Corinio
Access Intelligence
Book a demo
Access intelligence · built in Europe

Who can reach what — and can you prove it?

Corinio maps every access path across your identity and data platforms — direct, inherited, nested, cross-system — and keeps the evidence behind each one. So why does she have this? takes seconds instead of a week of screenshots.

Read-only by design Nothing revoked without a human EU data residency
One access path, end to end — swipe → Entra Azure RBAC Inherited
IDENTITY GROUP / ROLE ACCESS RESOURCE Freja Pedersen user · active Project-Nordwind group · direct member Data-Platform-Ops group · nested INHERITED Contributor Azure subscription 1 AZURE prod-datalake storage · write
Four hops, three systems. Nobody granted Freja access to production data — she was added to a project group two levels away from it. Illustrative example.
The distinction

Your identity system knows what it granted

It cannot tell you what people can actually reach. That is a different job, and it is the one Corinio does — across the systems no single identity platform administers.

Managing access

Request, approve, provision, review

Entra ID Governance, Omada, SailPoint. Strong, mature, and the right tool for handing out and taking back rights.

  • Sees what it administers itself
  • Access granted directly in a platform stays invisible to it
  • Rights that predate it are outside its record
Explaining access

Read, correlate, evidence, document

Corinio reads what the systems actually say and resolves it into effective access — the rights a person genuinely holds today, whatever route they took.

  • Identities joined on the platforms' own object ids, not on names
  • Inherited and nested paths resolved and walkable
  • Every finding opens onto the data behind it

We are not a replacement for your IGA. We are the layer that answers the question it cannot ask itself: does reality match what we think we granted?

What you get out of it

Every number opens into its evidence

Nothing Corinio reports is a dead end. A count leads to the objects it counted, each object to the finding behind it, and the finding to a recommended action. Four of the answers a single run returns:

01 · Posture

Where the tenant stands, in figures you can open

A score you can defend, the findings that move it, and the change since the previous run. Every tile is a door into the records behind it — not a summary you have to take on trust.

Posture · one run
21% SCORE Action required Secure Score, from the run
27 ▲ 5
High-risk findings
vs. previous run
19 ▼ 3
Groups without an owner
never recertified
4 —
Standing admin accounts
permanent, not just-in-time

Illustrative figures — a real run returns your own.

02 · Effective access

One person, every platform, one picture

Identities are joined on the platforms' own object ids, not on matching names. So a single person resolves into the rights they genuinely hold — in the identity platform, in the cloud, and in the data platform at once.

Effective access · one identity — swipe →
One identity joined on object id IDENTITY PLATFORM Directory role permanent · tenant-wide CLOUD Subscription role inherited via a group Storage write DATA PLATFORM Catalog grant via workspace group Table personal data

Three systems, one person. No single platform sees this picture.

03 · Findings

A finding that carries its own proof

Each one names the object, the path that produced it and why it matters — then a recommended action, raised as a ticket for approval in your own workflow. Corinio proposes; a person decides.

Finding · evidence
Finding Permanent privileged role, directly assigned High
Object An administrator account
directory role · scope: tenant root
Path identity → directory role → tenant root
Why The role is active around the clock, including when the account is not administering anything. Compromise the account and the access is immediate.
Action Move to eligible, activation on demand — raised as a ticket, approved by a person

Structure of a real finding; the object is anonymised here.

04 · Evidence for the auditor

Articles mapped to what your data can prove

NIS2, DORA, ISO 27001, GDPR and SOC 2 broken down to what is measurable in access data. Each article points at the controls behind it — and a control with no data says so, rather than passing.

Article · what backs it
NIS2 · Art. 21(2)(j)

Multi-factor or continuous authentication, especially for privileged accounts.

Privileged accounts hold MFA evidence Gap
Conditional Access baseline exists Met
Phishing-resistant methods registered Not in this run

No claim without evidence — and no percentage, because a score forces the unseen to count as something.

Why teams trust it

Built to be checked, not admired

Access data decides who reaches your most sensitive systems. A tool that is confidently wrong is worse than no tool, so Corinio is built to survive someone digging.

Unknown is never green

An area we have not assessed looks different from an area that came back clean. A missing metric never becomes a zero, and there is no compliance percentage anywhere — because a score forces the unseen to count as something.

Provenance on every figure

Each number belongs to a named run, a named source and a timestamp. Where two sources disagree, Corinio shows the disagreement instead of quietly picking one.

A person decides, always

Detect → explain → recommend → propose → approve → execute → verify. Corinio never revokes access on its own. Human approval is a permanent part of the design, not a first-version limitation.

Evidence, not a verdict

A requirement, not a nice-to-have

NIS2 has been Danish law since 1 July 2025 and DORA has applied since 17 January 2025. Both put access control and strong authentication on the board's desk — and the liability with management.

NIS2DORAISO 27001GDPRSOC 2

Corinio does not make you compliant. It gives you the access-layer evidence the requirements assume you already have — computed from your data, not ticked off in a spreadsheet.

Your access map stays in Europe

A complete picture of who can reach what is a map of how to move through your organisation. Built and hosted in Europe, for organisations that must answer where their data sits.

Read-only by default

Corinio observes. Any change to access leaves through your own ticketing and approval process, never from inside the dashboard.

Platforms

Start where your access actually lives

Microsoft identity and Azure first, because that is where most European organisations keep the keys — then the data platform where the sensitive tables are.

Microsoft Entra ID Azure RBAC Databricks

Modelled on the same access model, available as the need arises:

Power BI Azure DevOps SharePoint Confluence SAP BW/4HANA e-conomic

Every connector is built to one access model — identity → role → scope → resource — so adding a system is a connector, not a re-architecture. If the platform that matters to you is not on this list, that is a conversation, not a roadmap item.

Start with one assessment

See your own access map before you decide anything

A first assessment runs read-only against your tenant and comes back with:

01A full inventory of identities, groups, roles, service principals and the resources they reach
02Every access path mapped end to end, including the inherited ones no review shows you
03Prioritised findings, each with its evidence and a recommended action
04A baseline, so the next run can tell you what changed