Access reviews, joiner-mover-leaver, the service desk queue, the runbook that only one person can execute. IT gets more out of an agent platform than most teams — and is the team that has to say yes to it first. This page does both halves.
Runbooks that execute · deny-by-default reach · SAML 2.0 single sign-on
IT work is unusually well suited to this: it is procedural, it is written down somewhere already, and the cost of it not happening is invisible right up until an audit or an incident.
The mover case is where it earns its keep. A joiner gets a checklist and a leaver gets urgency; someone changing team quietly keeps both sets of access forever. A scheduled session finds those and drafts the revocations.
Who has what, how long they have had it, and when they last used it. It produces the review with a proposed action per row rather than a spreadsheet that gets forwarded twice and approved unread.
It reads the ticket, classifies it, finds whether your own documentation already answers it, and drafts the reply with the article linked. The ones it cannot answer get routed with the diagnosis already attached.
Write it down as a skill file and a session can execute it. That is the durable version of "ask Marta" — it survives Marta being on holiday, and improving it is a change request rather than a corrected memory.
What you pay for against what is assigned against what was opened this quarter. It writes the reclaim list per tool with the last-used date on every row.
It compares what your documentation says is configured against what is actually configured, and reports the difference. Reporting drift is safe and useful. Silently correcting it is neither, and it will not.
The artifact IT actually needs is not a dashboard. It is a list, with a defensible reason attached to each line, in a state where approving it does something.
| Principal | Grant | Granted | Last used | Recommendation |
|---|---|---|---|---|
| j.okafor | db · read-write | 14 mo | 9 mo | Revoke — moved to Support in Q1 |
| deploy-bot | registry · push | 8 mo | 2 h | Keep — in the release path |
| a.lindqvist | admin console | 22 mo | never | Revoke — granted for a migration |
| support-agent | helpdesk · read | 3 mo | 11 m | Keep — scoped, read only |
Kortix has a real account, member, group and role model with per-resource permissions for people and for agents. An access review that covers your humans and not your automation is half a review.
Revoke because they moved team. Keep because it is in the release path. A review you can approve in ten minutes is one where the reasoning is on the line, not in a separate document.
Revocation is a write, and writes are where you set a gate. The default configuration for a review session should be read-everything, change-nothing, and propose.
IT tooling is the least uniform stack in the company. Connect what is in the catalogue; define the rest yourself. Either way the credential is decrypted on our side and never enters the machine.
Easy connect covers 3,000+ apps through their own OAuth screens. We are not going to claim your identity provider, your MDM and your network vendor are all in it — for an IT estate the direct connector types are usually the real path, and they take about the same three minutes.
The same session machinery started three ways. IT is the function where the scheduled mode does the most good, because the work that gets skipped is the work with no deadline attached.
Someone mentions the bot in the IT channel. The thread becomes a session, the session reads your documentation, and the answer lands back in the same thread with the source quoted.
Set every write against an identity or an entitlement to Ask. The run holds at the call with the exact change in front of you, and resumes from that point when you approve. Set the irreversible ones to Block instead.
A cron trigger opens the quarterly access review and the monthly licence reconciliation. Triggers name the agent they run as, so the unattended session has exactly the reach the attended one has — no more.
You are also the team that has to approve this. Here are the answers, including the ones that are less flattering than the version you usually get on a page like this.
One project, one set of connectors, one memory that compounds. Each team writes the skills for its own work; nobody stands up a second system.
Open source and self-hostable. Any model, your keys. Kortix Cloud, your own VPC, or your own on-prem network.