Skip to content

Frequently asked questions about RAC/M Identity

What RAC/M Identity governs, how it fits with the systems you already run, and how a deployment starts.

What is RAC/M Identity?

RAC/M Identity is an Identity Governance and Administration (IGA) solution that helps organizations control who has access to their systems, applications and information. It brings identity and access information together so you can see who has access to what, why they have it and whether they should still have it.

It also helps automate identity lifecycle processes, access requests, approvals, reviews and provisioning.

How is RAC/M Identity different from Microsoft Active Directory or Entra ID?

Active Directory and Microsoft Entra ID provide directory, authentication and access-management capabilities. RAC/M Identity adds the governance layer across your environment.

It connects identity information from HR systems, directories and other sources with accounts and access rights across business applications and infrastructure. This gives you a consolidated view of access, enables access reviews and segregation-of-duties controls, and automates processes such as onboarding, role changes and offboarding.

RAC/M Identity integrates with Active Directory, Microsoft Entra ID, Microsoft Graph and other systems rather than requiring you to replace them.

Can RAC/M Identity manage employees, external users, non-human identities and AI agents?

Yes. RAC/M Identity can govern a wide range of human and non-human identities.

Human identities can include employees, contractors, consultants, students, partners, seasonal workers and other external users. It also supports people with multiple identities or personas, for example someone who is simultaneously an employee and a student, or a physician and a researcher.

RAC/M Identity can also govern non-human identities, including service accounts, machines, bots, workloads, automation tools and AI agents. These identities can be associated with appropriate owners, policies and access rights so they can be governed and reviewed rather than becoming unmanaged accounts hidden within the environment.

Can RAC/M Identity find orphaned, rogue and unnecessary accounts?

Yes. RAC/M Identity consolidates identities, accounts, roles and entitlements from connected systems so that access can be analyzed across the organization.

This helps identify orphaned accounts that no longer have a valid owner, rogue or unaccounted-for accounts, inappropriate access and access that is no longer required. Organizations can use these findings to clean up existing access, assign ownership and establish governance controls before and after automating identity processes.

This capability is particularly useful for organizations that need better visibility and access control but are not yet ready to undertake a full IGA transformation.

Can RAC/M Identity automate onboarding, job changes and offboarding?

Yes. RAC/M Identity can automate identity lifecycle processes so that access changes as people join the organization, change roles or responsibilities, and leave.

Access can be assigned through roles and business rules, approved through configurable workflows and provisioned automatically to integrated systems. When direct provisioning is not available, RAC/M Identity can also fulfill requests through mechanisms such as structured emails or IT service-management processes.

Can employees request access and managers approve it themselves?

Yes. RAC/M Identity includes a self-service portal where users can request access and designated managers, application owners or other approvers can review and approve requests.

The same portal supports access-review campaigns, allowing responsible people to periodically confirm whether users still require their existing access. Workflows can be configured according to the sensitivity of the application or resource and your organization’s governance requirements.

Can RAC/M Identity help with access reviews and compliance?

Yes. RAC/M Identity supports formal access certification and recertification campaigns in which managers, asset owners or other designated reviewers confirm whether identities, accounts, roles and access rights remain appropriate.

Reviews can target specific systems, populations or types of access and can include business-rule and segregation-of-duties violations. The resulting governance process provides evidence that access is being periodically reviewed and controlled, helping organizations demonstrate compliance to internal and external auditors.

Will RAC/M Identity integrate with the systems we already use?

Yes. RAC/M Identity is designed to integrate with existing HR systems, directories, databases, cloud services, business applications and IT service-management platforms.

Available connectors include technologies and applications such as Active Directory, Microsoft Graph, Microsoft 365, Workday, SAP SuccessFactors, PeopleSoft, Salesforce, Dynamics 365, AWS IAM Identity, LDAP, JDBC and SCIM-compatible applications. Generic APIs, database and file-based integration mechanisms can also be used for systems that do not have a dedicated connector. Any connector you need can be developed quickly by adapting an existing one.

Do we have to automate everything at once?

No. RAC/M Identity supports a progressive implementation.

Organizations can start by consolidating identity and access information, identifying risky or unnecessary access, conducting access reviews and establishing governance processes before automating provisioning.

OKIOK’s approach progresses through four stages: Discovery & Analytics, Governance, Automation and Evolution. This allows organizations to deliver useful governance results early and expand automation as their identity program matures.

Can RAC/M Identity be deployed in the cloud or on-premises?

Both. RAC/M Identity can be delivered as a SaaS solution hosted and administered by OKIOK, deployed in your own infrastructure, or provided as a managed service in which OKIOK can also operate elements of the identity governance program on your behalf.

The SaaS option eliminates the need to maintain the underlying RAC/M Identity infrastructure, while on-premises deployment gives organizations that require it control of the complete environment. Managed services can additionally cover operational activities such as access reviews, requests, approvals and maintenance of the access model.

How long does it take to deploy RAC/M Identity?

It depends on the amount of preparation and integration required. The main factors include the size and complexity of the organization, the maturity of existing IAM processes, the quality of directories and identity data, the desired target state, and the number and types of identity sources and target systems to be integrated.

Because RAC/M Identity is available as SaaS, an initial deployment can start producing useful results in as little as four weeks. A typical functional Phase 1 deployment takes approximately 20 to 40 weeks. More complex programs involving extensive integration and automation, advanced functionality, and role mining and modeling can extend to 50 to 60 weeks.

How much does RAC/M Identity cost?

The answer depends on both the number of identities being managed and the scope of the deployment.

RAC/M Identity licence fees for both editions are based on tiers of active identities. There are no additional licence fees for connectors or inactive identities.

Implementation costs are driven primarily by the preparation and integration effort described above. As a general planning guideline, a deployment typically requires the equivalent of approximately 1.5 to 2 full-time resources over the duration of the project, although this can vary significantly with scope and complexity.

A short discussion with one of our experts is usually enough to understand your environment, establish the likely scope and provide a budgetary estimate or detailed quote.

Still have a question?

Tell us about your environment and your identity governance requirements.

Send us a message

Only your email is required. Pick a subject, add a note, and send.

Incident in progress? Call the 24/7 line instead of waiting for a reply: +1 450 681-1681, extension 277