Skip to main content

Governance Control around every lifecycle change.

Tenriva keeps the request, the approvals, the decisions and the record attached to one another, so an access change can be explained long after the people involved have moved on.

Every capability described on this page is available today.

A door-access reader showing a red light on a concrete wall, with a closed door at the end of the corridor.

What is governed

Three things, kept together.

Access, the decisions made with it, and the record of both. Separately they are administration; attached to one another they are governance.

  1. 01

    Access

    People arrive as themselves.

    Tenriva is designed to work with Microsoft Entra ID and Microsoft 365 through Microsoft Graph. People sign in with their existing Microsoft work account, so there is no second directory to keep in step and no separate set of credentials to govern.

    The specific Microsoft Graph permissions are not published here yet. Ask, and we will go through them with you.

  2. 02

    Decisions

    Someone accountable says yes.

    Every request goes to the employee’s manager, then to IT for review, with an optional second IT sign-off for teams that want one. The route is the same every time, so a change that skipped a step is visible as an exception rather than lost in a mailbox.

  3. 03

    Records

    The decision outlives the conversation.

    Requests, approvals and actions are recorded in an audit history, and you can export the entries you are viewing as CSV or PDF. The record is a by-product of doing the work rather than something assembled afterwards from memory.

Records

What is in front of you is what exports.

The audit history is the working record, not a report generated for an auditor. The entries you are looking at are the entries that leave as CSV or PDF.

Tenriva’s audit log, each entry giving the time it happened and the person or system that acted.

Execution

Approved changes reach Microsoft 365.

An approved request carries into Microsoft 365 rather than being retyped somewhere else, and IT stays in control of when it runs. A step that fails can be retried or rolled back, so a half-finished change is something you can see and act on rather than something you discover later.

  • Microsoft 365 changes for joiners and movers

    Create accounts and apply licences, groups and Teams from the role profile when IT runs an approved request.

  • Microsoft 365 leaver actions

    Block sign-in, revoke sessions and remove licences and group access when IT runs an approved leaver request.

  • Retry and roll back

    Retry steps that fail while a request is carried out, and skip steps or roll back changes for joiners and movers.

The approval trail and the change itself stay attached to the same request, so the record shows both the decision and what it did.

Security and compliance

Where we actually are.

Tenriva is an early-stage product and does not currently claim ISO 27001 or SOC 2 certification.

We would rather say that plainly than imply an assurance position we have not earned. If you need one for procurement, tell us early. It is a better conversation before a pilot than during one.

What we will answer
Architecture, subprocessors, retention, and the permissions Tenriva asks for. Ask before a pilot rather than during procurement.
What we will not do
Claim a certification, an uptime figure or a framework alignment that has not been verified. That rule applies to this website as much as to a questionnaire.

How we work

Two rules we work by.

  1. Automate repetition, not judgement.

    The manager and IT approve every request before anything changes. Tenriva is built to take on the repeated steps, not the decisions, and each approval recorded in the audit history shows who made it.

  2. Say what is not finished.

    Work in progress is labelled as in development from the day it starts, rather than announced when it ships. The same goes for assurance: we do not claim a certification or an uptime figure we have not earned.

Availability

Everything the platform contains.

Every capability by name, grouped the way the Platform page describes them.

16

published capabilities, all available today.

  • Requests

    5
    • Joiner requests
    • Mover requests
    • Leaver requests
    • Role profiles
    • HR system connections
  • Approvals and the work queue

    2
    • Approvals
    • Work queue
  • Records and visibility

    4
    • Audit history
    • Licence insights
    • Device inventory
    • Analytics
  • Microsoft 365

    5
    • Sign-in with Microsoft Entra ID
    • Microsoft 365 changes for joiners and movers
    • Microsoft 365 leaver actions
    • Retry and roll back
    • Microsoft 365 service health

Next step

Ask us the difficult questions early.

Architecture, subprocessors, retention, permissions and assurance are better discussed before they become procurement surprises. Book a walkthrough and bring them, or start the trial and look for yourself.