OnDemand Access is a secure temporary access management solution that enables organisations to create and manage groups of accounts for time-bound access to systems, applications, and environments.
The platform supports on-premises Active Directory, Microsoft Entra ID, or a hybrid model, allowing businesses to provision and control temporary user access in the way that best fits their infrastructure. These accounts can be assigned to specific groups, roles, or access profiles and used for scenarios such as contractor access, project-based access, emergency elevated permissions, testing, training, or short-term operational needs.
OnDemand Access helps organisations improve security and governance by ensuring temporary accounts are created in a controlled manner, approved where required, and removed or disabled automatically when no longer needed. This reduces the risks associated with shared accounts, excessive standing privileges, and forgotten temporary access.
Key benefits of the solution include:-
In essence, OnDemand Access gives organisations a smarter, safer, and more efficient way to manage temporary access across their estate.
The platform supports a structured role-based access model to ensure clear separation of responsibilities, strong governance, and controlled administration across the solution. Key roles include Platform Administrators, who manage the overall system configuration and governance; Group Administrators, who oversee specific account groups and their associated settings; Requesters, who submit access requests; Approvers, who review and authorise requests in line with organisational policy; and Auditors, who have visibility of reporting, activity history, and compliance-related records for assurance and oversight purposes
The solution includes a core set of mandatory fields to ensure consistent data capture across all requests, while also providing the flexibility to configure additional custom fields through the admin portal. Administrators can define organisation-wide custom fields as needed, and can also assign bespoke fields at individual group level, allowing each group to capture information that is specific to its own access, process, or compliance requirements. This gives organisations a highly adaptable request framework without losing standardisation or administrative control.
Every action within the solution is fully audited, providing complete end-to-end traceability across the lifecycle of each account and request. This includes visibility from the original requester, through approval and provisioning, to the individual who ultimately accessed and used the account. The platform also includes comprehensive reporting capabilities to support operational oversight, compliance monitoring, and investigation requirements. In addition, the solution is designed with full GDPR considerations in mind, helping organisations meet data protection obligations through detailed audit records, controlled access to information, and robust governance over account usage and activity.
Through the worker agent, the solution can securely integrate with on-premises Active Directory to create, update, and decommission user and group objects as required. This enables automated identity lifecycle management, helping organisations maintain accurate directory data, streamline administration, and ensure that account and group changes are applied consistently and efficiently in line with operational processes.
The solution allows administrators to define and manage account availability periods at group level, enabling each group to have its own tailored access window. This provides greater operational flexibility and control, ensuring that temporary accounts are only available for the required duration in line with business, security, and compliance requirements.
The solution includes a comprehensive monitoring and dashboard capability that provides clear visibility into overall system activity, operational status, and key platform events. Through a centralised dashboard and dedicated monitoring screens, administrators can track what is happening across the environment in real time, review system health, monitor processing activity, and quickly identify issues or exceptions. This supports proactive management of the platform, improves operational oversight, and helps ensure the service remains reliable, transparent, and well governed.
The solution is accessed through a secure web interface, delivered as an Azure Web App hosted within the organisation’s own environment. It can be made available exclusively to internal networks, or securely exposed for wider access where required, providing a flexible front-end that aligns with the organisation’s security and access policies.
The solution’s backend is powered by Microsoft SQL, with flexible deployment options to suit organisational requirements. It can be hosted either in an Azure SQL Database for cloud-based scalability and resilience, or on a local SQL Server instance for on-premises control and integration.
The service can be deployed on any Windows Server environment, either alongside other applications or on a dedicated server, depending on organisational preference. Its only prerequisite is the .NET 10 Runtime, making deployment simple, lightweight, and easy to standardise.
The solution is a managed solution which is hosted by the customer, all cost for the hosting is paid for by the customer directly, cost for the solution and support/upgrades depends on the total groups/users needed.
Estimated cost for 5 groups and 200 users is £10,000 per year