281 standing grants. 64 nobody has used in 90 days.
CEDX Access scores every grant for risk, ages every standing privilege, and puts a decision on every review row: keep, revoke, or convert to just-in-time — with an AI recommendation you can overturn.
The riskiest grant in the demo is a break-glass account at 94, used this morning with no ticket claim attached. The root-caused alert names it. That is the point of a risk score.
access.cedxsystems.com — live build
Runs on demo data — Northline is the software's sample tenant, not a customer.
281 standing grants of 37371 of them high risk, scoring ≥55
41% review completion10 open campaigns — the lag is printed
45 JIT sessions active nowtime-bound by design, expiring on screen
What it is
Least privilege, with the arithmetic shown.
373 grants, each with a risk and a last-used
The grant table carries principal, resource, role, level, type and risk: the break-glass account on the ledger at 94, a service account approving finance at 92, a contractor's deploy grant at 91. Unused for 90 days is a counted state — 64 grants.
Standing, JIT, expired, revoked as chips
Human, service and agent principals distinct
Last used to the day on every row
access — screen-3
Reviews that end in a decision
The review board is 95 items with a decision per row: revoke the break-glass, keep the app-admin, convert the vault grant to just-in-time. The AI recommendation sits next to the decision — deny 97% — so agreement and disagreement are both recorded.
Top signal per row: unused ≥90d, critical resource
access — screen-2
Requests with risk before approval
43 open requests, 9 of them high risk. Each shows requester, resource, role, duration and the AI recommendation — deny the standing payroll admin at 95, convert the deploy grant to 24 hours, approve the scoped one at 74% confidence.
Duration on the ask: standing, 24 hours, 7 days
Approver named per request
Overturn rate tracked: 37% over 30 days
access — screen-4
Product tour
Four screens, captured from the running build.
Not a mockup and not a concept deck. This is what opens at /app/access.
access.cedxsystems.com
01 — Overview
The privilege estate, scored
281 standing grants, 43 requests awaiting decision, 9 high-risk, an access-health ring at 49. The root-caused alerts are the week's arguments: a contractor keeping deploy-operator unused since May, an SoD conflict where one person holds approver and deployer.
Grants issued versus revoked, daily
Standing by level: 63 critical, 56 high
Grant status mix: 281 standing, 58 JIT, 18 revoked
02 — Reviews
Attestation with teeth
10 campaigns at 41% completion, 29 items pending attest. The board sorts by risk, and every decision records what the agent thought — the 37% overturn rate is a feature: humans disagree measurably.
Review board 95 · campaigns 12 · request risk 88
Min-risk chips: all, ≥40, ≥55, ≥70
Simulator and scoring model as tabs
03 — Grants
The standing-privilege ledger
Filter to standing, sort by risk, and the ledger reads itself: break-glass at 94, service accounts at 92 and 80, contractor roles at 91. 13 grants belong to non-human agent principals, and they are labelled.
373 grants estate-wide
Level per grant: 63 critical standing
CSV export of the filtered ledger
04 — Requests
Ask for it the way you will lose it
A request names its duration up front — standing, 24 hours, 30 days — and the AI recommendation prices the ask. Convert-to-JIT at 83% confidence is the most common middle path in the demo queue.
80 requests in the window, 43 undecided
Average open risk 39 across the queue
Open, pending, approved, denied, expired tabs
Who runs it
Three roles keep privilege honest.
Roles, not references. We have no named customers yet, so nobody in these photographs is quoted, credited or claimed as one.
Privileged-access admin
Owns the break-glass accounts and the JIT sessions — a 94-risk grant used without a ticket is their first conversation of the day.
JIT sessions · 45
Review campaign owner
Runs the quarterly recerts: 95 items, decisions per row, and the 29 pending attests chased before the campaign closes.
review completion · 41%
Approving manager
Decides the 43 open requests with the risk score and the AI recommendation on the same row — and their overturns are counted, not judged.
overturn rate · 37%
The shape of it
What the demo estate actually looks like.
Every figure below is legible in the captures above. Nothing here is a projection of your estate — it is the state of the demo data.
Finding this out on the third call is worse for you than reading it here, and worse for us.
Access is not generally available. What opens today is the live build on demo data — Northline is the software's sample tenant, not a customer.
We have no named customers to show you, so this page shows none. The principals in the captures are demo personas inside the sample tenant.
Review completion in the demo is 41%, and the product prints it. We are not claiming the tool completes reviews for you — it makes the lag visible.
The AI recommendation is a recommendation: it is overturned 37% of the time in the demo, and the overturn rate is on the screen. Automated revocation is not something this build claims.
No audit or compliance certification has been issued for Access. What we can evidence about hosting, encryption and production access is on the security page.
Yes. Every screenshot is a capture of the running build and you can open the same build at /app/access. It runs on demo data — Northline is the sample tenant.
What makes a grant high risk?
The scoring model is its own tab, and every row names its top signal — unused for 90 days, critical resource, standing where JIT would do. The break-glass account at 94 is the demo's honest example.
What is convert-to-JIT?
The middle decision between keep and revoke: the grant stops being standing and becomes time-bound — 24 hours, 7 days — issued on request. 58 JIT grants exist in the demo estate, with 45 sessions active right now.
How do the AI recommendations hold up?
They are recorded next to every decision, and the overturn rate is tracked: 37% over 30 days in the demo. A recommendation you can measurably disagree with is more useful than one that hides its mistakes.
Is Access audited or certified?
No certification has been issued. What we can evidence about hosting, encryption, tenant isolation and production access is written up on the security page.
The ledger is scored. Go and look at it.
Live build, demo data, no card. Then ask which of your standing grants would survive a 90-day unused filter.