Skip to content
HEM Bilişim
All products

HEM ID

Identity and access management at enterprise scale

Access rights are the most concrete form a technical measure takes. HEM ID makes it manageable who reaches which system, on what grounds and for how long.

  • ISO 27001
  • SOC 2
  • NIST
The problem we solve

As access grows, control disappears

01

Leavers keep their accounts

The exit is closed in HR, but the accounts in each system wait to be shut down one by one. That gap is among the most common audit findings.

02

Permissions accumulate over time

An employee who changes role keeps the old permissions. Since nobody removes them, everyone ends up with more access than they need.

03

Privileged accounts get shared

Once an administrator password circulates in a team, it is impossible to say who performed an action. This is where traceability breaks first.

Capabilities

From identity to authorisation to record

Eight modules, built to satisfy ISO 27001 access control requirements.

Single sign-on (SSO)

One identity across corporate applications through SAML and OIDC. No separate password per application.

Multi-factor authentication (MFA)

A second factor with TOTP and WebAuthn support. Policy decides where it is mandatory.

Role and attribute based authorisation

Permissions by role with RBAC and by context (unit, location, device) with ABAC. The two can be combined.

Privileged access management

Administrator accounts are kept in a vault and sessions are recorded; password sharing disappears.

Directory integration

User synchronisation with LDAP and Active Directory. Your existing directory remains the source.

Just-in-time access

Temporary permission is granted and withdrawn automatically when it expires. Permanent permission creep stops.

User lifecycle

Accounts are opened, updated and closed automatically on joining, role change and leaving events.

Detailed audit log

Sign-in attempts, permission changes and privileged sessions are stored with timestamps.

How it works

Rollout steps

1

Inventory

Applications, accounts and current permissions are mapped.

2

Role design

Roles and policies are modelled on job definitions.

3

Connection

Directory and applications are connected through SSO.

4

Review

Periodic access review is put on the calendar.

Integrations

Connects to your existing systems

  • Corporate applications supporting SAML 2.0 and OpenID Connect
  • LDAP and Active Directory synchronisation
  • Joiner and leaver events triggered from the HR system
  • Log records forwarded to your central monitoring stack
FAQ

Frequently asked questions

See where you stand in 20 minutes

The free initial assessment maps your current state and tells you which step should come first. You are not committed to anything afterwards.

Look at it yourself first

A twenty-five question KVKK compliance test with per-area scores and a priority recommendation. No sign-up.

Start the compliance test

Let's look together

We discuss your current state and work out which step comes first and how long it takes.

Request a conversation