IDENTITY & ACCESS

Access that opens on day one and closes on the last.

Most breaches start with a login, not malware — a reused password, an admin right nobody took back, an account that outlived the employee. Cyfriq makes identity the strongest link.

STOPS: ACCOUNT TAKEOVER · PRIVILEGE ABUSE · LINGERING ACCESS
IN ONE LINE Authenticate, authorise, govern and de-provision — in one place.
THE FEATURES
01
Identity Provider (IdP) — one authority every application trusts.

Cyfriq verifies every sign-in itself — or sits in front of your existing Microsoft/Google identity, giving one governed view of every login with no migration.

02
Single Sign-On (SSO) — in once, out everywhere.

One session opens every sanctioned app, with desktop SSO on managed Windows. If an account is compromised, revoke every session estate-wide in seconds — including sessions opened before you noticed.

03
Multi-Factor Authentication — a second proof, sized to each group.

Authenticator app, SMS, email OTP, biometric or hardware security key — different methods for different populations, one policy.

04
Adaptive MFA — silent until something looks wrong.

Ordinary logins flow through untouched; challenges fire only on anomalies — unfamiliar geography, odd hours, unknown device, out-of-character behaviour. Less prompt fatigue, not more.

05
Identity Governance (IGA) — the auditor's answer on one screen.

Who has access, who approved it, when it was last reviewed. Scheduled certifications, segregation-of-duties enforcement, self-expiring access, a fully recorded break-glass route.

06
Privileged Identity Management (PIM) — nobody holds admin permanently.

Rights are requested, approved, used and auto-expired, every privileged action recorded. "Who held admin last quarter?" answers: nobody, permanently.

07
Provisioning & Password Sync — day-one access, last-day shutdown.

Joiner-mover-leaver automated across email, storage and business apps via SCIM; passwords sync; Cyfriq reads back actual current access, so reviews reflect reality, not a stale list.

08
Access Policies & Session Control — the right system, only in the right context.

Office-network-only, working-hours-only, managed-device-only, per system. Location-hiding connections flagged or blocked. Partners onboard themselves without ever seeing your admin consoles.

IN THE REAL WORLD

A developer's laptop is stolen at 2am.

Instead of resetting passwords across 30 systems one by one, the team cancels every session created after 2am in a single action — and because rights weren't standing, the stolen device opens nothing.

See it on your own network.

A 14-day pilot with success criteria you set. First findings in 7 days — yours to keep either way.

Book a demo Explore the platform