Skip to content

Let’s get technical

Here you will find information about architecture, specifications, documentation, APIs and more.

How RAC/M Identity works

A governance-first design centered on a single source of truth, wired to your systems through configuration rather than custom code.

Central identity repository

A central SQL repository of people, profiles, privileges and access levels, kept continuously in sync with connected systems, the single source of truth for who has access to what.

Identity Connector Framework (ICF)

A bidirectional connector layer that links the repository to identity sources, HR and ITSM systems, applications and databases, collecting access data and, on Premium, provisioning it back.

Configure, don’t code

The platform adapts to your technological and business context by configuring a rich array of built-in building blocks, eliminating costly customization and speeding deployment.

RAC/M Identity functional architecture: employee and other identity sources synchronized into a central repository hosted in a dedicated Microsoft Azure tenant, with analytics and correlation, self-service portal, approval and notification workflows, and bidirectional connectors that reconcile and automatically provision accounts and access across identity providers, directories, servers, cloud services and ticketing systems.

Deploy in SaaS mode or on prem

Three deployment options, distinguished by two responsibilities: who administers the platform, and who operates the governance program day to day.

On-premises

RAC/M Identity runs in your own infrastructure. You install, maintain and operate it end to end, backed by OKIOK’s proven methodology and support.

Administer
You
Operate
You

SaaS

OKIOK hosts and administers RAC/M Identity in a dedicated cloud tenant, with monitoring, patching, upgrading and evergreening, while you operate your own governance program.

Administer
OKIOK
Operate
You

Managed services

OKIOK both administers the platform and operates the governance program on your behalf, including access reviews, requests and the access model, as a turnkey service.

Administer
OKIOK
Operate
OKIOK

Automate everything, programmatically

A full REST API lets external systems such as ITSM platforms, AI agents and custom automations perform and manage IAM operations exactly as a human operator would, programmatically and at scale.

Beyond the API, the Identity Connector Framework (ICF) provides out-of-the-box, bidirectional connectivity to directories, HR and ITSM systems, SaaS applications and databases. Generic scripted, SCIM and JDBC connectors extend it to virtually any interface.

REST API reference →Available connectors →

Secure by design, audited yearly

Annual penetration testing

RAC/M Identity is designed from the ground up to be secure: strong encryption with TLS and Azure SQL, strong authentication via Entra ID or your preferred SAML IdP, and a hardened, dedicated tenant per customer.

Every change follows a formal change-management process with roll-back planning, audited annually under ISO 27001 and SOC 2 Type 2. The platform is tested by a professional offensive-security team through annual scans and penetration tests.

Platform, security & technical specifications

RAC/M Identity SaaS runs on Microsoft Azure, encrypted and monitored around the clock, on an extensible data model with broad, standards-based integration.

Platform & hostingRAC/M Identity SaaS only

Cloud platform
Microsoft Azure, dedicated per-customer tenant
Network link to Azure tenant
Point-to-point VPN or reverse-proxy agent (no inbound connections)
Data residency
Canada Central (Toronto) & Canada East (Quebec City)Other Azure regions determined by customers
High availability
Interzone geo-replication across regions
Availability SLA
99.5% monthly, 24/7/365 · 99.99% High availability option available

Data & encryptionRAC/M Identity SaaS only

Database
Azure SQL
Encryption at rest
AES-256, Transparent Data Encryption (TDE)
Encryption in motion
TLS with recommended cipher suites
Backups
Azure SQL, 10-second resolution
Disaster recovery
RPO < 10 seconds, RTO < 4 hours
Data retention
1 year by default, other duration available

Access & authentication

Single Sign-On
Entra ID / SAMLEntra ID SSO configuration →
Multi-factor authentication (MFA)
Leverages Entra ID or your IdP’s MFA mechanisms
Password self-service
Industry-standard PWM engine

Data model & scale

Identities volume
Unlimited
Identities types
Workforce, external, seasonal and other human identities, plus machines, bots, workloads and AI agents
Account types
Human, non-human, personal, privileged, service, shared, generic, technical
Data model
Dynamically extensible custom attributes
Access models
RBAC + ABAC + dynamic roles(role mining & modeling)

Integration & APIs

Connectors
ICF bidirectional connectorsAvailable connectors →
Collectors
Unidirectional flat files(CSV, XLS, XLSX, IDOC)
APIs
REST API for admin automationREST API reference →Manual provisioning API for customizing email requests and ticketsManual provisioning →
API authentication
OAuth 2.0

User interface

Supported browsers
Edge, Chrome, Firefox, Safari(Windows, macOS & iOS)
Client access
Any device with a compatible browser
User interface
Fully customizable look and feel
Languages
French and English, selected by locale, browser setting or user preference
Notifications
Fully customizable emails with MVEL scripts and manual provisioning API

Subscription

Subscription
Annual, based on the number of active identities
Environments
Includes a pre-production environmentAdditional environments available

Operations & support

MonitoringRAC/M Identity SaaS only
24/7/365 (availability, performance, security)
Technical support
Level 2 & 3Extended business hours included in subscription24/7/365 support available
Support languages
English & French

Put your technical questions to our experts

Evaluating RAC/M Identity for your environment? Talk to our product experts about architecture, integrations, deployment, security or any other technical requirements you need to validate.

Prefer to continue exploring on your own? Browse the RAC/M Identity datasheet, white papers and other technical resources.

Send us a message

Only your email is required. Pick a subject, add a note, and send.

Incident in progress? Call the 24/7 line instead of waiting for a reply: +1 450 681-1681, extension 277