
C1 Access
Self-service requests, RBAC, and just-in-time access control in one policy-driven system.
Give identities the right access for the right amount of time.
Request access where work happens
Let employees, contractors, workloads, and agents request access from the web, Slack, Teams, MCP, API, or CLI.
Apply policy before provisioning
Evaluate identity, role, resource, and risk context to auto-approve routine access or route sensitive requests.
Remove access when the work ends
Expire just-in-time grants automatically and keep the request, decision, grant, and removal together.
Dynamic Access Controls
Put policy and time limits into the access decision
How it works
Conditional policies evaluate role, attribute, and risk context in real time to grant or revoke access automatically.

Self-Service Access
Let people request access where work happens
How it works
Accept requests from a catalog, Slack, Microsoft Teams, CLI, web, or an approved automation.

RBAC + Just-in-Time Access
Use one policy model for roles and temporary access
How it works
Define role-based access around job function, team, attributes, and resource scope instead of rebuilding every grant by hand.

Role Mining
Build access profiles from how people actually work
How it works
Filter by department, job title, manager, employment status, or other mapped workforce attributes to identify a specific group of people.

