HEM · ID
HEM ID
Identity and access management at enterprise scale
Access rights are the most concrete form a technical measure takes. HEM ID makes it manageable who reaches which system, on what grounds and for how long.
- ISO 27001
- SOC 2
- NIST
As access grows, control disappears
Leavers keep their accounts
The exit is closed in HR, but the accounts in each system wait to be shut down one by one. That gap is among the most common audit findings.
Permissions accumulate over time
An employee who changes role keeps the old permissions. Since nobody removes them, everyone ends up with more access than they need.
Privileged accounts get shared
Once an administrator password circulates in a team, it is impossible to say who performed an action. This is where traceability breaks first.
From identity to authorisation to record
Eight modules, built to satisfy ISO 27001 access control requirements.
Single sign-on (SSO)
One identity across corporate applications through SAML and OIDC. No separate password per application.
Multi-factor authentication (MFA)
A second factor with TOTP and WebAuthn support. Policy decides where it is mandatory.
Role and attribute based authorisation
Permissions by role with RBAC and by context (unit, location, device) with ABAC. The two can be combined.
Privileged access management
Administrator accounts are kept in a vault and sessions are recorded; password sharing disappears.
Directory integration
User synchronisation with LDAP and Active Directory. Your existing directory remains the source.
Just-in-time access
Temporary permission is granted and withdrawn automatically when it expires. Permanent permission creep stops.
User lifecycle
Accounts are opened, updated and closed automatically on joining, role change and leaving events.
Detailed audit log
Sign-in attempts, permission changes and privileged sessions are stored with timestamps.
Rollout steps
Inventory
Applications, accounts and current permissions are mapped.
Role design
Roles and policies are modelled on job definitions.
Connection
Directory and applications are connected through SSO.
Review
Periodic access review is put on the calendar.
Connects to your existing systems
- Corporate applications supporting SAML 2.0 and OpenID Connect
- LDAP and Active Directory synchronisation
- Joiner and leaver events triggered from the HR system
- Log records forwarded to your central monitoring stack
Standards it serves
Which obligation it covers
- ISO 27001
- SOC 2
- NIST
Related services
- ISO 27001 implementation and audit readiness
- System integration and APIs
- Access management and authorisation
- Log collection, monitoring and retention
Frequently asked questions
Other products
See where you stand in 20 minutes
The free initial assessment maps your current state and tells you which step should come first. You are not committed to anything afterwards.
Look at it yourself first
A twenty-five question KVKK compliance test with per-area scores and a priority recommendation. No sign-up.
Start the compliance testLet's look together
We discuss your current state and work out which step comes first and how long it takes.
Request a conversation
