SAP, Active Directory, Entra ID, SCIM — one lightweight platform to manage users, roles, and compliance. Ships in days. Runs anywhere.
Roles scattered across SAP, AD, Entra. No single view. Drift accumulates silently until the next audit finds it.
Legacy IGA tools need months of consulting, middleware stacks, and six-figure licensing before you see a single dashboard.
Access reviews done in Excel. SoD checks are manual. Reports take weeks to compile. Auditors are not impressed.
Nova is a single Python process backed by PostgreSQL. No app server cluster, no message bus, no Kubernetes required. Install it, connect your systems, start governing.
Native connectors for SAP (RFC), LDAP / Active Directory, Microsoft Entra ID, and any SCIM endpoint. Pluggable — add a new system by dropping in a connector package.
Three-way diff: Nova's desired state vs. each backend's actual state vs. your policies. Catches drift per user, per system, with conflict resolution built in.
Assign a business role → Nova provisions across every linked backend automatically. SAP full-sync via BAPI, LDAP/Entra incremental. Validity windows merge intelligently.
Multi-step approval workflows, self-service access requests, org-based role inheritance, full audit trail. Risk scoring on every role and business role.
Each connector is a self-contained package: connection logic, routes, and background job executors. Adding a fifth system means adding a folder — not refactoring core code.
Nova uses AI for three specific problems where pattern recognition beats manual review. It's not a chatbot strapped onto a dashboard — every AI feature maps to a concrete governance outcome.
Compares each user's entitlements against peers, department baselines, and known SoD matrices. Flags anomalies with scored confidence, not vague warnings.
Apriori frequent-itemset algorithm discovers which roles are always assigned together. Suggests business role candidates from real usage — not from org charts.
Describe the report you need in plain language. Nova generates validated SQL, runs it in a read-only sandbox, and formats the output. Chat to iterate.
Runs on your terms
Local mode via Ollama (air-gapped, no data leaves your network) or cloud mode with Claude / OpenAI. You choose per deployment. Switch at any time.
| Nova | SailPoint | SAP IAG | Okta IGA | |
|---|---|---|---|---|
| Native SAP RFC | Yes | Add-on | Yes | — |
| LDAP + Entra + SCIM | Yes | Yes | — | Yes |
| AI risk analysis & chat | Yes | Limited | — | — |
| AI role mining | Yes | Yes | — | — |
| Air-gapped / on-prem AI | Yes | — | — | — |
| Three-way reconciliation | Yes | Yes | Partial | — |
| Plugin extensibility | Yes | Yes | — | API only |
| Deploy in a day | Yes | — | — | SaaS |
| No per-user licensing | Yes | — | — | — |
| No middleware / app server | Yes | — | — | SaaS |
Vanilla JavaScript SPA. No React, no build step, no node_modules. Loads in any browser, works offline.
Python / Flask with modular blueprints. Connector packages for each system type. Plugin system for extensions. MCP tool bridge for AI integration.
PostgreSQL with auto-migrating schema. 19 tables. JSONB for flexible configs. No ORM — direct queries, full control.
No per-user fees. No hidden costs. Pick the model that fits your organisation.
Ideal for organisations willing to adopt early and provide feedback. Limited spots.
For teams that run their own infrastructure and want predictable costs.
For organisations that want to be productive from day one with expert guidance.
No six-month rollout. No middleware. No per-seat ransom.
Just the IAM tool your team will actually use.