None of the following is available today, and no launch dates are promised. They are
published because a roadmap you can read is more useful than one you cannot — and because
which of them ships first is a decision our engagements will make, not our marketing.
RoleIQ
Authorization Intelligence
Roadmap Role mining, RBAC and ABAC recommendations, separation-of-duties analysis and access optimization.
Every large organization has a role model that drifted. RoleIQ is intended to mine what access people actually hold and use, propose a role structure that fits it, and surface the toxic combinations that separation-of-duties policy already forbids on paper.
- Role mining from effective entitlements rather than intended design
- RBAC and ABAC model recommendations
- Separation-of-duties conflict analysis
- Access optimization with least-privilege targets
For IAM teamsERP teamsEnterprise architects
Tell us this is the one you need → GovernanceHub
Architecture Governance
Roadmap Architecture Review Board workflow, standards, exception management and decision tracking.
Architecture governance usually lives in a wiki, a spreadsheet and somebody’s memory. GovernanceHub is intended to make it an operating system: standards that are queryable, exceptions with owners and expiry dates, and decisions with a record of why they were made.
- ARB submission and review workflow
- Architecture standards as living, queryable records
- Exception management with owners and expiry
- Risk acceptance and decision tracking
For Enterprise architecturePlatform teamsCTO office
Tell us this is the one you need → ComplianceIQ
Compliance Automation
Roadmap Control mapping, evidence collection, audit readiness, risk register and policy management.
Compliance evidence goes stale the moment it is collected. ComplianceIQ is intended to make evidence a continuous output of the environment rather than a quarterly project, mapping one fact set to whichever framework is asking.
- Multi-framework control mapping from a single fact set
- Continuous evidence collection tied to live configuration
- Audit readiness tracked over time, not sampled at audit
- Risk register and policy management
For ComplianceInternal auditMid-market security
Tell us this is the one you need → CostLens
FinOps & Cloud Economics
Roadmap Cloud cost visibility, optimization recommendations, forecasting and budget tracking.
Most cost tools attribute spend to resources. The more useful question is which workload — and which identity — caused it. CostLens is intended to give cost an owner rather than a line item.
- Cost visibility across accounts and subscriptions
- Optimization and right-sizing recommendations
- Forecasting with budget guardrails
- Per-workload and per-team attribution
For FinOpsPlatform engineeringFinance
Tell us this is the one you need → HealthCloud Compass
Healthcare Cloud Governance
Roadmap HIPAA control tracking, cloud governance, data flow mapping and audit readiness for healthcare estates.
Healthcare runs on integrations, and each one moves regulated data somewhere. HealthCloud Compass is intended to make those flows explicit and tie them to the HIPAA controls that govern them — built on the sector where our own engagement history is deepest.
- HIPAA control tracking against live configuration
- Data flow mapping across clinical and analytics estates
- Cloud governance guardrails for regulated workloads
- Audit readiness for HIPAA and HITRUST
For Healthcare securityComplianceClinical platform teams
Tell us this is the one you need → VendorTrust
Third-Party Risk
Roadmap Security questionnaires, vendor assessments, third-party risk and a hosted trust center.
Every organization is now on both sides of the vendor questionnaire — sending them and answering them. VendorTrust is intended to serve both directions from one record, so the answers you publish and the answers you demand stay consistent.
- Questionnaire issuance and response tracking
- Vendor assessment with reassessment cadence
- Third-party risk register
- Hosted trust center for inbound diligence
For SecurityProcurementGRC
Tell us this is the one you need →