Skip to content

SafePaaS Summer 2026 Newsletter

SHARE
SafePaaS
Customer newsletter
Summer 2026
Governance · Risk · Identity

Summer
2026

Identity lifecycle, IT General Controls automation, and a first look at Identity 360.

Opening letter

A Message
from Our CTO

Identity lifecycle management remains a critical governance challenge as organizations extend core ERP capabilities with best-of-breed SaaS solutions and integrate multicloud architectures with on-premises systems.

Many organizations use Identity Governance and Administration (IGA) solutions to manage Joiner, Mover, and Leaver processes. However, traditional IGA solutions often fall short of auditors’ compliance expectations. They do not prevent risk during access requests, and periodic reviews may exclude critical identities provisioned outside the IGA platform. Deployments can also be costly and leave identity sources uncovered when vendor connectors are unavailable.

To address these challenges, SafePaaS has introduced two capabilities:

ONE Self-service application onboarding with guided identity-object mapping and role configuration, enabling rapid, affordable coverage for identity lifecycle management and periodic certification.

TWO Enterprise provisioning and deprovisioning of identity roles and privileges across multiple applications using the “People” Role, helping align Human Capital Management and application roles for optimal performance at the lowest acceptable risk level.

We have also expanded our IT General Controls assessment and certification capabilities in response to another growing customer challenge: managing third-party risk across an increasingly complex landscape of cloud and on-premises servers, databases, networks, applications, and service providers.

SafePaaS can support SOX 302 and SOX 404 control testing while automating ITGC assessments and certifications for financial, IT, and operational controls through an integrated risk management platform. This enables organizations to standardize testing, improve accountability, connect findings with remediation, and provide more complete evidence to auditors and other stakeholders.

Looking ahead, we are developing Identity 360 to provide broader visibility across human and non-human identities, including service accounts, APIs, bots, shared accounts, automation, and AI agents. As these identities become more prevalent, organizations will need a consistent way to understand their access, activity, and associated risk across the enterprise.

Thank you for your continued partnership with SafePaaS. We look forward to helping you strengthen compliance, improve security, and gain greater value from your existing identity governance and risk management investments without requiring a disruptive platform replacement.

Hennie Vermeulen
01
New capability
DataPaaS Guided Onboarding

Onboard Security Data from Any Application. No Connector Required

Not every business application has a pre-built connector, but that shouldn’t prevent you from bringing it under governance. DataPaaS Guided Onboarding is a new self-service wizard that lets administrators upload security data directly from a CSV or Excel file and onboard users, roles, privileges, and assignments in minutes without coding, custom integrations, or development projects.

The six-step guided workflow validates your data before it’s imported, automatically provisions the required DataPaaS components, and applies your existing transformation and mapping rules. Once loaded, the data behaves exactly like information collected through a native connector, enabling access monitoring, segregation of duties analysis, reporting, and certifications using the same SafePaaS capabilities.

Why it
matters

With Guided Onboarding, you no longer need to wait for a connector to govern a new application. You can quickly extend governance to virtually any system, catch mapping errors before data is loaded, reuse saved mapping profiles for future imports, and maintain a complete audit history of every import. The result is faster onboarding, broader application coverage, and self-service governance without additional integration effort.

02
Access provisioning
People Role creation, mapping & provisioning

Integrated People Role Creation, Mapping & Provisioning

Access requests are often expressed in business terms, but fulfilled through technical ERP roles and application entitlements that managers do not understand.

A new employee may require access across five or six systems. IT must determine which technical roles to assign, managers are asked to approve unfamiliar role names, and segregation of duties conflicts may not be discovered until after access has been granted.

SafePaaS People Role Management connects the way the business defines a job with the way access is provisioned.

Administrators can create business-friendly People Roles such as AP Manager, Finance Controller, or Procurement Analyst, then map each one to the required roles, privileges, and security contexts across connected applications. SafePaaS checks the role design for segregation of duties conflicts and applies the appropriate approval and provisioning workflow.

Explore People Role Management in more detail
SafePaaS Manage My Access — user information review, current roles and pending access setup
Enterprise iAccess · Manage My Access
Five steps

How It Works

1
Define the business role

Create a People Role using a clear job-based name, description, risk level, and designated owner.

2
Map access across applications

Add the ERP roles, application roles, privileges, and relevant security contexts required for that job function.

3
Identify risk before provisioning

SafePaaS evaluates the mapped access against segregation of duties policies while the People Role is being created and again when a user requests it.

4
Route the request for approval

Clean requests move through the appropriate approval workflow. Requests with conflicts require business justification before access can be approved.

5
Provision and track access

Once approved, SafePaaS sends provisioning instructions to connected systems and records every decision, assignment, and outcome in a versioned audit log. Administrators can monitor provisioning status and retrigger failed assignments from one report.

Outcomes

Business Outcomes

Give new hires the access they need sooner.
Reduce manual role interpretation and provisioning work for IT.
Make access requests easier for employees and managers to understand.
Prevent segregation of duties conflicts before access is granted.
Provision coordinated access across multiple applications in one workflow.
Maintain audit-ready evidence from request through provisioning.
Align Human Capital Management roles with application access as employees join, move, or leave.
Customer tip
Start with a small number of high-volume job functions.

Identify roles that generate frequent access tickets—such as Accounts Payable, Procurement, Finance, or Human Resources—and convert them into standardized People Roles. This can deliver an immediate improvement in provisioning speed, approval quality, and policy enforcement.

03
Compliance
IT General Controls Automation

Scale and Automate IT General Controls Testing Across an Expanding Digital Landscape

The challenge is no longer simply having a compliance process, it is ensuring that process can keep pace with an expanding technology landscape spanning cloud and on-premises applications, servers, databases, networks, infrastructure, and third-party service providers.

Compliance Management System — assessment plans Asset Library — total, active, critical, under review and decommissioned assets Asset inventory with linked risks and controls
Assessments · Certifications
GRC libraries · Assets
Six questions

When control testing relies on spreadsheets, email, shared folders, and disconnected tracking systems, even basic questions become difficult to answer:

Which controls have been tested?
Which assessments are overdue?
Where is the supporting evidence?
Who owns each finding?
Which remediation actions remain open?
Can an auditor see the complete history of an issue?

SafePaaS IT General Controls Automation connects assessments, certifications, evidence, findings, remediation, and reporting in one integrated process.

Lifecycle

Automate the Control Testing Lifecycle

SafePaaS enables compliance, IT, risk, and audit teams to:

01 Centralize regulations, risks, ITGCs, application and third-party controls, assets, and supporting documentation.
02 Plan, assign, execute, review, and approve control assessments through standardized workflows.
03 Launch certifications with configurable questionnaires, ownership rules, and approvals.
04 Monitor outstanding responses, overdue activities, findings, and remediation in real time.
05 Link each issue to its originating assessment, related control, owner, evidence, due date, and approval history.
06 Provide current dashboards covering assessment progress, certification completion, issue aging, remediation status, and overall compliance health.
07 Produce complete, traceable evidence for SOX 302, SOX 404, internal audits, and other compliance requirements.
Why it matters

As the digital environment expands, scaling manual control testing is neither efficient nor sustainable. SafePaaS helps organizations standardize IT General Controls testing across the enterprise, strengthen accountability, identify delays earlier, and connect findings directly to remediation. The result is less time spent coordinating compliance activities and greater confidence that control status and audit evidence are complete, current, and traceable.

Learn more about ITGCs and SOX
04
What’s coming next
Identity 360

See Every Identity in One Place

Most organizations can quickly identify their employees.

Far fewer can answer:

Which service accounts retain privileged access?
Which contractors have been inactive for months?
Who owns each API, bot, or AI agent?
Which non-human identities pose the greatest business risk?

Identity 360 provides a complete inventory of human and non-human identities across the enterprise, helping organizations understand who—or what—has access to critical business systems.

Identities 360 — unified view of identity privileges, life cycle and risk posture
SafeInsight · Identity Analytics · Identities 360
How it works

How Identity 360 Works

Identity 360 continuously collects identity data from connected systems, including Active Directory, Microsoft Entra ID, Okta, Oracle, SAP, Salesforce, and other business applications.

Each identity is automatically:

Classified by identity type.
Linked to an owner when available.
Evaluated for governance and security risks.
Monitored continuously for changes.

Instead of searching across multiple directories and applications, teams can work from a single, searchable inventory that stays current as the environment changes.

Quickly Identify the Identities That Need Attention

Complete visibility is valuable, but knowing where to focus first is essential.

Identity 360 evaluates identities using multiple risk indicators, helping teams prioritize accounts that require immediate review, including:

Dormant accounts that no longer serve a business purpose.
Contractors or third-party users with excessive access.
Shared accounts without clear ownership.
Segregation of duties conflicts.
Overprivileged users.
Service accounts requiring ownership or certification.
Accounts with governance policy violations.

Rather than manually reviewing thousands of identities, administrators can focus immediately on those presenting the greatest business risk.

Non Human Identities — NHI discovery engine and incident report Access Graph — identity to entitlement path with risk paths detected
Non-human identities · access graph
05
Customer Success Story

Modernizing Oracle GRC: How a U.S. Federal Agency Simplified Access Governance and Continuous Monitoring

When Oracle announced the end of support for Oracle Governance, Risk, and Compliance (GRC), organizations faced an important decision: migrate to multiple point solutions, build custom processes, or adopt a modern governance platform.

One U.S. federal agency used this transition to modernize its identity governance and compliance program with SafePaaS.

The agency needed more than a like-for-like replacement. It wanted greater visibility into user access, more automated governance processes, and less manual effort supporting audits across its Oracle E-Business Suite environment.

With SafePaaS, the agency brought access governance, segregation of duties, access certifications, provisioning workflows, continuous controls monitoring, and audit reporting together on a single cloud platform. Rather than recreating legacy GRC processes, it redesigned them to improve automation, increase visibility, and reduce administrative overhead.

Improvements delivered

With SafePaaS, the agency can now:

Continuously monitor segregation of duties risks rather than rely on periodic reviews.
Automate user access reviews with complete audit evidence.
Streamline provisioning and approval workflows while enforcing access policies.
Give security, compliance, and audit teams real-time visibility into access risks.
Replace manual evidence collection with automated reporting.
Why it matters

Many Oracle E-Business Suite customers are now planning their Oracle GRC migration strategies. Modernization is not simply about replacing an end-of-life product; it is an opportunity to simplify governance, improve audit readiness, and reduce the effort required to maintain compliance.

SafePaaS provides a unified platform for identity governance, segregation of duties, access certifications, compliance automation, and continuous monitoring, helping organizations strengthen controls while reducing manual work.

06
Did You Know?

Managers Can Review Actual User Permissions not Just Business Roles

Many organizations believe they conduct comprehensive access reviews because managers approve users based on business roles. In practice, reviewers often see only the assigned role’s name not the underlying entitlements and privileges that determine what a user can actually do.

For example, a manager may approve a user with an Accounts Payable Manager role without knowing that it also permits the user to create suppliers, modify payment details, or approve invoices above a specified threshold.

Without this visibility, managers may approve access they cannot fully evaluate.

See the Access That Really Matters

SafePaaS allows reviewers to examine the entitlements and privileges behind each role, providing the context needed to make informed certification decisions.

Instead of reviewing role names alone, managers can evaluate:

Individual privileges Application permissions Sensitive business functions High-risk entitlements Segregation of duties conflicts

This helps reviewers understand exactly what they are approving while providing stronger evidence for auditors.

Get More from Your Access Reviews

If you already use SafePaaS Access Reviews, consider these best practices:

Configure campaigns to display entitlement-level permissions alongside business roles.
Include access from ERP systems, Active Directory, SaaS applications, and other connected sources in the same review.
Prioritize certifications for privileged users and high-risk applications.
Use segregation of duties insights to identify risky access combinations.
Export audit-ready evidence directly from completed certification campaigns.

These changes can significantly improve certification decisions while reducing the effort required during audits.

Quick tip

Before launching your next certification campaign, ask:

“Can reviewers clearly understand what each user is actually able to do?”

If the answer is no, consider enabling entitlement-level reviews. Giving managers more context leads to better certification decisions, stronger compliance evidence, and more meaningful access governance.

Get Started with Access Reviews
Product Resources
Release notes

Recent enhancements

18-Jun-2026 12:00AM Enhancement EAM-1786 EAM>Detect Violations

Included email address for a user in the Violations reports to allow users to view and report on email infomration within the affected reports.

28-May-2026 12:00AM Enhancement DTP-1368 DTP>Setup>Manage Data Source

Enhanced metadata snapshot extraction performance using parallel processing

28-May-2026 12:00AM Enhancement DPS-135 DPS>Manage Snapshot

Enhanced the DataPaaS snapshots to include details through a link to the snapshot details page.

14-May-2026 12:00AM Enhancement MTP-565 MTP>Manage Monitors

Enhanced the Incident approval for Monitors to allow user that receive the incident notifications to Approve or Reject the incidents.

30-Apr-2026 12:00AM Enhancement EIA-399 EIA>Manage My Access

Introduced the ability to Request Email notification/intimation On Approved access

30-Apr-2026 12:00AM Enhancement EIA-397 EIA>Manage My Access

Introduced the ability to Request To Show Violations Only For Requested Role