In development · early pilot phase
SecureFlow
Identity governance and IT self-service for Microsoft 365
SecureFlow brings requests, approvals and evidence around identities together in one portal. For Entra ID, Exchange Online, Teams and SharePoint, optionally with on-premises Active Directory.
Guiding principle: every identity-related action is traceable, approved and executed consistently in all target systems.
Where we stand
SecureFlow is in development and in an early pilot phase. This page describes the planned scope. Not every module is available today, and details may change before general availability. Get in touch if you want to know what can already be used today.
What's in the name?
SECURE stands for the topics SecureFlow covers. Flow stands for workflows and approvals.
- S
- Self-Service
- E
- Entitlements
- C
- Compliance
- U
- User Lifecycle
- R
- Reviews
- E
- Evidence
Benefits
Traceable
Every identity-related action is recorded in a chained audit log (hash chain). Entries are only ever appended, never changed or deleted.
Approved
Requests go through defined approvals, including delegation. Who approved what and when can be shown at any time.
Consistent
A change is executed the same way in all connected target systems, instead of by hand in several admin consoles.
Relieves IT
Employees submit requests via self-service. IT stays in control and is relieved of routine work.
Evidence for audits
An ISO 27001 evidence package and a WORM export support audits and reviews.
Privacy built in
GDPR retention periods are part of the core. Customer data stays in the customer's instance.
The core: always on
These features are part of every instance.
- Sign-in via Entra SSO, plus a local break-glass account with TOTP
- Roles and permissions in the portal
- Audit hash chain and WORM export
- ISO 27001 evidence package
- Approvals with delegation and an inbox
- People directory and self-service
- GDPR retention periods and notifications
Modules
Additional modules can be enabled per instance. A module switch applies throughout: to the user interface, APIs, background jobs and permissions.
Guests
Inventory, invitation and reviews of guest accounts.
Teams and SharePoint governance
Owner rules, reviews and archiving.
Sharing inventory
Find shared links and revoke them selectively.
Access packages and access reviews
Time-limited memberships, Conditional Access automation and recertification.
Licences and reports
Costs, redundancies and a report suite.
HR processes (JML)
Joiners, movers, leavers and absences, with roles and templates.
Hybrid AD
Write path into on-premises Active Directory via a connector that only connects outbound.
Software catalogue
Catalogue, contracts and usage queries.
Desk booking
Floor plan, booking and mailbox provisioning.
Backup integration
Restore evidence via a backup provider.
HR data from your source
Joiners, movers and leavers arrive in the portal as a uniform HR case: with person, effective date, manager, company, cost centre, role and deputy. The source is interchangeable.
- Entry directly in the portal
- SharePoint list with configurable column mapping
- Dynamics 365 / Dataverse with configurable field mapping
- CSV or file import
Further adapters, for example for HR SaaS systems, are planned.
Two ways to run it, one software
One image, one Helm chart, no customer-specific special versions. The variants differ only by configuration.
SaaS
- A dedicated instance per customer, operated by us
- Sign-in via a multi-tenant app with admin consent in your tenant
- Your own host name under secureflow-it.de
- We roll out updates per instance
- On-premises AD via a connector on your side that only connects outbound
Self-hosted
- In your Kubernetes (Helm) or on a container host (Docker Compose)
- Images are mirrored into your own registry
- Your own app registrations in your tenant
- Your own host name in your domain
- You decide when to adopt new releases
Clear separation and privacy
One instance per customer
Every customer gets a dedicated instance: own database, own audit chain, own keys, own secrets and own host name.
Mail from your tenant
Notifications are sent from a service mailbox in your own tenant, with your domain. The send permission is limited to exactly this mailbox.
Your data stays with you
Customer data stays in the customer's instance. As the provider we only see operational data. For SaaS we sign a data processing agreement with every customer.
Supply chain
Signed images, an SBOM and a vulnerability scan per release are planned.
Demo or pilot phase?
Want to get to know SecureFlow or bring in your requirements early? Write to us. We are happy to show you the current state.
Request a demo by email