The products

Two guards. Every access & change control, covered.

SOXMATE puts a dedicated AI guard on each of the two ITGC domains that fail audits most. Here's exactly what each one does.

Access ITGCs

AccessGuard

Who can get into your financial systems — and whether they should — is the most-scrutinized area of any SOX audit. AccessGuard automates all three access controls: reviews, provisioning, and deprovisioning.

Q2 access review · NetSuite 14 to review
Users with elevated access
AL
Aisha Lawson
Controller
SoD conflict
TN
Tom Nguyen
AP Manager
Approved
SB
Sara Bello
GL Accountant
Pending
User access reviews

Reviews that run themselves.

AccessGuard pulls every user and entitlement from your in-scope systems, routes each line to the right owner, and flags segregation-of-duties conflicts before a human even looks. Sign-offs are captured as immutable evidence.

  • Detects "pay & approve" SoD conflicts automatically
  • Routes each line to the right reviewer
  • Reviewer sign-off captured as evidence
Leaver revocation SLA 1 breach
HR terminations vs system access
DK
Dana Kim
Left Mar 3 · NetSuite
31h overdue
MR
Marco Ruiz
Left Mar 9 · Okta
6h left
PT
Priya Tan
Left Mar 1 · Workday
Revoked
Provisioning & leavers

No access without approval. No leaver left behind.

Every new grant is reconciled to an authorized request — if access appears without an approval, it's flagged instantly. And every HR termination is matched against live access, with a countdown on your revocation SLA and an auto-ticket to IT the moment it's breached.

  • Matches each access grant to its approval ticket
  • Counts down leaver revocation SLAs live
  • Auto-opens revocation tickets to IT
REVIEWS

Periodic UARs

Quarterly or monthly access reviews, fully orchestrated end to end.

PROVISIONING

Approval-before-grant

Reconciles every new access event back to an authorized request.

LEAVERS

SLA deprovisioning

Races the clock on every termination and tickets IT on breach.

Change ITGCs

ChangeGuard

Unauthorized or untested changes to financially-relevant systems are a classic SOX deficiency. ChangeGuard proves every production change followed your change-management control — automatically.

Production deploys · this week 23/24 matched
Releases reconciled to change tickets
#1
billing-svc v4.12
CR-3310 · approved & tested
Compliant
#2
ledger-api v2.8
No change ticket found
Unauthorized
#3
report-gen v1.9
CR-3318 · approved & tested
Compliant
Change reconciliation

Every deploy, tied to an approval.

ChangeGuard pulls deployments from your CI/CD and reconciles each one to an approved, tested change ticket. A release with no matching authorization is surfaced as an unauthorized change the moment it ships — not at year-end testing.

  • Reconciles every deploy to a change ticket
  • Flags unauthorized changes instantly
  • Confirms approval & test evidence on file
Developer / deployer SoD clean
Who wrote vs who shipped
JC
CR-3310 · billing-svc
dev: J. Cole · deploy: pipeline
Segregated
EV
CR-3290 · ledger-api
dev: E. Voss · deploy: E. Voss
Same person
RP
CR-3318 · report-gen
dev: R. Patel · deploy: pipeline
Segregated
Segregation of duties

The person who builds it can't be the one who ships it.

ChangeGuard checks that the developer behind a change isn't also the one who pushed it to production — a core change-management control. When the same person does both, it's flagged for review with the full trail attached.

  • Developer vs deployer separation enforced
  • Emergency-change exceptions tracked separately
  • Full change timeline preserved as evidence
RECONCILIATION

Deploy ↔ ticket

Matches every production release to an approved change record.

AUTHORIZATION

Approved & tested

Confirms sign-off and test evidence exist before go-live.

SoD

Dev ≠ deployer

Enforces separation between who builds and who ships.

See the guards on your own systems.

Bring your access and change controls — we'll show AccessGuard and ChangeGuard testing them live in 30 minutes.