
LARA · Lightweight Access Review Application
Turn the next access-review deadline into an accountable campaign
LARA is a lightweight access-review application designed specifically for the identity environment you already run. Rather than forcing an expensive, multi-year governance platform migration, LARA connects directly to your existing NetIQ or Active Directory infrastructure over read-only LDAP(S), freezes a stable review snapshot, guides business owners through unambiguous choices, keeps campaign progress visible, and closes with structured revocation deltas and frozen, hash-stamped audit evidence.
The review deadline
The next access review inevitably starts with another directory export. Spreadsheets are assembled by hand and distributed through email threads. Reviewers return conflicting formats, ignore follow-up notes, or rubber-stamp access lists without context.
Meanwhile, campaign managers spend weeks chasing outstanding submissions across inboxes. When the campaign finally concludes, revocation decisions must be manually re-keyed for another operational team to execute, and defensible evidence must be hurriedly reconstructed after the deadline has already elapsed.
LARA eliminates this operational friction by introducing an identity-aware campaign layer that runs directly over your current directory estate.
Where manual reviews break down
01 · Scope Assembled by Hand
The breakdown: Every review cycle begins with ad-hoc directory exports that must be manually reconciled with user identities, organizational roles, and current system owners.
The consequence: Review scope is stale before the first invitation email is sent, creating immediate audit vulnerabilities.
02 · Reviewers Lack One Consistent Decision Path
The breakdown: NetIQ IDM roles and directory group memberships land on managers' desks without structured guidance or consistent tooling.
The consequence: Decisions are delayed, questions vanish into email backlogs, and managers resort to unverified blanket approvals.
03 · Outstanding Work Hides in Email
The breakdown: Campaign managers have no real-time visibility into who has started, who is blocked, or which departments have stalled.
The consequence: Follow-up relies on broadcast email chasing, missed deadlines, and uncoordinated emergency escalations.
04 · Evidence Rebuilt After the Fact
The breakdown: Revocation instructions remain scattered across spreadsheets, while auditor proof requires assembling unversioned files months later.
The consequence: Auditors reject unverified records, and revoked permissions persist in production systems indefinitely.
Add campaign accountability without replacing your IAM platform
Enterprise access certification does not require a rip-and-replace identity governance migration. LARA deploys as three containers on one host of your choosing, run with Docker Compose or podman-compose, inside your own network perimeter. It operates through a strictly read-only service account over LDAP(S), connecting to the NetIQ or Active Directory environment you trust today.
Installation and initial configuration can be completed in minutes, establishing a governed recertification process without touching directory schemas, re-architecting user provisioning, or introducing operational latency.
NetIQ IDM Mode
Inspects and recertifies business and technical roles assigned to users within OpenText / NetIQ Identity Manager.
NetIQ Group Mode
Audits direct and dynamic eDirectory group memberships across organizational units.
Active Directory Group Mode
Audits enterprise Active Directory domain security and distribution group assignments.
One campaign, three accountable views
LARA decouples administrative orchestration from line-of-business evaluations and independent compliance inspections.
Campaign Manager
Keep ownership and velocity visible
- Scope & Launch: Define review populations, filter access rights, and assign primary and fallback reviewers dynamically from directory attributes.
- Track Progress: Monitor completion velocity in real time through clear status meters per reviewer, department, and application.
- Targeted Action: Trigger focused email reminders to stalled reviewers or generate personal review links for personnel without direct mailbox access.
Reviewer
Make every access decision explicit
- Clear Action Trio: Review access items one by one or in bulk with three unambiguous choices: APPROVE, REVOKE, or ESCALATE.
- Context-Rich Escalation: Reassign ambiguous access rights to secondary supervisors with attached context and explanatory notes.
- Persistent Staging: Progress is auto-saved as reviewers work; incomplete reviews can be closed and resumed at any time before final submission.
Auditor
Read the closed record with cryptographic proof
- Read-Only Inspection Portal: Access a dedicated, time-limited auditor view to examine campaign parameters, timing, and reviewer actions.
- Complete Metric Breakdowns: Inspect verified totals, decision distributions, exception logs, and potential rubber-stamp timing signals.
- Frozen Evidence Record: Export an immutable, hash-stamped PDF certificate proving exactly what was reviewed, by whom, and when.
Set the campaign up to be reviewable, keep it moving, then close the loop
Collect without disturbing the source
Connect over secure LDAP(S) in NetIQ IDM, NetIQ Group, or Active Directory Group mode using a read-only service account. LARA requires zero schema extensions or directory agent installations.
Freeze a stable review population
Define the identities, organizational units, and access entitlements in scope. LARA captures an immutable campaign snapshot so that in-flight directory modifications never distort the ongoing review.
Give every access item an owner
Map reviewers dynamically using directory manager hierarchy attributes. Automated fallback rules ensure that orphan accounts or missing manager fields never leave access rights unassigned.
Keep reviewer choices unambiguous
Reviewers interact through a clean web workspace to approve legitimate access, flag rights for revocation, or escalate uncertain items with contextual notes for second-level determination.
Surface what still needs attention
Campaign managers maintain live visibility over pending items. Targeted reminder notices nudge unresponsive reviewers, while deadline adjustments can be broadcast across active participants.
Leave immutable evidence and structured action
Lock the campaign permanently. LARA instantly generates a tamper-evident, hash-stamped PDF evidence dossier alongside structured revocation delta files ready for downstream execution.
Move from review decisions to verifiable action
A recertification campaign is only as valuable as the evidence it leaves behind and the revocations it triggers. When a LARA campaign closes, it freezes the entire decision history and produces two critical outputs:
Frozen, Hash-Stamped PDF Evidence
- Cryptographically Sealed: Every closed campaign generates a comprehensive PDF report stamped with a unique cryptographic hash, sealing the review scope, participant actions, timestamps, and justification notes.
- Audit-Ready Presentation: Designed for direct presentation to external regulatory examiners (NIS2, DORA, ISO 27001, SOX) without post-campaign compilation.
- Read-Only Auditor Portal: Auditors can be granted secure, view-only web access to inspect statistics, decision distributions, and reviewer velocity directly.
Structured Revocation Handoff
- Machine-Readable Outputs: Revocation choices are emitted as clean, structured CSV and JSON delta feeds containing user identifiers, revoked roles/groups, and decision timestamps.
- Downstream Integration: Hand off revocation lists directly to IT ticketing workflows (ServiceNow, Jira), automated provisioning scripts, or existing NetIQ IDM fulfillment workflows.
- Zero Translation Error: Replaces manual spreadsheet copying with structured, deterministic revocation data.
The old way vs. the LARA way
| Failure mode | The old way | The LARA way |
|---|---|---|
| Scope assembled by hand | Every review cycle begins with ad-hoc directory exports that must be manually reconciled with user identities, organizational roles, and current system owners — review scope is stale before the first invitation email is sent. | LARA captures an immutable campaign snapshot so that in-flight directory modifications never distort the ongoing review. |
| No consistent decision path | NetIQ IDM roles and group memberships land on managers' desks without structured guidance, so decisions are delayed and managers resort to unverified blanket approvals. | Reviewers work through a clean web workspace with three unambiguous choices — approve, revoke, or escalate with contextual notes. |
| Outstanding work hides in email | Campaign managers have no real-time visibility into who has started, who is blocked, or which departments have stalled — follow-up relies on broadcast email chasing. | Campaign managers maintain live visibility over pending items, with targeted reminder notices to unresponsive reviewers. |
| Evidence rebuilt after the fact | Revocation instructions remain scattered across spreadsheets while auditor proof is assembled from unversioned files months later — auditors reject unverified records. | Closing the campaign instantly generates a tamper-evident, hash-stamped PDF evidence dossier alongside structured revocation delta files. |
LARA owns the periodic campaign layer
Each product in the Mir.IAM ecosystem solves a distinct, mission-critical identity challenge around the directory environment:
LARA does not replace these operational controls—it builds upon them. LARA owns the scheduled access recertification event: freezing the snapshot, orchestrating human decisions, following up on deadlines, and producing audit-proof evidence.
Let's trace one campaign from scope to evidence
Together, we will follow identities and access rights through directory connection, reviewer assignment, decision workflows, follow-up tracking, closure, and revocation output. You leave the session knowing exactly where LARA fits your current LDAP environment and access-review process.
LARA orchestrates periodic access reviews and generates structured audit evidence. It does not replace internal control frameworks or guarantee regulatory compliance under NIS2, DORA, ISO 27001, or SOX. Independent legal and audit review remains the responsibility of the adopting enterprise.