Addepar

Addepar

Corma connects to Addepar to control which users see which client portfolios, revoke access when people leave and keep access reviews audit-ready.

The Corma and Addepar integration brings your Addepar users under Corma's identity governance, so operations, IT and compliance teams know who can see which client data and can remove that access the moment it is no longer justified. Addepar is a data and analytics platform for wealth management, used by RIAs, private banks and family offices, and reports more than $9 trillion in assets across 1,500+ clients in over 60 countries.

Key takeaways

  • In Addepar, access is defined by a user's role and by the client portfolios that user is permissioned to see.
  • The riskiest Addepar accounts are administrator or firm-wide accounts that survive a job change or a departure.
  • Corma links Addepar access to HR events and runs periodic reviews that show compliance teams exactly who sees what.

What does access mean in Addepar?

Addepar accounts are not all equal. Each user carries a role, a standard set of permissions for your firm, and a list of permissioned entities: the client portfolios that user can open. Some users are firm administrators, others can see all data. A junior analyst who covered a family office last year may still see its portfolios today, and an advisor who joined a competitor may still have a valid login if offboarding relied on an email to operations.

For wealth managers this is not only an IT topic. Client positions and family structures are among the most confidential data a firm holds, and regulated financial entities in the EU must prove they restrict access to their ICT assets, as our DORA compliance checklist explains.

How Corma governs Addepar access

  • Visibility: every Addepar user appears in Corma next to your other applications, with the access they hold.
  • Offboarding that closes the loop: when an employee leaves, Corma revokes their Addepar access in the same workflow that removes email and CRM, so no orphaned account keeps pointing at client data.
  • Least privilege for joiners: new hires receive the Addepar access defined for their team, in line with the principle of least privilege, and anything wider goes through an approval.
  • Reviews compliance can sign: access review campaigns ask managers to confirm each Addepar user, and Corma keeps the evidence.

The approach fits firms where a handful of administrators manage hundreds of client relationships: access decisions stop living in inboxes and become traceable.

Frequently asked questions

How long does it take to connect Corma to Addepar?

About a minute. An administrator authorizes Corma through a secure OAuth flow, with no code to write, and Corma starts syncing Addepar users right away.

Does Corma replace Addepar single sign-on?

No. Addepar supports SAML single sign-on, which controls how users log in. Corma works on top of it and decides whether each account, and the access attached to it, should still exist.

Where is Corma data hosted?

In France, on AWS infrastructure, with encryption in transit and at rest. Corma only requests the permissions needed to manage access, is ISO/IEC 27001:2022 certified, and the connection can be revoked at any time.

See how Corma supports security and compliance teams, or book a demo to review your Addepar access.

Related Integrations

Check out other integrations that could help you on managing your software licences and accesses!