Identity governance, read-only

Know what's broken in your identity platform, and what breaks next.

Sifr watches the platform that governs your identities: syncs, provisioning, appliances, reviews and configuration. It never changes a thing, and every finding is reviewed and signed by a named expert.

Book a 20-minute fit callWhat the Health Check involves

Now: SailPoint Identity Security CloudRunning IdentityIQ, Saviynt, Entra or Okta? Tell us

Health Check report

Sample · fictional tenant

Cedar Hollow HealthRead 26 Sep 2026 · 8 findings, 6 root causes

2 need you now

  1. P1 · urgent

    Clinical Network cluster has no healthy appliance

    All sources served by this cluster, including Cedar Clinical EHR, cannot sync or provision access until an appliance is restored.

  2. P1 · urgent

    Workday authoritative source outage

    Identity data from Workday will not update, so new hires, terminations and attribute changes will not be reflected until the connection is restored.

2 could break next

  1. P2 · this week

    Missing delete thresholds on authoritative sources

    A bad or incomplete sync from either source could delete large numbers of accounts unchecked, causing mass loss of access.

  2. P3 · can wait

    DMZ Relay cluster lacks failover

    If this single appliance fails, all sources depending on the DMZ Relay cluster will lose connectivity with no automatic failover.

Signed by the reviewer

Check it

They watch your identities. We watch the platform that governs them.

Posture tools

Risky permissions, dormant accounts, missing MFA. Automated, scored, on a dashboard.

Sifr

Failed syncs, stuck provisioning, appliances down, reviews that won't finish, configuration drift. Reviewed and signed by an expert, in a short report.

How a report is made

Eight findings. Six causes. Two that need you.

  1. 01 · Read

    Read, never write

    The engine reads 13 kinds of signal through a client that can only read, and deterministic rules decide what's wrong and how serious it is. No AI sets a severity.

  2. 02 · Explain

    Group by cause

    An AI model groups findings that share a cause and explains each one in plain English. It never sees a name or an email, and every object it mentions must exist in your data.

  3. 03 · Sign

    An expert signs

    The expert checks each cause against the evidence, confirms or changes it, and signs. Nothing is signed automatically.

The Health Check

A signed report within five business days. About 2½ hours of your team's time.

  1. Day 0

    Kickoff call

    Scope, and who creates the access.

    You: 30 min

  2. Day 1

    Read-only access

    Your admin creates a service identity with read scopes, from our checklist.

    You: about 1 hour

  3. Days 1–4

    We read twice, then review

    Two readings, three days apart, catch drift. The expert reviews and signs.

    You: nothing

  4. By day 5

    Report and walkthrough

    The signed report, and a call with the expert who signed it.

    You: 45 min

The clock starts once access works; your own approvals may add days. Revoke the token when we're done, or keep it for the weekly letter.

Verify

Don't trust us. Check.

Every report carries the expert's signature, and your browser can check it with nothing uploaded. Change one number and the signature stops fitting. Try it.

The sample is signed with a throwaway key made for it, not a real reviewer's key.

Signed. To check it yourself, run sifr report verify on the bundle.

Report R-87d236608704 · key K-4dc60f25abd559c7

Signed by
Amro Alemam
The line
“Review Q3 2026 Manager Certification is overdue, 131 of 212 complete”

Price

Start with one Health Check.

Health Check

$5,000 fixed, one tenant up to 50,000 identities

  • The signed report: every root cause with its severity, impact and next step
  • A walkthrough with the expert who signed it
  • No changes to your platform, ever

Design partners: $2,500. Three slots, for teams willing to tell us what to fix.

Request a design-partner slotor book a fit call

Then, every week

$3,000 a month, up to 10,000 identities

The weekly letter's monthly price by tenant size
Up to 25,000 identities$4,500 a month
Up to 50,000 identities$6,500 a month
LargerQuoted
  • A signed letter every week: what broke, and what could break next
  • A full signed Health Check every month
  • Your Health Check fee counts towards the first three months

Questions buyers ask

Before you book.

Do you change anything in our platform?

No. Every request goes through one client that can only read, and anything else is refused before it leaves our process. We hand your team the exact change to make.

What access do you need?

A dedicated service identity with a token limited to read scopes. The Health Check page lists every scope and what it's for. Revoke it whenever you like.

Where does our data go?

The engine runs as a container inside your network, or hosted by us. Before any AI model sees anything, names and email addresses are removed; it gets configuration, counts and error text.

Which platforms do you support?

SailPoint Identity Security Cloud today. If you run IdentityIQ, Saviynt, Entra ID Governance or Okta, tell us: it decides what we build next.

Who signs the findings?

Amro Alemam reviews every root cause against the evidence and signs it. Nothing is signed automatically, and nothing unsigned reaches you.

How is this different from posture tools?

Posture tools watch identities: risky permissions, dormant accounts, missing MFA. Sifr watches the platform that governs them: whether syncs run, provisioning works, appliances are up, reviews will finish and configuration has drifted.

Read-only. Reviewed. Signed.

Book a 20-minute fit call