, vendor platform, and regulatory obligations, so the platform is set up around those facts first. Not a trial you have to assemble. A program that is accurate on day one.
Talk to us. A short call about your environment: directory, HR system of record, IGA platform, and what your auditors are asking for.
We set up your workspace. We provision the tenant, run the onboarding and discovery capture with your team, and load your vendor deployment guide.
Your plan is generated. The implementation plan, compliance baseline, and maturity baseline are in place on day one, built from your actual environment.
You run the program. Your team works the plan. We stay available for configuration changes and new workspaces.
Questions buyers ask before a demo.
Which IGA platforms does Apex Steward work with?
Which compliance frameworks does Apex Steward support?
Does it replace my IGA platform?
What does the AI actually do?
Is Apex Steward SOC 2 certified?
Can I sign up and try it myself?
How long does setup take?
How is it priced?
Book a walkthrough.
We set up the workspace, load your environment, and walk your team through the plan, the compliance baseline, and the report. One call to start.