IT Workflow Builder
Build custom IT Ops automations at scale with enterprise-grade security
Shadow AI
Spot Shadow AI and NHIs before the breach
Zero-Touch Provisioning
Automated JML along the identity lifecycle: right access day 1, updated permissions for movers and clean off-boardings
Role-based Access control
Enforce least privilege with Identity Governance to pass any audit
Self-serve Access
Self-serve app store with RBAC & LPAM approval flows
Security audits & reviews
Automated access reviews & time-bound access for ISO 27001 and SOC 2 compliance
Spend management
Manage software & contract lifecycle for optimized IT spend
Finance
Track spend, renewals, and chargebacks
HR
Onboard and offboard employees in one click
IT
Centralize apps and automate access
Security
Enforce least-privilege and streamline audits
Discovery & Observability
Spot and monitor all software and AI usage
Shadow AI Detection
Spot risky agents and NHIs before they become a breach
Identity Lifecycle Management
Instant access with Joiner Mover Leaver workflows
RBAC & IGA Policy enforcement
Access control through a smart Identity Governance layer
App store & Access approval flows
Manage Access Requests through self-service & smart approval processes
SaaS Management
Manage SaaS & AI on application, subscription and licence level
Custom IT Ops automations at scale
Limitless AI Automation
Automations and actions beyond APIs with browser-based agents
Integrations
Connect all your apps in an instant through API or Agent
Changelog
Discover all the new features and much more in our Corma changelog!
Calculator
Estimate your savings with Corma
Community calendar
Join us for live events and demos
FAQs
Answers to your key questions
About us
The team and vision behind Corma
Press
The latest news
Video Center
Watch instead of read
Careers
Join the team
Partners
Leverage Corma for your business
Definitions with examples on the most common terms in IT.
HRIS integration makes the HR system the trigger for IT access. Learn how it works and why contractors stay invisible to every automation built on it.
Employee onboarding takes a new hire from contract to productive. Learn what the IT half involves and why day-one access still slips so often.
Just-enough-access limits every account to the exact permissions its task needs. Learn how JEA works and why it only pays off paired with JIT access.
Break glass access is the emergency account used when normal login fails. Learn how to design it, protect it, and keep it out of your audit findings.
Access governance is the discipline of proving who has access to what and why. Learn what it covers and how it differs from access management.
Privilege creep is the slow build-up of access rights as employees change roles. Learn why internal movers are the blind spot and how to reverse it.
Fine-grained access control decides permissions at record and field level. Learn how it works, what it costs to run, and when coarse control is enough.
Just-in-time access grants elevated rights only when needed, then revokes them. Learn how JIT access works and how it differs from JIT provisioning.
Privilege escalation turns limited access into control. Learn the vertical and horizontal types, and the SaaS path most mid-market teams miss.
Mandatory access control (MAC) enforces access through central classification labels. Learn how it works and how it differs from DAC and ABAC.
Discretionary access control (DAC) lets the resource owner decide who gets in. Learn how DAC works and why your SaaS stack runs on it by default.
An access control list (ACL) defines who can reach a resource and what they can do with it. Learn how ACLs work and why they stop scaling in SaaS.
Adaptive authentication adjusts login requirements to real-time risk signals. Learn which signals matter, how it works, and where it has no visibility.
A directory service is the central store of identities and groups in an IT estate. Learn how it works and why it is not SaaS access governance.
Biometric authentication verifies identity with a fingerprint or face. Learn how it works, what GDPR Article 9 requires, and where the data lives.
RADIUS authenticates users to Wi-Fi, VPN, and network gear. Learn how the protocol works, why it persists, and the offboarding gap it creates.
WebAuthn is the W3C browser API behind passkeys and FIDO2 logins. Learn how it works, how it differs from FIDO2, and what it covers in a SaaS stack.
FIDO2 is the open standard behind passkeys and security keys. Learn how it blocks phishing, what WebAuthn and CTAP do, and where to deploy it first.
TOTP is the six-digit code produced by authenticator apps. Learn how the algorithm works, what it protects against, and where phishing defeats it.
A JSON Web Token (JWT) is a signed token carrying identity claims between systems. Learn its structure, its role in SSO, and its offboarding risk.
Microsoft Entra ID, formerly Azure AD, is Microsoft's cloud identity service. Learn how it works and where SaaS access still escapes its policies.
Active Directory is Microsoft's on-premises directory service for Windows identities. Learn how AD works and where it stops covering your SaaS apps.
AI agent governance applies access controls and oversight to autonomous AI agents. Learn what it covers, why it matters, and how it extends IAM.
A machine identity authenticates non-human entities like servers and services. Learn how they work, how they differ from NHIs, and why governance matters.
A non-human identity (NHI) is a digital identity for a machine, service, or AI agent. Learn what NHIs are, why they grow, and why they need governance.
An orphaned account is an active account with no owner. Learn why orphaned accounts are a security risk and how clean deprovisioning eliminates them.
An audit trail is a chronological record of who did what, when. Learn how audit trails work, what they record in IAM, and why compliance needs them.
Data sovereignty means data is governed by the laws of where it is stored. Learn how it differs from data residency and why it shapes vendor choice.
EU data residency means storing and processing data inside the EU. Learn what it is, how it supports GDPR, and why European buyers require it.
A Software Bill of Materials (SBOM) is an inventory of all components in software. Learn what an SBOM contains, why it matters for supply-chain security.
SOC 2 is a framework for managing customer data on five trust principles. Learn how SOC 2 works, SOC 2 vs ISO 27001, and what a report proves.
The NIS2 Directive strengthens EU cybersecurity rules for essential and important entities. Learn its scope, requirements, and how to comply.
Renewal management tracks software renewals so none auto-renew unchecked. Learn how it works, why it prevents waste, and how Corma surfaces renewals early.
Vendor consolidation reduces software vendors to cut cost and complexity. Learn how it works, its benefits, and how it fits SaaS spend optimization.
Application rationalization reviews your apps to keep, consolidate, or retire them. Learn how it works, the framework, and how it tackles SaaS sprawl.
Software Asset Management (SAM) governs software across its lifecycle. Learn how SAM works, how it relates to SaaS management, and why it matters.
License reclaim recovers unused or departed-user seats. Learn how reclamation works, what triggers it, and how Corma automates it to cut spend.
Software license management tracks and optimizes software licenses across a company. Learn how it works, why it cuts cost, and how Corma automates it.
SaaS discovery finds every app in use, including shadow IT. Learn how SaaS discovery works, its data sources, and why it underpins SaaS control.
Shadow AI is the unsanctioned use of AI tools by employees. Learn the risks of shadow AI, why it differs from shadow IT, and how to bring it under control.
Shadow IT is software used without IT approval. Learn what shadow IT is, the risks it creates, and how SaaS discovery brings it under control with Corma.
SaaS sprawl is the uncontrolled growth of SaaS apps across a company. Learn its causes, risks, and how to regain control with SaaS discovery and Corma.
Entitlement management governs the fine-grained permissions users hold in apps. Learn how it works, how entitlements relate to roles, and why it matters.
Access certification is the documented sign-off proving access was reviewed. Learn how it works, how it differs from reviews, and why auditors need it.
An access review checks that user access is still appropriate. Learn how access reviews work, review vs certification, and how Corma automates them.
Identity lifecycle management governs access from onboarding to offboarding. Learn its stages, how it links to JML, and how Corma automates it.
The Joiner-Mover-Leaver (JML) process manages access across the employee lifecycle. Learn how JML works, its three stages, and how Corma automates it.
Just-in-time (JIT) provisioning creates accounts the moment access is needed. Learn how JIT works, JIT vs standing access, and how it supports Zero Trust.
Deprovisioning removes user access when people leave or change roles. Learn the risks of poor deprovisioning, best practices, and how Corma automates it.
User provisioning creates and manages accounts and access across apps. Learn how provisioning works, manual vs SCIM vs JIT, and how Corma automates it.
Federated identity lets one identity access systems across domains. Learn how identity federation works, federation vs SSO, and where it fits in IAM.
An identity provider (IdP) authenticates users and issues trusted tokens to apps. Learn how an IdP works, IdP vs SP, and how Corma governs IdP access.
Separation of Duties (SoD) splits critical tasks across people to prevent fraud. Learn how SoD works, common conflicts, and how Corma detects them.
Zero Trust is a security model built on "never trust, always verify." Learn its core principles, how it works, and how access control fits in.
The principle of least privilege grants only the minimum access needed. Learn how least privilege works, why it matters, and how Corma enforces it.
Policy-Based Access Control (PBAC) governs access through central policies that blend roles and attributes. Learn how PBAC works and compares to RBAC.
Attribute-Based Access Control (ABAC) grants access using attributes and context. Learn how ABAC works, ABAC vs RBAC, and when to use each model.
Role-Based Access Control (RBAC) grants permissions by role, not per user. Learn how RBAC works, RBAC vs ABAC, and how it supports least privilege.
Customer Identity and Access Management (CIAM) manages external customer identities at scale. Learn how CIAM works and how it differs from workforce IAM.
Privileged Access Management (PAM) secures and monitors high-level access to critical systems. Learn how PAM works, PAM vs IGA, and why it matters.
Identity Governance and Administration (IGA) ensures access is appropriate and auditable. Learn how IGA works, IGA vs PAM, and how Corma automates it.
Identity and Access Management (IAM) controls who can access what. Learn the pillars of IAM, how it differs from IGA, and how Corma delivers it for SaaS.
A passkey is a phishing-resistant credential that replaces passwords using FIDO2 and WebAuthn. Learn how passkeys work and why adoption is accelerating.
Passwordless authentication verifies identity without a password, using biometrics, passkeys, or magic links. Learn how it works and why it matters.
Kerberos is a network authentication protocol using tickets and a trusted KDC. Learn how Kerberos works, where it is used, and how it relates to IAM.
LDAP is a protocol for querying and managing directory services like Active Directory. Learn how LDAP works, where it is used, and how it relates to IAM.
OpenID Connect (OIDC) adds an identity layer on top of OAuth 2.0. Learn how OIDC works, how it compares to SAML, and where it fits in modern SSO.
OAuth 2.0 is the standard for delegated authorization. Learn how OAuth 2.0 works, how it differs from OIDC and SAML, and why it matters for SaaS access.
SCIM automates user provisioning and deprovisioning across apps. Learn how SCIM works, how it differs from SAML, and how Corma extends it to every app.
SAML is an XML standard for exchanging authentication data and enabling SSO. Learn how SAML works, how it differs from SCIM, and where Corma fits in.
Multi-Factor Authentication (MFA) verifies identity with two or more factors. Learn how MFA works, its types, and how it fits IAM compliance with Corma.
Single Sign-On (SSO) lets users access multiple apps with one login. Learn how SSO works, its benefits, and how Corma governs SSO access at scale.