{"id":50454035,"url":"https://github.com/mizcausevic-dev/entra-access-review-control-plane","last_synced_at":"2026-06-01T01:05:35.077Z","repository":{"id":360550972,"uuid":"1250665946","full_name":"mizcausevic-dev/entra-access-review-control-plane","owner":"mizcausevic-dev","description":"Operator control plane for Microsoft Entra access reviews, privileged-role decisions, stale approvals, and identity-governance remediation posture.","archived":false,"fork":false,"pushed_at":"2026-05-26T22:20:41.000Z","size":291,"stargazers_count":0,"open_issues_count":4,"forks_count":0,"subscribers_count":0,"default_branch":"main","last_synced_at":"2026-05-26T23:22:14.236Z","etag":null,"topics":["access-review","azure","azure-ad","entra","identity-governance","intune","microsoft-365","platform-engineering","privileged-access","security-operations","typescript"],"latest_commit_sha":null,"homepage":"https://kineticgain.com/","language":"TypeScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"agpl-3.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/mizcausevic-dev.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2026-05-26T21:20:19.000Z","updated_at":"2026-05-26T22:20:43.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/mizcausevic-dev/entra-access-review-control-plane","commit_stats":null,"previous_names":["mizcausevic-dev/entra-access-review-control-plane"],"tags_count":2,"template":false,"template_full_name":null,"purl":"pkg:github/mizcausevic-dev/entra-access-review-control-plane","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mizcausevic-dev%2Fentra-access-review-control-plane","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mizcausevic-dev%2Fentra-access-review-control-plane/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mizcausevic-dev%2Fentra-access-review-control-plane/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mizcausevic-dev%2Fentra-access-review-control-plane/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/mizcausevic-dev","download_url":"https://codeload.github.com/mizcausevic-dev/entra-access-review-control-plane/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mizcausevic-dev%2Fentra-access-review-control-plane/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":33755379,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-26T15:22:16.424Z","status":"online","status_checked_at":"2026-05-31T02:00:06.040Z","response_time":95,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["access-review","azure","azure-ad","entra","identity-governance","intune","microsoft-365","platform-engineering","privileged-access","security-operations","typescript"],"created_at":"2026-06-01T01:05:35.008Z","updated_at":"2026-06-01T01:05:35.072Z","avatar_url":"https://github.com/mizcausevic-dev.png","language":"TypeScript","funding_links":[],"categories":[],"sub_categories":[],"readme":"# Entra Access Review Control Plane\n\n[![CI](https://github.com/mizcausevic-dev/entra-access-review-control-plane/actions/workflows/ci.yml/badge.svg)](https://github.com/mizcausevic-dev/entra-access-review-control-plane/actions/workflows/ci.yml)\n[![License: AGPL v3](https://img.shields.io/badge/License-AGPL_v3-blue.svg)](./LICENSE)\n[![Deploy](https://github.com/mizcausevic-dev/entra-access-review-control-plane/actions/workflows/pages.yml/badge.svg)](https://github.com/mizcausevic-dev/entra-access-review-control-plane/actions/workflows/pages.yml)\n\nOperator control plane for Microsoft Entra access reviews, privileged-role decisions, stale approvals, and identity-governance remediation posture.\n\n## Why this exists\n\n- Enterprise teams need more than a raw Microsoft Graph export when audits, access reviews, and remediation timing collide.\n- Access-review operators need one surface that shows overdue privileged decisions, self-reviews, auto-approvals, stale-but-not-applied changes, and review ownership.\n- Recruiters and buyers looking for `Azure / Microsoft 365 / Entra / Intune` proof should see an admin/operator dashboard, not a cloud tutorial.\n- Identity governance work is most valuable when it becomes a visible release and remediation system for platform, security, and audit teams.\n\n## Why this matters (KG Embedded tie-back)\n\nThis repo demonstrates the identity-governance control-plane primitive for Microsoft tenant operations: access reviews, privileged-role risk, stale application posture, and buyer-readable remediation packets in one operator surface. Kinetic Gain Embedded extends this pattern into productized in-app dashboards where security, audit, and platform signals need to be visible without exposing unsafe write paths or tenant secrets. See [kineticgain.com/embedded](https://kineticgain.com/embedded).\n\n## What it shows\n\n- review-lane visibility for Entra access-review instances and ownership\n- privileged-role risk detection using Microsoft role template ids\n- stale decision and overdue closeout posture\n- remediation packets for privileged access, guest access, and app-consent review flows\n- offline-safe analysis of captured Microsoft Graph exports\n\n## Routes\n\n- `/`\n- `/review-lane`\n- `/access-risks`\n- `/remediation-posture`\n- `/verification`\n- `/docs`\n\n## API\n\n- `/api/dashboard/summary`\n- `/api/review-lane`\n- `/api/access-risks`\n- `/api/remediation-posture`\n- `/api/verification`\n- `/api/sample`\n\n## Screenshots\n\n![Overview](./screenshots/01-overview-proof.png)\n![Review lane](./screenshots/02-review-lane-proof.png)\n![Access risks](./screenshots/03-access-risks-proof.png)\n![Remediation posture](./screenshots/04-remediation-posture-proof.png)\n\n## Local Development\n\n```powershell\ncd entra-access-review-control-plane\nnpm install\nnpm run dev\n```\n\nOpen:\n- [http://127.0.0.1:5511/](http://127.0.0.1:5511/)\n- [http://127.0.0.1:5511/review-lane](http://127.0.0.1:5511/review-lane)\n- [http://127.0.0.1:5511/access-risks](http://127.0.0.1:5511/access-risks)\n- [http://127.0.0.1:5511/remediation-posture](http://127.0.0.1:5511/remediation-posture)\n- [http://127.0.0.1:5511/verification](http://127.0.0.1:5511/verification)\n\n## Validation\n\n- `npm run lint`\n- `npm run typecheck`\n- `npm run coverage`\n- `npm run build`\n- `npm run demo`\n- `npm run smoke`\n- `npm run prerender`\n- `npm run render:assets`\n\n## Production status\n\n| Aspect | Status |\n|--------|--------|\n| CI | Node 20 + 22 matrix — lint · typecheck · coverage · build · demo · smoke · `npm audit` |\n| License | [AGPL-3.0-or-later](./LICENSE) |\n| Deploy | Static prerender -\u003e **https://entra.kineticgain.com/** |\n| Data posture | Synthetic sample data only; no tenant credentials or live Graph tokens |\n| Suite | Part of the [Kinetic Gain Protocol Suite](https://suite.kineticgain.com/) operator portfolio · apex: [kineticgain.com](https://kineticgain.com) |\n\n## Docs\n\n- [Architecture](./docs/architecture.md)\n- [Origin](./docs/ORIGIN.md)\n- [Kinetic Gain Embedded tie-back](./docs/KINETIC_GAIN_EMBEDDED.md)\n- [Changelog](./CHANGELOG.md)\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmizcausevic-dev%2Fentra-access-review-control-plane","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fmizcausevic-dev%2Fentra-access-review-control-plane","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmizcausevic-dev%2Fentra-access-review-control-plane/lists"}