$ every product image on this site is an unretouched screenshot of the running platform — demo tenant, fictional people, captured live
📐 Platform · Policies

See the blast radius
before you save.

Birthright access declared as rules — "every employee in IT gets the AppHub IT group" — built with pickers, simulated live, and enforced by reconciliation.

Visual policy builder

Conditions with pickers, not JSON.

The builder walks you through conditions, target resources and validity. A live simulation names exactly which identities match — before anything goes live.

  • Live simulation: "11 of 46 identities matched", listed by name
  • Pickers bound to your real data — departments, functions, entitlements
  • Time-bound policies with tenant-configurable validity presets
app.rapidvalue.eu/policies · builder
the policy builder — conditions, simulation, blast radius
the policy builder — conditions, simulation, blast radius

Policies that stay true

Reconciliation keeps reality aligned with the rule.

A policy isn't a suggestion: reconciliation continuously compares the declared access against what exists, grants what's missing (gated if you want), and flags what shouldn't be there.

  • Policy-granted access carries its provenance forever
  • Drift from the rule surfaces in the control center with the fix attached
  • Policies can also grant accounts themselves — "every employee gets an AD account"
…/reconciliation
reconciliation — expected vs actual, drift per system
reconciliation — expected vs actual, drift per system

Related

See a policy simulated on your own data.

A 30-minute kickoff connects your HR feed and one system — working POC the same day.