Your copilots act with your users' access. What that changes about access reviews
Warde How it works Screens Agents Connectors Savings Platform Audit Book a walkthrough →
For heads of security and risk

Know who can reach what, and prove it to your auditor.

Warde runs access requests and user access reviews inside your ServiceNow instance. Every grant has an approver on record, every removal is confirmed back from the system that made it, and every review leaves evidence an auditor can test. It works with the identity system you already run, and delivers through ServiceNow tasks where you have none. Nothing to host.

Connects to SailPoint and Microsoft Entra today, and uses ServiceNow tasks where there is no identity engine

Standing access, People & Culture 9 people · 22 entitlements
Harold Payne
Grace Okafor
Nia Bishop
Tom Vestergaard
Fiona Ledger
Dev Sharma
Priya Nair
Marcus Bell
Aiko Tanaka
held high risk expiring in flight conflict

Every square is one grant. Nia Bishop left on 22 August and still holds a high-risk HR role that conflicts with Payroll Approver.

238public companies disclosed a material weakness in fiscal 2025, KPMG found. In IT controls, most were about access
7 yearsof insert-only history for every request, approval, removal and review decision, by default
US$250k+a year of time back for a 10,000-person customer, once most joiners and movers have an access bundle
3 monthsor less to pay back the subscription out of those savings
Two minutes

See it working on a live instance.

A request, an access bundle, My Access, a review, and the setup behind them, all recorded in ServiceNow.

Every line in the video is on screen as text, so it works with the sound off.
Who it is for

Three starting points.

No identity engine

Native governance in your instance

You run ServiceNow with Active Directory or Entra, and access reviews live in a spreadsheet. Warde gives you requests with proper approval, delivery as ServiceNow tasks, and reviews with evidence. Typically 1,000 to 10,000 staff.

Entra or Saviynt shop

Requests and reviews where staff already are

You own a governance product, and staff still ask for access by ticket. Warde puts requests, approvals, user access reviews and My Access in Employee Center. It hands delivery to Entra through its connector. If you run Saviynt, we build that connector with you as soon as you need it. Typically 3,000 to 15,000 staff.

SailPoint shop

Replace the home-built integration

You run IdentityIQ or Identity Security Cloud, with a custom ServiceNow integration somebody built years ago. Warde replaces it with a supported connector, adds user access reviews decided in ServiceNow, and keeps your options open on the vendor. Typically 15,000 staff and up.

How it works

Ask, approve, deliver, review.

One path for every request, whether a connector or a person does the work at the end of it. Removals and review revocations go down the same path.

01 · ASK

One request

Search for access by name and put several applications in one request, for yourself or for somebody else. Duplicates, conflicts and missing prerequisites show before you submit.

02 · APPROVE

The right people, in order

Manager, application owner, security: whatever chain your policy sets. Each approver sees what the access is, in plain words, and why it has come to them.

03 · DELIVER

Your engine provisions it, automatically

Warde sends the approved change to your identity system, and the engine provisions it with no ticket and no manual work. Warde retries, shows the requester a promised date, and reports the request as done only when the engine confirms the change was made. If your engine cannot provision it, or you have none, Warde routes a task to the right team at the right time.

04 · REVIEW

User access reviews, with evidence

Scheduled user access reviews show a reviewer what people hold. Every decision, and every revoke that follows, is recorded in the evidence pack.

Your identity system stays the system of record. Warde does not take over your role model, your policy engine or your identity warehouse. It does not spot the joiner or the leaver either: your HR feed calls its lifecycle endpoint, and Warde provisions from there.

Agents and copilots

An agent inherits the access of whoever ran it.

Copilots and MCP clients act with delegated permission. They can do exactly what the person who ran them can do, and nothing stops them using all of it. Every grant a person should have lost three roles ago is now reachable by software acting in their name.

Warde governs human access. That is what an agent borrows when it acts for somebody.

There is no separate agent entitlement to review. The agent uses the user's, and keeping that correct is what this product was already built for.

Delegation

The agent is the person who ran it

MCP clients and copilots hold delegated permission under OAuth. The agent's ceiling is that person's access, so somebody carrying ten years of accumulated grants hands all of it to something willing to use all of it.

Exposure

Dormant access stops being dormant

A person uses a fraction of what they hold, which is why over-provisioning has been survivable. An agent can use all of it in a second, and a prompt injection reaches exactly as far as the permissions allow.

Machine and non-human identity is a different product, and Warde does not claim it. What Warde will do is let an assistant use it. An MCP server is on the roadmap, so an assistant can raise a request, read what somebody holds or take a review decision, under the same permissions the person has.

The screens

What staff, reviewers and your IAM team see.

All of it lives in Employee Center, which your staff already use for laptops and leave. The screens are built for people who have never heard the word entitlement: plain names, one place to ask, and nothing to learn.

Request access

Search, request, one approval over the lot.

The form is narrowed to what you are allowed to be given. Access you already hold is marked and cannot be asked for twice. Terms of use are read and accepted on the form. Before anything is raised, the form shows the approver your policy resolved to.

Employee Center · Request access
The Request Access form, filled in by Priya Nandan for herself. The Enterprise Applications collection asks its own narrowing questions, then lists eight matching entitlements, including GlobalProtect VPN, Legacy Claims Desktop and SAP Accounts Payable, which she already holds.
  1. 1The application asks its own questions first, so the list that follows fits where you work.
  2. 2Access you already hold is listed and marked, and cannot be asked for a second time.
Access reviews

A user access review a line manager can read.

Reviewers keep or take away access one row at a time or several at once, and hand over any row that was never theirs to judge. Each row shows how the access was granted. Nothing is saved until they choose, and the screen confirms every decision.

Employee Center · A quarterly finance user access review
A quarterly finance user access review, open in front of its reviewer. It has four people to decide on, and each row shows how the access was granted, with Keep, Take away and Hand over buttons.
For the head of identity and access management

One view of where access is drifting.

Access health shows the bundles, applications, entitlements and approval policies that need attention: access nobody has reviewed, entitlements with no approval policy, members still waiting on approval. Other pages cover leavers whose removals have not finished, orphan accounts and reviews past due. Every figure opens the list behind it.

Admin Workspace · Access health · Bundle health
The Admin Workspace's Access health page on its Bundle health tab: donut charts of bundles by state and members by pre-approval state, and bar charts of active assignments and members for each access bundle.
Approval policies

A different approval policy for every kind of access.

Standard access goes to the manager. High-risk access adds the application owner and security. Licensed software adds the licence owner. A bundle is approved once, for everything in it. Each policy is a chain of stages you write in the wizard. Every approver comes from your own data: the requester's manager, the entitlement's owner, a group, a named person, or a field on the application's CMDB record such as who manages it. Conditions read the request line, so a stage can run only for admin accounts or only above a risk rating. If a stage's approver is missing, it falls back to one you name instead of being skipped.

Running it

Your IAM team runs it, with no developer.

Three wizards cover the first setup, each new application and every change to who approves what. It needs no consultant and no update sets.

Initial setup · about a day

Guided setup, thirteen steps

Grant the roles, connect an engine or choose task fulfilment, bind accounts to people, import what they hold, decide who approves, publish the catalog items and My Access, brand the emails, schedule the reviews. Most of the day is spent on your decisions rather than on clicks.

Each application · an afternoon

Onboarding wizard, eight steps

Set the owners, approval policy, expiry and audience. Then one bulk pass gives a plain name, an owner and a risk rating to every entitlement the application brought in.

Each policy change · minutes

Approval policy wizard, four steps

Write or change a chain and try it against a real request before anybody has to live with it.

Connectors

Works with the identity system you own, or with none.

A connector reads what people hold and writes changes back. Every connector is included, and most customers need none.

built

SailPoint Identity Security Cloud

Reads what people hold and writes changes back.

built

SailPoint IdentityIQ

Reads and writes, and confirms that each change was made.

built

Microsoft Entra ID Governance

Reads and writes groups, app roles, licences, directory roles and access packages.

on request

Saviynt

Built with you as soon as you need it.

No identity engine

It works where you have no engine at all.

Provisioning and deprovisioning are dispatched as tasks to the team that owns the application. Requests, approvals, user access reviews and the evidence pack are the same either way.

The other vendors' applications

What each vendor's ServiceNow application does on your instance.

A tick means the work happens in ServiceNow. A dash usually means the vendor does it well in its own console.

  WardeSailPointSaviyntEntraOktaOmada
Ask for access in the ServiceNow catalogyesyesyesyespartly: the documented integration runs the other way, from Okta into ServiceNowyes
Approve it in ServiceNowyesyesyesyespartly: the documented integration runs the other way, from Okta into ServiceNowyes
Your identity engine does the provisioningyesyesyesyesyesyes
User access reviews decided in ServiceNowyesyes, for Identity Security Cloud: SailPoint documents a certification portal in ServiceNow where certifiers approve, revoke and sign offnononono
Campaigns defined and scheduled in ServiceNowyestheir consoletheir consoletheir consoletheir consoletheir console
Approval policies built in ServiceNowyesnonononono
Access bundles curated in ServiceNowyesnonononono
My Access: one page for what you and your team hold, and the reviews waiting on youyespartly: the app shows the roles and access profiles a person holds, without a team view or reviews on the same pagenot statedtheir consoletheir consolenot stated
An admin workspace on the instance: what is stuck, what is stale, connector healthyesnot statednot statednonono
The auditor’s evidence pack, in ServiceNowyesnonononono
Runs with no identity engine at allyesnonononono
Spots the joiner and the leaver for younot on its own: your own joiner and leaver trigger calls Warde’s lifecycle endpoint, and Warde provisions from thereyesyesyesyesyes

Read from each vendor's published documentation in September 2026. For Okta, "partly" means the documented integration runs the other way: a request raised in Okta creates a record in ServiceNow. For SailPoint on the My Access row, it means the app shows what a person holds, without the team view or the reviews waiting. SailPoint's tick on user access reviews is for Identity Security Cloud's Store app, which SailPoint documents as a certification portal where certifiers approve, revoke and sign off. The IdentityIQ integration does not include it. On the last row, Warde does not watch your HR feed. Whichever system already knows somebody has joined or left calls Warde's lifecycle endpoint, and Warde grants or removes the access from there. The full sixty-three-row version, sources attached, is yours if you ask for it.

The business case
US$250k+ a year of time back for a 10,000-person customer, once most joiners and movers have an access bundle: US$282,000 on the figures below. The subscription pays for itself in under three months.
Where it comes fromHours a yearValue
Service desk time on access requests2,625US$118,000
Business time: asking, approving, and new starters waiting to start2,230US$100,000
Access bundles for most joiners and movers: 4,100 fewer approvals1,110US$50,000
High-risk access reviews run as campaigns for each application owner310US$14,000
Total a year6,275US$282,000

If you build roles by hand today, as catalog items or order guides, building them as bundles in Warde saves about US$35,500 a year more.

How each line is worked out
LineBasis, at US$45 an hour
Service desk8,750 access requests a year, 35 percent of 25,000 requested items, at 40 minutes each. Connector fulfilment and named tasks take out 45 percent.
Business timePeople asking: 12 minutes a request, a third removed (590 hours). Approvers: 2 minutes on each approval read, half removed (110). Managers: 40 minutes deciding what each joiner or mover should hold, halved for the half with a bundle (340). New starters: half a day blocked by missing access, a quarter of it back (1,190).
Access bundlesOwners sign off each bundle once, and each request then needs only the line manager. With four in five joiners and movers on bundles instead of half: 4,100 fewer approvals, 2,500 fewer requests and less waiting, less 175 hours a year to build and keep 100 bundles. On the NIST study's measured wait for roles it comes to about 3,600 hours.
High-risk reviews38 applications reviewed every quarter, 25 people each. About three hours per application by hand: pulling the list, chasing the owner, raising removals and filing the evidence. About 45 minutes as a campaign, most of it the owner deciding.

Every business-side figure is an assumption, set low on purpose. Replace each with your own before taking this to a budget holder. The quickest start is a report on sc_req_item over the last twelve months, grouped by catalog item, with the access items marked.

Sources: Fixify 2026 IT Help Desk Benchmark Report · Enterprise Strategy Group, now Omdia, on the six-day wait for a new hire's access · O'Connor and Loomis, 2010 Economic Analysis of Role-Based Access Control, RTI International for NIST · Ponemon Institute for GuidePoint Security, 2025 · Zluri, a governance vendor, on manual and automated reviews · Serval · HDI · Gartner IT Key Metrics Data.

For the platform owner and the architect

Nothing to host. Nothing leaves your instance.

No vendor tenant, no middleware, no copy of your people or their access anywhere else. Outbound only, from your instance, on credentials you hold. The facts a platform review asks for are below.

QuestionAnswer
Where does it runAs a scoped application on your instance, installed from the ServiceNow Store as one versioned release. No servers, containers or agents. The people who already run your instance run this.
What does it store26 tables of its own, all in its scope, plus six import set staging tables the sync uses. Tables in a certified Store application do not come out of your custom table allocation. Your request, task, user and group records are read, never altered. Whatever your team has customised over the years, there is nothing of ours in it to conflict with.
How does it connectOutbound REST from your instance to your identity system, on credentials held in your instance. No vendor service calls in. Your HR feed can call one lifecycle endpoint on your instance to say who has joined or left.
Where do staff use itEmployee Center: three catalog items (Request access, Access bundles, Remove access) and one portal page, My Access. Nothing new to log in to.
Where do admins use itA workspace that says what is stuck and what is stale, and three wizards: guided setup, application onboarding, approval policy. Changing who approves what needs no developer.
What roles does it addThree application roles, granted in guided setup. Everything else runs under the platform's own access controls.
What about emailYour existing service catalog notifications keep working as they are. Warde sends only a handful of its own, triggered by events on the request and the review, with your branding if you want it. One property hands them to your own notification stack instead.
Does it need AINo. Nothing in the product depends on an AI licence, and it behaves the same on an instance that has never had one.
What does an auditor getA full history of every request, approval, delivery, removal and review decision, insert-only with no update and no delete for anybody, kept seven years by default. User access review evidence packs that freeze the campaign as it was launched and keep their own copy of every person, account and entitlement. Each revoke in them is confirmed back from the engine.
Audit and compliance

The most common IT weakness a public company discloses is somebody's access.

Rights that were never appropriate, and leavers who kept theirs. KPMG counted 238 companies disclosing a material weakness in fiscal 2025. Within the IT general controls theme, that is what most of them were about.

An auditor asks whether the list under review was complete.

A spreadsheet cannot answer that. Months later, nobody can show which query produced the export, on what date, or that nothing was dropped between the export and the sign-off. Warde's evidence pack can.

Frozen at launch

The pack reports the campaign as it was launched

A campaign snapshots its scope, its reviewers and its rules the moment it launches, and the export reads the snapshot. An edit made afterwards cannot change the record of what was reviewed.

Rows that survive

A rename does not rewrite the evidence

Every line keeps its own copy of the person, the account, the entitlement, how the access was granted and when. An audit row that resolves to "(deleted)" is not audit evidence.

Closed loop

Taken away, and confirmed back

A revoke records the engine that ran it, the engine's own reference, and the stamp confirming it was carried out. Items the source system stopped including partway through the campaign stay in the pack, marked as withdrawn.

The four controls an auditor tests, and where Warde stands
ControlWhat is asked forWhere Warde stands
ProvisioningWas it authorised before it was granted, by somebody with the standing to authorise itThe chain resolves to named approvers before the request is raised, and every decision is a row carrying a person, a time and the policy that put them there
DeprovisioningWas a leaver's access removed inside the window, and can you show that it wentRemovals and review revocations run the same approval and fulfilment path and are confirmed back rather than assumed. Warde does not spot the leaver: your joiner and leaver feed calls the endpoint. Access past its expiry date is removed by a nightly pass, with warnings to the holder and their manager first
Periodic reviewDid somebody independent confirm the access is still appropriate, on a cadence, and can you prove what was in front of themScheduled user access review campaigns, reviewer strategies that fall through to the holder's manager and then to a mandatory backstop, delegation, and the evidence pack
Separation of dutiesAre conflicting combinations stopped on the way in, or found and clearedVerdicts on the form and again on the line before approval, enforced per entitlement as block, warn or off. The ruleset stays in your engine, so an application with no engine behind it gets no check

Warde is not a GRC platform. It keeps no control library and maps nothing to frameworks. What it produces is the evidence for one family of controls, in a shape an auditor can test.

SOX 404

US filers

Authorised provisioning, timely removal, periodic review, separation of duties.

PCI DSS 4.0

Card data

Requirement 7.2.4: review accounts and access at least once every six months.

ISO 27001

Annex A 5.18

Access rights reviewed at planned intervals by the owner, and documented.

APRA CPS 234

Australia

Access control and third-party assessment, sized to the threat.

DORA and NIS2

Europe

ICT risk management, including the review of access rights.

Quarterly reviews satisfy every one of them, and quarterly is what a filer needs anyway.

Where it stands

Built and running, waiting on Store certification.

What is built and what is not are both named, so you can decide whether the gaps matter to you.

Working today

On a developer instance now, covered by 56 automated tests
  • ✓Request access, with the duplicates, conflicts, expiry rules and approval chain settled on the form
  • ✓Access bundles, asked for whole, given back whole, and curated by the people who own the access
  • ✓Remove access, down the same path as a grant
  • ✓Approval policies, as many stages as the access deserves, written in a wizard
  • ✓Microsoft Entra ID Governance connector, for groups, app roles, licences, directory roles and access packages
  • ✓Fulfilment that retries, promises a date, and raises a task when it cannot finish
  • ✓User access reviews, from the campaign to the evidence pack, with delegation in between
  • ✓My Access, what you hold, what your team holds, and what is waiting on you
  • ✓Administration, three wizards and a workspace that says what is stuck and what is stale
  • ✓A regular read of your identity system, so the record of what people hold stays current
  • ✓Joiner, mover and leaver provisioning, as an endpoint your HR system calls. Spotting the joiner stays with you
  • ✓Birthright bundles, granted by policy with no approval when your joiner feed names them
  • ✓Expiry, with access past its date removed by a nightly pass that warns the holder and their manager first

Coming soon

Named so you can decide whether it matters
  • ○Birthright by rule. Warde choosing the bundle from department, location or job, rather than your feed naming it
  • ○Account creation. Somebody with no account on the target system yet is reported, not created
  • ○Reporting on orphan accounts, dormant access, and who has what
  • ○An MCP server, so an assistant can raise a request, read what somebody holds or take a review decision, under the same permissions the person has
  • ○Saviynt connector, built with the first customer who needs it
Missing a feature

If what you need is on neither list, ask for it.

Releases are short and the people who ask set the order, so a feature goes from a call to a release without waiting on anybody else's roadmap. Bring the request your current tool will not handle, or the report your auditor keeps asking for. If it belongs in an access request product, it gets built.

Tell us what is missing →

Not everything will. Some of what you need is your identity engine's job, and you will hear that on the call rather than after the purchase order.

Talk to us

Bring the access request you hate most.

Forty-five minutes on a live instance, with no slides. We will show you what replaces it, what it costs, and what the product still cannot do.

Email
[email protected]Or book a walkthrough by email
Availability
ServiceNow StoreSold and updated through the Store, as one versioned release
Launch offer
Up to 30 percent offFirst three customers, in return for a case study, a Store review and a reference call