Skip to main content
FORTISEU
Legal

Legal & Compliance

Transparency is the foundation of trust. Review our legal documents, data processing agreements, and compliance commitments.

All AI Systems

Access Review AI Recommendations

High Risk — Art. 6 + Annex III

Risk Classification Rationale

This AI system recommends approve/revoke/flag decisions for identity access reviews, directly affecting employee and contractor access rights to essential work systems.

EU AI Act: Category 4(a) — Employment, workers management, access to self-employment

Purpose

Generate non-binding access review recommendations to assist human reviewers in identity governance campaigns. Analyzes peer group prevalence, entitlement risk levels, segregation of duties conflicts, and dormancy.

Input Data

  • Identity entitlements and assignments
  • Identity profiles (department, role)
  • Access review item metadata
  • Entitlement risk levels
  • Segregation of Duties violation flags
  • Peer group prevalence statistics

Output Data

  • Recommendation per item: approve, revoke, or flag for review
  • Confidence score (0-100%)
  • Natural language rationale

Model & Processing

Provider
Mistral AI (France, EU)
Model
mistral-large-latest
Processing Location
France (EU)

Known Limitations

  • !Cannot assess business context for legitimate exceptions
  • !Peer group analysis depends on accurate department/role data
  • !Confidence scores are not calibrated probabilities
  • !Small peer groups (<5 members) produce unreliable statistics

Fairness Measures

  • +Monthly automated bias audits measuring demographic parity and disparate impact ratio
  • +Override rate monitoring by department and role group
  • +Minimum cohort size (5 profiles) for peer group analysis
  • +Action threshold: >10% deviation triggers investigation

Human Oversight

Human reviewer must explicitly approve or reject each access review item. AI recommendation is non-binding and displayed alongside raw entitlement data. Overrides require documented reason and are logged for audit.

Appeal Process

Any person affected by an AI-assisted access decision may request human-only review via the Appeal button. Appeals are assigned to the compliance team and resolved within 14 days. The reviewer reassesses without AI recommendation visible.

Data Governance

Recommendations cached for 90 days after access review completion, then purged. No customer data used for model training. All processing in France (EU). Tenant-isolated via row-level security.

AI System Card · EU AI Act (Regulation (EU) 2024/1689) · Articles 11, 13 · Last updated: March 2026