Finds the access that outlived the job
Joining works because someone is waiting for a laptop and complains. Leaving fails quietly: the person has gone, nobody is inconvenienced by their still-active account, and it surfaces in an access review a year later or in an incident.
The middle case is worse. Someone changes role and gains the new team's access without losing the old team's, and after three internal moves one person can approve a purchase order, raise the invoice and release the payment. That is the textbook segregation-of-duties failure, and an organisation doing nothing wrong builds it one promotion at a time.
This agent reconciles the employment record against what people can actually reach. It reports access that outlived a leaver, access a mover kept from a previous role, joiners still waiting on something their role needs, and the combinations that let one person complete a transaction end to end. It also finds what left with someone — the process only they knew, the account only they could access.
It revokes nothing. Removing someone's access is an action with employment and operational consequences, and it belongs to a person who can see the context this agent cannot.
The findings are already known and already being fixed.
Before it is used, deliberately or by accident.
Including the systems nobody remembered they were on.
Leavers still holding accounts. It fails silently because nobody is inconvenienced by it.
The new team's permissions added, the old team's never removed. Three promotions and one person can run a transaction end to end.
Approve, raise and release held by one person — the finding auditors look for first.
Someone in post for three weeks without something their role requires, which nobody logged.
The process only they ran and the account only they could reach — found while it can still be recovered.
Removing access has employment and operational consequences. It belongs to a person who can see what this cannot.
Why People and hiring in particular. Identity tools track accounts, HR systems track employment, and almost nobody reconciles the two. Every finding lives in that gap — including the person who, after two internal moves, can raise a purchase order, approve it and release the payment.
Runs unattended
Started by you or by an event, and it finishes on its own. Nothing waits for someone to be at a desk.
The same standard every time
The two-hundredth item is held to the bar the first one was. Consistency is the part people cannot sustain.
It cannot act on its own
Employee Lifecycle Agent has no path to sending, spending or committing. That limit is why its output is safe to act on.
This agent runs server-side through the PROMIVO runtime. Each run is logged step by step and every tool call is permission-checked before it executes.
Read-only by design. This agent has no path to sending, spending, publishing or committing anything. Where that limit is the product, removing it would remove the reason to trust the output.
Demo dataIllustrative sample output, abridged.
{
"access": [],
"people": [],
"asAtDate": "2026-09-02"
}{
"escalate": true,
"disclaimer": "A reconciliation of records. No access has been changed, nobody has been assessed, and holding access beyond a role is a process finding rather than an allegation about any person.",
"policyFound": true,
"joinersWaiting": [
"EMP-231 has been in post 23 days without the ticketing access their role requires. Nothing in the record shows it was ever requested."
],
"escalationReason": "A leaver has held production database access for 214 days, and one person can complete a purchase transaction end to end.",
"accumulatedAccess": [
{
"person": "EMP-091",
"system": "Purchase approvals",
"fromRole": "Procurement Officer — a role they left in March. The access came with the role and never went with it."
}
],
"leaversWithAccess": [
{
"person": "EMP-118",
"system": "Production database",
"sensitivity": "high",
"daysSinceLeaving": 214
},
{
"person": "EMP-204",
"system": "Payment gateway",
"sensitivity": "high",
"daysSinceLeaving": 61
}
],
"singlePersonAccess": [
"The payroll bureau portal is reachable by one person, who is a leaver at the end of this month."
],
"unattributedAccess": [
"A service account with production write access, granted 2023, matching no person or role on record."
],
"dangerousCombinations": [
{
"person": "EMP-091",
"systems": [
"Purchase approvals",
"Supplier ledger",
"Payment release"
],
"combination": "Can raise a purchase order, approve it, and release the payment. Three roles' access held by one person after two internal moves."
}
]
}No integrations required.
Everything still open in their name, in one list.
What an auditor would raise, before they raise it.
Where moves left people holding two roles' worth of access.
The segregation findings, found by you first.
$449/month
Billed monthly through your PROMIVO subscription. Cancel at any time.
Runs consume your plan allowance for agent executions and tokens. See plan limits.
No, and it must not. Revoking someone's access mid-project or mid-dispute has consequences this agent cannot see. It produces the list; a person acts on it.
Identity tools track accounts and HR systems track employment. Almost nobody reconciles the two, and every finding lives in the gap between them. That reconciliation is the whole product.
Never. It reports access against roles. Holding access you no longer need is a process failure, not a personal one, and the report says so.
No reviews yet. Reviews open once customers have run this agent.
Tell us what to change and our team will scope a customised version for your business.
Customize this agent