The affordable Identity Governance & Administration (IGA) platform for Google Workspace groups and Okta SSO apps
Evaluator Plan
$20/mo
$200/yr
$120/yr
Connect to Google or Okta to prove the value for your team and expense it later.
- Each weekly sync picks up your new joiners and places them in every group their attributes call for. The access steps of your onboarding checklist complete themselves instead of waiting on tickets.
- Every plan includes the full Core Platform. That means the directory with custom attributes, the policy engine, Google Workspace and Okta group management, exports, the API, and the CLI. The Core Platform card further down this page lists every capability.
- Your Google Workspace or Okta users are synced every Monday. Each sync detects new users (joiners), deactivated users (leavers), and attribute profile data changes (movers). Your policy rules are re-evaluated against the latest directory data and each group's membership is updated to match. Users who qualify are added and users who no longer qualify are removed.
Explorer Plan
Explore the platform features and create policies with sample directory data.
Essentials Plan
$200/mo
$2,000/yr
$1,200/yr
Help your HR, Identity, IT, or TechOps team automate on a tight budget.
Save $400/yr (17%)
$167/mo Effective
Save $1,200/yr (50%)
$2,400 Billed Today
- Most access requests exist because group membership is maintained by hand. You write policy rules once and each business-day sync provisions the access people would otherwise have to request.
- Every plan includes the full Core Platform. That means the directory with custom attributes, the policy engine, Google Workspace and Okta group management, exports, the API, and the CLI. The Core Platform card further down this page lists every capability.
- Your Google Workspace or Okta users are synced every weekday during the 3 hour window of your choice (starting at 6am, 9am, 12pm, or 3pm in your region's timezone). Each sync detects new users (joiners), deactivated users (leavers), and attribute profile data changes (movers). Your policy rules are re-evaluated against the latest directory data and each group's membership is updated to match. Users who qualify are added and users who no longer qualify are removed.
- Reach a person who knows the product. Support requests get a response the same or next business day rather than sitting in a queue.
- Work with the engineers building Provisionr in a shared Slack channel. You ask questions, report issues, and help steer the roadmap without a support desk in between.
Add-On Modules
Coming in Early 2027
Coming in Early 2027
Coming in Early 2027
Coming in Early 2027
Enterprise Plan
$3,000/mo
$30,000/yr
$18,000/yr
The full suite for your organization with single tenant dedicated infrastructure.
Save $6,000/yr (17%)
$2,500/mo Effective
Save $18,000/yr (50%)
$36,000 Up Front
- Run Provisionr inside your operations rather than beside them. Audit and event data streams into your SIEM, hourly syncs keep access current, and point-in-time exports of members and rules back your access reviews.
- Every plan includes the full Core Platform. That means the directory with custom attributes, the policy engine, Google Workspace and Okta group management, exports, the API, and the CLI. The Core Platform card further down this page lists every capability. The Self-Service and Governance modules are included rather than priced as add-ons. As each module ships you get self-service access requests with approval routing, access review campaigns, separation of duties rules, and auditor tooling.
- Your Google Workspace or Okta users are synced every hour. Each sync detects new users (joiners), deactivated users (leavers), and attribute profile data changes (movers). Your policy rules are re-evaluated against the latest directory data and each group's membership is updated to match. Users who qualify are added and users who no longer qualify are removed.
- A contractual Service Level Agreement (SLA) with defined severities, response times, and escalation paths for incidents and support requests. The commitments run during business hours rather than around the clock.
- A named contact who knows your deployment, checks in on your rollout, and carries your feedback straight into the roadmap. Enterprise is founder-led. You are talking to people who can actually change things.
Infrastructure
Included
Limited
Roadmap
Unlimited
Core Platform
Directory
- Provisionr builds its working directory from the users it reads out of your identity provider and connected systems. This is the population every policy and group rule operates on. The directory is the foundation of everything else. The ingestion keeps the users current as your source systems change.
- Access decisions are only as good as the attributes they rest on. Provisionr lets you define custom attributes across multiple dimensions, like team, region, project, and clearance, and use them in both attribute-based and role-based rules. This is what lets a rule express real intent, such as granting a regional channel only to reps in that region instead of maintaining a list by hand.
- You can slice the directory by any combination of attributes to find exactly the population you care about, whether for building a rule, auditing access, or exporting a report. Advanced filters make the directory queryable rather than just a flat list. That matters once you are governing thousands of users across many dimensions.
- Your directory data is yours. Export users and their attributes in the format that fits your workflow, whether a spreadsheet for a stakeholder, JSON for a script, or YAML for configuration. This keeps Provisionr from becoming a silo and supports auditing, reporting, and integration with your own tooling.
- Today Provisionr governs the users that exist in your identity provider. A contractor only appears if they have an IdP account. Many organizations manage contractors outside their HRIS and IdP. That leaves a real governance gap. Provisionr will add the ability to manage these non-HRIS contractors directly so their access is governed on the same footing as employees.
- Similar to contractors, external collaborators on other email domains often need scoped access to specific groups and resources. First-class management of third-party domain users will let you grant and revoke their access through policy rather than by hand.
- An org chart derived from directory attributes lets you see and govern access along reporting and team lines. Teams update themselves as attributes change. A richer dynamic org chart, where teams form and dissolve automatically from policy, lets access follow team structure as it evolves.
- Provisionr reads attributes from your systems today. Writing them back, so that an attribute computed or corrected in Provisionr can update your HRIS, IdP, or other integrations, closes the loop and makes Provisionr a source of truth rather than only a consumer.
Policy and Group Management
- The policy engine is the heart of Provisionr. You write rules with conditions over user attributes and membership follows automatically. A rule reads as intent, such as "everyone in the finance team in the EU region belongs in this group," and Provisionr enforces it on every sync. This is what replaces the hand-maintained membership lists that drift out of date.
- Once a rule is in place, Provisionr adds and removes members to match it across every connected system without anyone filing or approving a request. This is the core value of the product. The access that should follow automatically from who someone is now happens automatically.
- When you want a group brought current immediately instead of waiting for its next scheduled run, you trigger a manual sync. Rate limits protect shared infrastructure; dedicated infrastructure lifts them.
- Every rule, and every individually added user, can carry a justification that explains why the access exists. This turns your group memberships into a self-documenting record. When an auditor or a teammate asks why someone has access, the answer is attached to the grant rather than lost to memory.
- When someone changes roles, revoking their old access the instant the rule stops matching can break work in progress. A grace period holds the old access for a configured window before removing it. The role change is smooth rather than abrupt and the access is still guaranteed to go away.
- Export any group's current members and the policy rules that govern it to CSV, JSON, or YAML. The export is a point-in-time snapshot for audits, access reviews, or handoff to your own tooling.
- Access that is never used is access that should probably not exist. Inactivity removal will revoke entitlements that have gone unused for a defined period. Standing access shrinks automatically.
Core Integrations
- Direct management of Google Cloud Identity groups. These are distinct from Google Workspace groups.
- Provisionr manages Google Workspace group membership today by adding and removing members to match your rules. Shared drives, calendars, and apps in Google are all mediated by group membership. That makes this one of the highest-leverage integrations.
- Provisionr manages Okta group membership today. Since Okta groups often drive downstream application access, governing them with policy propagates correct access across everything Okta gates.
Lifecycle Automation
- A single view that shows the complete onboarding or offboarding status for each person across every group, system, and step. Coordinators get real visibility instead of chasing status across tools. Confirming at a glance that every access has been removed when someone leaves is what makes offboarding auditable.
- Beyond group membership, onboarding often involves a checklist of steps. Full checklist automation coordinates those steps end to end; a more limited variant handles only the access-related portions.
- Just-in-time access grants an entitlement exactly when it is needed and removes it when it is not. Standing access stays minimal. A continuous cadence with grace-period removal approximates the behavior under a polling model. Real-time provisioning delivers true just-in-time access.
- When someone joins, Provisionr automatically places them in every group their attributes call for. Their birthright access is correct from their first scheduled sync. There is no onboarding ticket and no manual list.
- The role change is the most commonly missed lifecycle event because the old access rarely gets cleaned up. Provisionr handles both halves. When someone's role changes, they gain the groups the new role requires and lose the ones the old role justified. The grace period smooths the transition.
- When someone leaves, every group membership driven by their attributes is removed. This closes the lingering-access gap that manual offboarding leaves behind.
- Provisionr keeps your groups correct by syncing them on a weekly, weekday, or continuous schedule that you set. The cadence is the tier difference; every tier runs the same policy engine.
- Access that should end gets removed on schedule rather than lingering. Revocation is not waiting on a manual cleanup pass. The cadence the removal runs at is whatever the underlying sync model supports.
Managed Resources
- You can govern access to Google Cloud folders and projects today by managing the Google groups bound to their IAM policies rather than by Provisionr touching the resources directly. This indirect approach follows Google's own recommended practice of granting IAM roles to groups. The access is governed through the group rules you already write.
- Governing sharing on individual Google documents through policy means sensitive files are shared with exactly the right people and unshared when access should end. Today this is delivered through the Google groups bound to each document. It follows the same indirect approach as Cloud IAM.
- Policy-driven access control for Drive folders and files extends governance from groups down to the documents themselves by managing the Google groups bound to each folder rather than touching files directly.
- Managing membership and access on Workspace shared drives through policy keeps drive access following the same rules as the groups and roles around it.
- A Google mailing list is a Google group with an email address. Provisionr manages its membership directly from policy. The right people stay subscribed to the right lists based on their attributes with no manual list edits.
- You can govern access to Okta-integrated applications today by managing the Okta groups bound to each app rather than by Provisionr touching the app assignments directly. This follows Okta's own recommended practice of granting app access through groups. The assignment is governed by the group rules you already write.
Additional Integrations
- Managing AWS Identity Center group membership from policy lets cloud access follow the same rules as everything else.
- Policy-driven management of GitHub organization and team membership brings source-code access under the same governance as the rest of your stack.
- Provisionr will manage GitLab group membership from policy so engineering access tracks team and project attributes automatically.
- Policy-driven management of Slack user groups. These are often used for mentions and access.
Platform
- A fast, scriptable command-line tool is built for administrators who live in the terminal. The CLI is a primary interface rather than an afterthought.
- A scoped CLI for group managers, who own a subset of groups rather than the whole workspace, lets delegation happen in the terminal too.
- Everything Provisionr does is available through its API. You can integrate it into your own systems and automation.
- Our API and CLI commands are fully documented and can be parsed by AI chats and agents. Run commands locally through the CLI from any AI client on your machine, or create a Service Account in your workspace for async automation or for an AI to poll the API and send changes. This is an evolving area and we do not have anomaly behavior detection yet. Grant least-privilege permissions for AI service accounts and keep them read-only where possible.
- A full web interface for administrators sits alongside the CLI for those who prefer a graphical view of the directory, policies, and activity.
- Sending Provisionr notifications into Slack so the team sees relevant access events where they already work.
- Emitting webhooks when Provisionr events occur lets your systems react to access changes as they happen.
- Connectors for low-code and no-code platforms let non-developers wire Provisionr into their workflows.
- A published Terraform provider lets you manage Provisionr configuration as infrastructure-as-code.
Security
- The number of administrators or teammates who can sign in to your workspace is not capped or metered. Pricing is a flat rate per workspace rather than per seat. You never pay more for adding another person to the console.
- You can authenticate to Provisionr with Google sign-in today for fast and familiar access without managing another password.
- Full single sign-on authenticates your workspace against your own identity provider and is applied at the domain level.
- Administrative control over your organization, its users, and its verified domains. This is the structure SSO and domain-scoped policy rest on.
- Every meaningful action in Provisionr is recorded in an event log that gives you a complete operational history. This is the baseline record for troubleshooting and accountability.
- Pulling the event log through the API lets you ship Provisionr's operational record into your own systems for archival, analytics, or alerting. Progressive rate limits protect shared polling; dedicated infrastructure lifts them.
Access Requests & Approvals Module
- Letting end users request access themselves, routed for approval and then provisioned automatically, turns exceptional access into a governed workflow rather than a Slack message to IT.
- An access request can route through more than one approver before it is granted. A manager signs off first and the group owner confirms after. Each stage is recorded so the full approval chain lands in the audit trail.
- A web interface for group managers to review and adjust the groups they own.
- A web interface for the people who manage a group's policy ruleset. They review and adjust the rules for the groups they own without holding workspace-wide admin rights.
- An end-user web interface lets employees request access and see what they have.
- A scoped interface for external IT teams or managed service providers who administer access on a client's behalf.
- Letting users request access through the Slack app as an alternative to the web interface.
Audit & Governance Module
- Access intelligence surfaces who has access to what, where risk concentrates, and what looks anomalous across your environment. It depends on a broader data surface and a user-facing interface to make the patterns navigable.
- A review campaign drives periodic recertification across the organization. Each reviewer is routed the access they need to approve or revoke and completion is tracked. This is the formal, auditable process regulated organizations run. It relies on a web interface and reviewer roles.
- Giving auditors their own read-only interface to verify access and pull evidence, without routing every request through your team, removes a recurring burden during audit season.
- As organizations grant access to AI agents and service identities, those non-human actors need governance too. Controlling what AI agents can access under the same policy engine that governs people brings the same discipline to non-human identity.
- Separation of duties prevents one person from holding a combination of access that creates risk. The classic example is one person both requesting and approving payments. SOD rules let you declare conflicting entitlements so the system flags or blocks violations.
Feature Requests and Ideas
We are an early stage company, so you are talking to the people building the product and making the decisions.