For IT and security teams

Close the leak risk
by design.

Employee IDs are stopped by HR integration and IGA. External partner IDs sit outside both. Tactna leaves the employee IdP and IGA in place and turns issuing, changing, detecting and deleting external IDs into a system, without adding to IT's workload.

Customers

  • Fujitsu G-Search
  • KITZ Corporation
  • CPA
  • MS&AD InterRisk Research & Consulting, Inc.
  • Ministry of Economy, Trade and Industry

Problem

HR feeds,
and IGA
neither reaches outside.

Nothing anywhere stops an external partner's ID.

Employees sync with HR and are reviewed by IGA. Distributor and supplier contacts are in neither the HR system nor the IGA ledger. IT issues their IDs per app on request, and IDs nobody asks to stop simply remain.

  • RequestEvery add and delete lands on ITEvery partner handover becomes a request from the business. Issued per app, and sometimes the deletion is forgotten.
  • 30%IDs that never stop, left behindA leaver's ID stays open until someone tells you. In one customer, 30% of distributor IDs were unused.
  • ScatteredEvidence in email and spreadsheetsWho approved when, who deleted when. The evidence auditors want is scattered across request emails and shared folders.

How it is solved

Problem by problem,
what changes.

  1. 01

    Add/delete requests pile up on IT

    Before

    Requests from the business, handled by hand per app.

    After

    Delegate to partner admins. In-policy actions run automatically; only exceptions need approval.

  2. 02

    IDs that never stop

    Before

    Waiting to hear who left. A yearly spreadsheet review.

    After

    Detect inactivity and auto-lock. Confirm with the partner and remove from every app.

  3. 03

    Duplicate admin with existing systems

    Before

    Bouncing between the IdP, IGA, and every app's console.

    After

    IdP for authentication, IGA for employees, Tactna for external. One policy, one record.

A day in that job

After go-live,
three moments.

  • Scene 01

    The day request emails stop

    A distributor contact changes. It used to mean a request from the business and three admin consoles. Now the distributor admin does it in the Portal, and the audit log records it.

    IT sees only the exceptions that need approval.

  • Scene 02

    The Monday morning you read the lock notices

    Over the weekend, 12 IDs were auto-locked at 90 days inactive. Partner admins have received the confirmation request. IT checks the count on the dashboard and does nothing.

    The stopping is done by the system.

  • Scene 03

    The day the auditor asks for evidence

    "Who approved this distributor's IDs, when, and when were they deleted?" Search the distributor in the Activity Log and export a CSV. Ten minutes.

    No digging through email. No spreadsheets.

Customer story · Industrial valve manufacturerKITZ

Customers

Distributor onboarding went from weeks to immediate. The 30% zombie accounts were wiped out, and user-management work fell 70%.
  • InstantOnboarding (from weeks)
  • 30%Zombie accounts eliminated
  • 70%Less user-management work

KITZ Corporation

An industrial valve manufacturer with a global distributor network. IDs for several distributor-facing apps were unified on Tactna, with inactivity detection, auto-lock, and automatic deletion from every system built in. OutSystems seat-license cost was optimized as well.

FAQ

Before you buy,
what people ask.

Does it compete with our existing IdP (Okta / Entra ID / Auth0)?

No. Okta or Entra ID keeps authenticating your employees, while Tactna includes its own identity platform (Auth0 or Amazon Cognito) for external partners. Nothing changes in your internal IdP. If you already use Auth0 for external users, the Tactna team migrates the tenant.

We already run IGA (SailPoint / Saviynt). How are the roles split?

Employees: IGA. External partners: Tactna. IGA is strong at top-down request and approval; Tactna at delegation to partners and reviewing unused IDs. Both sets of evidence can go to the audit.

Can we delegate to partners and stay in control?

Yes. The manufacturer's access policy decides what is allowed, and partners can only act within it. Every action is logged, and actions needing approval go to IT.

Security certifications and data residency?

We hold ISO 27001 and ISO 27017. Data is stored in-region, and the audit log is append-only and tamper-proof.

External IDs
stop by design, too.

  • Your employee IdP and IGA stay as they are
  • Inactivity detection and auto-lock
  • ISO 27001 / 27017 certified