Access provisioning from 3 days to 11 minutes at a Fortune 500
A Fortune 500's access-request workflow took 3 business days on average and produced a chronic tail of standing, over-privileged entitlements auditors kept flagging. pronix.ai built an agentic provisioning workflow that resolves standard requests in 11 minutes, applies least-privilege by default, and gave the SOX team a clean audit for the first time in four years.
- Client
- Fortune 500 diversified holdings company
- Industry
- Enterprise
- Platform
- Kore.ai Agent Platform · SailPoint · Okta · ServiceNow · Microsoft Entra ID
*Representative outcome; results vary by client, scope and platform configuration.
The challenge
45,000 access requests per year moved through a manual approval chain averaging 3.2 business days end-to-end. Approvers rubber-stamped 92% of requests, over-privileged entitlements accumulated, and SOX audits produced repeat findings on segregation of duties. Prior RPA attempts brittle-failed the moment a new app or role appeared.
Our approach
Policy-as-code entitlement catalog
Codified the entitlement catalog with role, app, risk tier and required approver policy — the agent consulted policy instead of improvising, and any policy change was reviewable in Git.
Agentic request → provision workflow
The agent interviewed the requester in Teams, resolved role and app to a catalog entry, checked segregation-of-duties conflicts against SailPoint, and either auto-provisioned via Okta / Entra or routed to the correct approver — no more generic 'IT approval' queues.
Least-privilege by default with time-bound access
Elevated entitlements defaulted to time-boxed grants with automatic revocation. Standing privileged access dropped 71% without a single project ticket.
Immutable audit trail wired for SOX
Every decision — agent, policy version, approver, evidence — logged to ServiceNow and mirrored to the audit warehouse in an append-only structure the auditors reviewed directly.
HITL for high-risk and privileged joiners
Anything above the risk threshold, plus every privileged-role joiner, held for a named human approver with a pre-built context view — approvals took under a minute instead of a day.
Ongoing entitlement review by the agent
Quarterly access reviews were run by the agent — draft revocation lists prepared, manager sign-off collected in Teams, revocations executed on approval. Review cycle went from 6 weeks to 4 days.
“The audit committee stopped asking about access controls. That is a first for us — and it is because the workflow is explainable to a human, not because a model is clever.”
Illustrative case study. Scenarios, metrics, quotes and client details are representative composites based on Pronix engagements and industry benchmarks unless a named client is shown with written consent. Outcomes vary by client, scope, data quality and platform configuration. Nothing on this page is a guarantee, warranty or professional advice. See our Terms of Use for the full disclaimer.
AWS, Salesforce, Microsoft, NICE, Genesys, Kore.ai, Google, ServiceNow, Amazon Connect and logos referenced on this site are trademarks of their respective owners. References are for descriptive purposes only and do not imply endorsement, sponsorship or partnership beyond stated partner relationships. See our Disclosures.
Talk to the team that shipped it.
Book a working session with a pronix.ai lead on this practice — we'll map the approach to your platform, industry and constraints.