HomeHow It WorksLive DemoAssessmentIntegrationsPricingAboutSecurityFAQFree Consultation
Frequently asked questions

Understand How MeridianAuthZ Strengthens Your Identity Environment

How MeridianAuthZ works, what it connects to, how it supports audits, and how your organization can get started.

About MeridianAuthZ
MeridianAuthZ is an Identity Governance and Administration (IGA) and identity-security platform designed for businesses that rely on business productivity and cloud platforms or enterprise identity providers and directories. It helps organizations see who has access, identify former employees with active accounts, review contractor and vendor access, reduce unnecessary permissions, monitor administrative and sensitive access, simplify access reviews, and produce evidence for audits and compliance. It adds an additional layer of visibility, governance, and protection around the identity and application environment your business already uses.
As organizations grow, employees, contractors, vendors, and administrators gain access to more systems and information. Over time, businesses may lose track of former employees with active accounts, contractors whose access should have expired, employees with permissions from previous roles, inactive or forgotten accounts, users with unnecessary administrative access, and access that has never been reviewed. MeridianAuthZ helps identify these issues and gives your team a clear process for reviewing, correcting, and documenting access.
MeridianAuthZ provides identity and access management and identity governance capabilities focused on access visibility, access reviews, identity-risk reduction, remediation, and audit evidence. It helps organizations understand who has access, determine whether that access is still appropriate, and document what actions were taken.
MeridianAuthZ can help provide visibility and governance over administrative and privileged access. Depending on the available integrations and enabled capabilities, it may help identify users with elevated roles, unused administrative accounts, contractors with privileged permissions, former employees with administrative access, privileged accounts without a confirmed owner, and administrative access that has not been reviewed. MeridianAuthZ is not a replacement for a dedicated privileged-access management vault or session-management platform.
Identity governance capabilities
Yes. MeridianAuthZ is designed to provide identity lifecycle governance, access visibility, certifications, policy controls, remediation, and audit evidence across identity sources and connected applications. It uses identity and access information from your identity providers and combines it with information from selected business applications to provide a broader view of access across the organization.
No. MeridianAuthZ works alongside the identity and application environment your organization already uses. Your identity sources and business applications remain the foundation for identities, authentication, groups, applications, and access. MeridianAuthZ adds an additional layer focused on visibility, governance, risk identification, remediation tracking, and audit evidence. Keep your systems. Add visibility. Strengthen governance.
Identity providers provide important authentication, directory, and access capabilities. However, organizations often need centralized governance across multiple applications, identities, entitlements, lifecycle events, certifications, policies, and audit requirements. Businesses may still need a simpler view of access risk, visibility across identity provider and non-identity provider applications, easier reporting for business leaders, focused reviews of former employees and contractors, support organizing audit evidence, assistance with implementation and ongoing operation, and a governance solution aligned with their budget and available IT resources. MeridianAuthZ is a practical IGA platform that unifies governance across the systems, identities, and access decisions already present in your environment.
Yes. MeridianAuthZ supports structured access reviews and certifications for users, groups, roles, entitlements, applications, contractors, privileged access, and other governed resources. MeridianAuthZ organizes certification scope, reviewers, decisions, escalations, remediation, completion tracking, and evidence across connected systems.
Yes. MeridianAuthZ supports governance of joiner, mover, and leaver events by connecting authoritative identity data with account and access information across connected systems. MeridianAuthZ helps identify lifecycle gaps, trigger or track provisioning and deprovisioning actions, verify completion, document exceptions, and prepare audit evidence.
Yes, when the relevant identity source, directory, cloud service, application, database, or infrastructure platform is connected through a supported integration. Identities may have multiple accounts, roles, groups, entitlements, and privileges across financial systems, customer platforms, cloud applications, databases, internal tools, and sensitive business resources. MeridianAuthZ correlates identities with accounts and access information from selected systems so your team can govern the complete access picture.
Access visibility and risk
Yes. MeridianAuthZ compares employment status with account and permission information to identify former employees who still have active identity provider accounts, application accounts, group memberships, assigned roles, administrative permissions, or access to sensitive information. The completeness of the result depends on the quality of the connected identity, HR, and application data.
Yes, when removal is enabled for that system and approved by your team. MeridianAuthZ removes access automatically only after you configure and approve that process. Which systems support one-click removal depends on the connector, and we confirm yours during scoping. Where automated removal is not enabled, MeridianAuthZ identifies and recommends the access for removal.
An orphaned account is an account that remains active but no longer has a confirmed, active owner. Examples include an account belonging to a former employee, a contractor account that remains after a project ends, an application account that cannot be connected to an employee, an old administrative account, a service account with no documented owner, or a duplicate account that is no longer needed. MeridianAuthZ helps identify accounts that require ownership confirmation or removal.
Excessive access occurs when a person has more permissions than are required for their current responsibilities. This can happen when an employee changes departments, temporary access is never removed, permissions accumulate over several years, group memberships are copied from another user, a contractor receives broad access, or administrative access is assigned unnecessarily. MeridianAuthZ helps highlight access that may require review, reduction, or removal.
Yes. MeridianAuthZ identifies employees who retained permissions after changing departments, job functions, locations, or responsibilities by comparing historical identity information, current role information, and connected permission data. A manager or application owner confirms whether the access is still required before it is removed.
Yes. MeridianAuthZ can help organizations review contractor account status, project or contract end dates, application access, group memberships, administrative permissions, sensitive access, last activity, review history, and access expiration. This helps prevent temporary access from becoming permanent access.
Yes. MeridianAuthZ identifies inactive accounts when account-status or activity information is available from connected systems. Inactivity alone does not always mean the account should be deleted, because some legitimate accounts are used only periodically. MeridianAuthZ presents the account with ownership, role, activity, and access context so your team can decide.
MeridianAuthZ may help identify multiple accounts that appear to belong to the same person, using matching information such as employee identification number, email address, username, name, department, manager, application ownership, and other identity attributes. Potential matches should be reviewed before accounts are combined, disabled, or removed.
Yes. MeridianAuthZ shows who can access financial information, customer records, employee information, confidential documents, administrative settings, business-critical applications, security systems, and privileged resources once those sensitive systems, roles, groups, or permissions are identified and connected. Your organization determines what is considered sensitive and how that access should be reviewed.
MeridianAuthZ helps reduce the likelihood of unauthorized access by identifying unnecessary, outdated, unmanaged, or excessive permissions. It can support stronger access reviews, faster removal, clearer ownership, and better access governance. However, no single cybersecurity product can guarantee that unauthorized access or a security breach will never occur.
Applications and integrations
MeridianAuthZ is centered on authoritative identity sources and connects with selected business applications and directories. Integration categories include identity provider services, employee directories, human resources systems, financial applications, customer-management platforms, collaboration tools, cloud applications, databases, internal systems, administrative platforms, and custom business applications. Only integrations that have been developed, tested, and approved are publicly listed as supported.
MeridianAuthZ connects through APIs, directory integrations, secure file imports, database connections, secure data feeds, or custom connectors. The recommended method depends on the application's available interfaces, security requirements, and the information needed for the review.
We will review the application and determine whether it can be connected through an available API, a secure file export, a database connection, a scheduled data feed, or a custom connector. Connector availability, estimated effort, required permissions, and any additional cost will be confirmed before you commit.
Yes. Custom applications can be connected when they provide reliable identity, account, role, permission, or activity information through an approved integration method. A technical review confirms feasibility before scope is finalized.
Connections use the minimum permissions required for the approved capability. Read-only access is often sufficient for visibility and assessment activities. Remediation or automated changes can require additional permissions. Every requested permission is documented and approved before connection.
Yes. An organization can begin with one authoritative identity source and expand to additional applications later. However, the identity source alone may not show every account and permission that exists across external business systems. Connecting additional applications provides a more complete view.
Audits and compliance
MeridianAuthZ helps organize evidence about identities, accounts, permissions, reviews, findings, decisions, and corrective actions. It can help answer questions such as who had access, what each person could access, which former employees remained active, which contractors were reviewed, when access was reviewed, who approved continued access, what access was removed, which risks were identified, and what corrective action was completed.
MeridianAuthZ produces user and account inventories, application-access reports, group and role reports, contractor-access reports, former-employee findings, administrative-access reports, access-review records, approval and denial decisions, remediation records, identity-risk reports, review completion reports, and compliance-supporting documentation. The exact evidence set depends on the connected systems and enabled capabilities.
No. MeridianAuthZ supports audit readiness, access governance, evidence collection, and remediation tracking. Whether an organization passes an audit depends on its full control environment, policies, procedures, technical configuration, documentation, employee practices, and the auditor's requirements.
No product automatically makes an organization compliant. MeridianAuthZ can support compliance by improving access visibility, strengthening reviews, documenting actions, and producing evidence. Your organization remains responsible for determining which laws, regulations, frameworks, and contractual requirements apply.
MeridianAuthZ supports access-control and evidence requirements associated with frameworks or obligations such as SOC 2, HIPAA, SOX, ISO 27001, NIST-based programs, customer security requirements, and internal access-control policies. The exact support depends on your configuration, connected systems, implemented controls, and audit requirements. MeridianAuthZ is not presented as formally certified against any framework unless that certification has been independently completed.
Yes. MeridianAuthZ reduces manual work by centralizing identity and access information, review decisions, findings, and remediation evidence. The time saved depends on the number of connected systems, data quality, existing processes, reporting requirements, review scope, and customer participation.
Deployment and implementation
A focused pilot is typically completed in approximately 30 days. The timeline depends on system access, connector availability, number of applications, identity volume, data quality, security approvals, customer participation, and custom integration requirements. A broader production deployment can require additional time.
A typical pilot includes an authoritative identity source, employee and contractor identities, three to five business applications, former-employee account discovery, inactive-account analysis, contractor-access review, excessive-permission analysis, administrative-access review, sensitive-access review, an identity-risk report, remediation recommendations, audit-supporting evidence, and a demonstration using your environment.
No. MeridianAuthZ is designed for growing organizations that may not have a dedicated IAM or identity-governance team. Implementation and ongoing services may include environment discovery, connection setup, application integration, configuration, reporting setup, administrator training, technical support, connector assistance, and periodic optimization.
The MeridianAuthZ team can assist with installation, connection, configuration, testing, reporting, and administrator training. You will need to provide appropriate system access, technical contacts, security approvals, and application information.
The goal is to minimize disruption. Assessment and visibility activities can often begin using read-only or limited-permission connections. Any configuration or access change is reviewed, tested, approved, and scheduled according to your change-management process.
Yes. MeridianAuthZ is designed to start with your identity sources and a small number of priority applications. Your organization can add more identities, applications, reports, and governance capabilities after the initial value has been demonstrated.
Security and privacy
MeridianAuthZ protects identity and access information through implemented controls such as secure authentication, role-based administrative access, encryption in transit, encryption at rest, audit logging, customer data separation, limited integration permissions, data-retention controls, backup and recovery, vulnerability management, security monitoring, and incident-response procedures. We only claim controls that have actually been implemented and verified.
MeridianAuthZ does not require or store employee passwords. Connections use approved authentication and authorization methods, service identities, application permissions, tokens, or other secure integration mechanisms. The exact connection method is documented during implementation.
Not necessarily. MeridianAuthZ is focused on identities, accounts, roles, groups, permissions, application assignments, and related access information. It requests only the information needed for the agreed governance use case. Any access to additional data is clearly documented and approved.
Customer information is used only to provide, secure, support, and improve the agreed MeridianAuthZ services, according to applicable contracts and privacy policies. Customer data is not sold. Our privacy policy and customer agreement explain how information is collected, used, retained, protected, and deleted.
Retention depends on the service agreement, technical design, regulatory needs, and customer requirements. MeridianAuthZ maintains a documented retention policy describing what information is retained, why, for how long, when it is deleted, and how customers can request deletion where applicable.
MeridianAuthZ supports cloud-hosted deployment, with customer-hosted or hybrid options reviewed during technical consultation. We describe only deployment models that are currently supported, and a technical consultation confirms the right fit.
Pricing and purchasing
MeridianAuthZ pricing is based on the size and needs of your organization. Factors include the number of employees and contractors, number of connected applications, required capabilities, integration complexity, deployment model, reporting needs, implementation services, and support level. A clear scope and price are provided before work begins.
Yes. Organizations can begin with a free 30-minute consultation to discuss their identity environment, employee and contractor access, current manual processes, audit requirements, priority applications, potential access risks, and recommended next steps.
A typical 30-day pilot starts at $2,500 and may range from $2,500 to $7,500, depending on the environment and scope. The final price is confirmed in a written proposal before the pilot begins.
No. Organizations can begin with a focused pilot before committing to an annual subscription. This allows you to evaluate MeridianAuthZ using your own identity environment and selected applications.
The pilot fee may be applied toward the first-year subscription when you proceed with an annual agreement. The applicable credit is confirmed in the pilot proposal.
Installation, configuration, integration, training, and support may be included or priced separately depending on the selected package. The proposal clearly identifies subscription, implementation, connector, custom-development, and support costs, plus any optional services. No additional work is charged without your approval.
No unexpected charges are added after the scope has been approved. Any additional connector, customization, application, or service requirement is discussed and approved before the work begins.
Yes. Organizations can begin with their identity sources and a few important applications, then add more identities, more applications, more access reviews, advanced reporting, additional workflows, custom connectors, privileged-access oversight, and expanded support.
Demo and assessment
Yes. The public live demo uses fictional sample data and allows visitors to explore how MeridianAuthZ can display employees and contractors, former users, accounts, permissions, access risks, administrative access, remediation decisions, and audit evidence. No identity provider account or company data is required.
No. The public demo is a safe, isolated environment using fictional information. It does not connect to your identity provider tenant, access your applications, or modify real accounts.
Yes. The online assessment asks seven business-friendly questions about access visibility, former-employee removal, contractor access, sensitive information, excessive permissions, manual processes, and audit evidence. It provides general guidance and does not inspect your actual identity environment.
No. The online assessment is an educational screening tool based on your answers. It does not verify technical controls, inspect accounts, test systems, guarantee compliance, or replace a formal audit.
Non-human and service identities
Yes, when the relevant account and ownership information is available from connected systems. Service accounts, application accounts, shared mailboxes, automation identities, API credentials, and similar non-human identities often lack a clear owner, never get reviewed, and hold standing access that nobody remembers granting. MeridianAuthZ helps surface these accounts, confirm ownership, document their purpose, and include them in access reviews.
MeridianAuthZ can help identify accounts whose characteristics suggest shared use, such as generic names, multiple associated users, missing individual owners, or sign-in patterns from many sources, when that information is available from connected systems. Shared accounts weaken accountability because actions cannot be reliably traced to one person. Findings are presented for review so your team can replace, restrict, or formally document them.
HR and lifecycle triggers
Yes, when your HR system is connected through a supported integration. An authoritative HR source lets MeridianAuthZ compare employment status against live accounts and permissions, which is what makes former-employee detection, joiner-mover-leaver tracking, and contractor-expiration reviews accurate. If no HR integration is available, employment-status information can also come from your identity provider or a secure file import.
When role or department information is available, MeridianAuthZ can flag permissions that no longer match the person's current responsibilities. Access tends to accumulate quietly when people move: old group memberships stay, project access is never revoked, and temporary approvals become permanent. MeridianAuthZ surfaces these leftover permissions so a manager or application owner can confirm what should stay and what should go.
Comparison and alternatives
Enterprise IGA platforms are powerful but are typically designed for organizations with large budgets, dedicated identity teams, and lengthy implementation programs. MeridianAuthZ focuses on the governance outcomes growing businesses actually need first: seeing who has access, removing former-employee and contractor access, reviewing excessive permissions, and producing audit evidence. The goal is practical time-to-value without a multi-quarter implementation project.
Many businesses try, and it usually works once. The problems appear on the second and third review: exports go stale, nobody remembers which list was final, decisions are not documented consistently, and evidence has to be rebuilt from scratch for every audit. MeridianAuthZ keeps identity and access information current, tracks every review decision, and retains the evidence, so each review starts where the last one ended.
No. MeridianAuthZ gives your IT team or managed service provider the visibility and process they are missing today. They remain in control of decisions and changes; MeridianAuthZ handles the correlation, review organization, reminders, and evidence that are impractical to maintain by hand.
Data residency and migration
Storage location depends on the deployment model selected during implementation. Available hosting and data-residency options are documented and confirmed in your agreement before any data is connected. If your organization has specific residency or sovereignty requirements, raise them during the consultation so the right option can be confirmed.
Your reports, review records, and exportable evidence remain yours. On cancellation, you can request an export of your data, and remaining customer data is deleted according to the documented retention and deletion schedule in your agreement. We do not hold your environment hostage: no proprietary lock-in is required to keep your own audit evidence.
Yes. Because MeridianAuthZ reads from your identity sources and connected applications rather than replacing them, moving from another tool is usually straightforward. Existing review history, evidence, and reports from a previous platform can be retained in your own records, and MeridianAuthZ starts building current, verified evidence from the day it connects.
Support and ongoing operation
Support options include technical assistance, connector troubleshooting, periodic configuration reviews, and help preparing review cycles, depending on the selected plan. Your team also receives administrator guidance so routine operations such as adding an application or launching a review do not require outside help.
It depends on your risk and audit requirements. Many organizations review sensitive and administrative access quarterly and run broader access reviews once or twice a year, with continuous monitoring in between. MeridianAuthZ supports recurring review schedules and keeps the evidence from every cycle organized, so reviews become routine instead of a yearly emergency.
Typically one administrator from IT or operations runs the platform day to day, with managers and application owners participating as reviewers. No dedicated identity team is required. MeridianAuthZ is designed so a small team can operate it alongside their existing responsibilities.
Getting started
The recommended process is: schedule a free 30-minute consultation, discuss your identity environment and priority applications, identify your most important access and audit concerns, confirm supported integrations, define the pilot scope, receive a written proposal, begin the 30-day pilot, review findings and recommendations, and decide whether to continue with an annual subscription.
It is helpful to know which identity providers and directories you use, the approximate number of employees and contractors, the number of business applications, how access is currently granted and removed, whether you have an upcoming audit, which systems contain sensitive information, which access problems concern you most, and who manages your identity environment. Detailed technical information is not required for the first conversation.
Useful participants may include a business owner, IT manager, security leader, identity platform administrator, compliance or audit representative, application owner, or operations leader. Not every role needs to attend the initial discussion.
After the consultation, you may receive a summary of the identified concerns, a recommended pilot scope, a list of proposed systems, integration requirements, an estimated timeline, pricing, implementation responsibilities, and next steps.
Still have questions?

Speak With the MeridianAuthZ Team

Every identity environment is different. Tell us how your organization manages employees, contractors, applications, and audits, and we will help you determine whether MeridianAuthZ is a practical fit.

Keep your systems. Add visibility. Strengthen governance.

Schedule a Free Identity Risk Consultation ▶ Try the Live Demo