LARA product visual showing a frozen review population resolving into approve, revoke, and escalate decisions, closing on a sealed record.
← All products
LARA

LARA · Lightweight Access Review Application

Turn the next access-review deadline into an accountable campaign

LARA is a lightweight access-review application designed specifically for the identity environment you already run. Rather than forcing an expensive, multi-year governance platform migration, LARA connects directly to your existing NetIQ or Active Directory infrastructure over read-only LDAP(S), freezes a stable review snapshot, guides business owners through unambiguous choices, keeps campaign progress visible, and closes with structured revocation deltas and frozen, hash-stamped audit evidence.

The review deadline

The next access review inevitably starts with another directory export. Spreadsheets are assembled by hand and distributed through email threads. Reviewers return conflicting formats, ignore follow-up notes, or rubber-stamp access lists without context.

Meanwhile, campaign managers spend weeks chasing outstanding submissions across inboxes. When the campaign finally concludes, revocation decisions must be manually re-keyed for another operational team to execute, and defensible evidence must be hurriedly reconstructed after the deadline has already elapsed.

LARA eliminates this operational friction by introducing an identity-aware campaign layer that runs directly over your current directory estate.

Where manual reviews break down

01 · Scope Assembled by Hand

The breakdown: Every review cycle begins with ad-hoc directory exports that must be manually reconciled with user identities, organizational roles, and current system owners.

The consequence: Review scope is stale before the first invitation email is sent, creating immediate audit vulnerabilities.

02 · Reviewers Lack One Consistent Decision Path

The breakdown: NetIQ IDM roles and directory group memberships land on managers' desks without structured guidance or consistent tooling.

The consequence: Decisions are delayed, questions vanish into email backlogs, and managers resort to unverified blanket approvals.

03 · Outstanding Work Hides in Email

The breakdown: Campaign managers have no real-time visibility into who has started, who is blocked, or which departments have stalled.

The consequence: Follow-up relies on broadcast email chasing, missed deadlines, and uncoordinated emergency escalations.

04 · Evidence Rebuilt After the Fact

The breakdown: Revocation instructions remain scattered across spreadsheets, while auditor proof requires assembling unversioned files months later.

The consequence: Auditors reject unverified records, and revoked permissions persist in production systems indefinitely.

Add campaign accountability without replacing your IAM platform

Enterprise access certification does not require a rip-and-replace identity governance migration. LARA deploys as three containers on one host of your choosing, run with Docker Compose or podman-compose, inside your own network perimeter. It operates through a strictly read-only service account over LDAP(S), connecting to the NetIQ or Active Directory environment you trust today.

Installation and initial configuration can be completed in minutes, establishing a governed recertification process without touching directory schemas, re-architecting user provisioning, or introducing operational latency.

NetIQ IDM Mode

Inspects and recertifies business and technical roles assigned to users within OpenText / NetIQ Identity Manager.

NetIQ Group Mode

Audits direct and dynamic eDirectory group memberships across organizational units.

Active Directory Group Mode

Audits enterprise Active Directory domain security and distribution group assignments.

One campaign, three accountable views

LARA decouples administrative orchestration from line-of-business evaluations and independent compliance inspections.

Campaign Manager

Keep ownership and velocity visible

  • Scope & Launch: Define review populations, filter access rights, and assign primary and fallback reviewers dynamically from directory attributes.
  • Track Progress: Monitor completion velocity in real time through clear status meters per reviewer, department, and application.
  • Targeted Action: Trigger focused email reminders to stalled reviewers or generate personal review links for personnel without direct mailbox access.

Reviewer

Make every access decision explicit

  • Clear Action Trio: Review access items one by one or in bulk with three unambiguous choices: APPROVE, REVOKE, or ESCALATE.
  • Context-Rich Escalation: Reassign ambiguous access rights to secondary supervisors with attached context and explanatory notes.
  • Persistent Staging: Progress is auto-saved as reviewers work; incomplete reviews can be closed and resumed at any time before final submission.

Auditor

Read the closed record with cryptographic proof

  • Read-Only Inspection Portal: Access a dedicated, time-limited auditor view to examine campaign parameters, timing, and reviewer actions.
  • Complete Metric Breakdowns: Inspect verified totals, decision distributions, exception logs, and potential rubber-stamp timing signals.
  • Frozen Evidence Record: Export an immutable, hash-stamped PDF certificate proving exactly what was reviewed, by whom, and when.

Set the campaign up to be reviewable, keep it moving, then close the loop

01 CONNECT

Collect without disturbing the source

Connect over secure LDAP(S) in NetIQ IDM, NetIQ Group, or Active Directory Group mode using a read-only service account. LARA requires zero schema extensions or directory agent installations.

02 SCOPE

Freeze a stable review population

Define the identities, organizational units, and access entitlements in scope. LARA captures an immutable campaign snapshot so that in-flight directory modifications never distort the ongoing review.

03 ASSIGN

Give every access item an owner

Map reviewers dynamically using directory manager hierarchy attributes. Automated fallback rules ensure that orphan accounts or missing manager fields never leave access rights unassigned.

04 DECIDE

Keep reviewer choices unambiguous

Reviewers interact through a clean web workspace to approve legitimate access, flag rights for revocation, or escalate uncertain items with contextual notes for second-level determination.

05 FOLLOW UP

Surface what still needs attention

Campaign managers maintain live visibility over pending items. Targeted reminder notices nudge unresponsive reviewers, while deadline adjustments can be broadcast across active participants.

06 CLOSE

Leave immutable evidence and structured action

Lock the campaign permanently. LARA instantly generates a tamper-evident, hash-stamped PDF evidence dossier alongside structured revocation delta files ready for downstream execution.

Move from review decisions to verifiable action

A recertification campaign is only as valuable as the evidence it leaves behind and the revocations it triggers. When a LARA campaign closes, it freezes the entire decision history and produces two critical outputs:

Frozen, Hash-Stamped PDF Evidence

  • Cryptographically Sealed: Every closed campaign generates a comprehensive PDF report stamped with a unique cryptographic hash, sealing the review scope, participant actions, timestamps, and justification notes.
  • Audit-Ready Presentation: Designed for direct presentation to external regulatory examiners (NIS2, DORA, ISO 27001, SOX) without post-campaign compilation.
  • Read-Only Auditor Portal: Auditors can be granted secure, view-only web access to inspect statistics, decision distributions, and reviewer velocity directly.

Structured Revocation Handoff

  • Machine-Readable Outputs: Revocation choices are emitted as clean, structured CSV and JSON delta feeds containing user identifiers, revoked roles/groups, and decision timestamps.
  • Downstream Integration: Hand off revocation lists directly to IT ticketing workflows (ServiceNow, Jira), automated provisioning scripts, or existing NetIQ IDM fulfillment workflows.
  • Zero Translation Error: Replaces manual spreadsheet copying with structured, deterministic revocation data.

The old way vs. the LARA way

Failure modeThe old wayThe LARA way
Scope assembled by handEvery review cycle begins with ad-hoc directory exports that must be manually reconciled with user identities, organizational roles, and current system owners — review scope is stale before the first invitation email is sent.LARA captures an immutable campaign snapshot so that in-flight directory modifications never distort the ongoing review.
No consistent decision pathNetIQ IDM roles and group memberships land on managers' desks without structured guidance, so decisions are delayed and managers resort to unverified blanket approvals.Reviewers work through a clean web workspace with three unambiguous choices — approve, revoke, or escalate with contextual notes.
Outstanding work hides in emailCampaign managers have no real-time visibility into who has started, who is blocked, or which departments have stalled — follow-up relies on broadcast email chasing.Campaign managers maintain live visibility over pending items, with targeted reminder notices to unresponsive reviewers.
Evidence rebuilt after the factRevocation instructions remain scattered across spreadsheets while auditor proof is assembled from unversioned files months later — auditors reject unverified records.Closing the campaign instantly generates a tamper-evident, hash-stamped PDF evidence dossier alongside structured revocation delta files.

LARA owns the periodic campaign layer

Each product in the Mir.IAM ecosystem solves a distinct, mission-critical identity challenge around the directory environment:

LARA does not replace these operational controls—it builds upon them. LARA owns the scheduled access recertification event: freezing the snapshot, orchestrating human decisions, following up on deadlines, and producing audit-proof evidence.

Let's trace one campaign from scope to evidence

Together, we will follow identities and access rights through directory connection, reviewer assignment, decision workflows, follow-up tracking, closure, and revocation output. You leave the session knowing exactly where LARA fits your current LDAP environment and access-review process.

LARA orchestrates periodic access reviews and generates structured audit evidence. It does not replace internal control frameworks or guarantee regulatory compliance under NIS2, DORA, ISO 27001, or SOX. Independent legal and audit review remains the responsibility of the adopting enterprise.