Discovery notes in. Build-ready specs and config out.
Keyscribe is an AI business analyst for identity governance teams. Paste the notes from an application discovery call and get the spec, the Terraform variables and the UAT cases, with every gap flagged before build starts.
Discovery notes
Fleetdesk call w/ app owner. Postgres backend, JDBC ok? Accounts keyed on emp number. Roles = viewer, dispatcher, admin. Leavers: disable, delete keep for audit 90d. Admin approver TBC. Contractors… not sure, ask HR.
Built for teams onboarding applications to SailPoint Identity Security Cloud and IdentityIQ. Fleetdesk is a fictional example.
Everything the build team needs, in one spec
Discovery calls produce half-answers scattered across notes and transcripts. Keyscribe pulls them into the structure an identity engineer actually works from, and tells you exactly what is still missing.
- Source and connector
- Connector type, connection approach and aggregation scope, with assumptions marked.
- Account schema and correlation
- Native identity, key attributes and how accounts match identities.
- Entitlements and access profiles
- What can be requested, who owns it and who approves it.
- Joiner, mover, leaver
- What should happen to accounts at each lifecycle event, including retention.
- Gaps and contradictions
- Missing owners, unclear scope and conflicting answers, phrased as questions to send back.
- Draft UAT cases
- Test cases derived from the spec, ready for the test lead to refine.
Running onboarding as config as code?
Keyscribe gathers requirements in the shape your pipeline needs. Alongside the readable spec, you get a structured version that can sit in Git and feed your existing Terraform modules, instead of being retyped by hand.
Values are checked against your naming conventions and ownership rules before anything reaches a pull request, so reviewers spend their time on design, not typos.
Credentials are never captured. Specs only reference your secret store.
# fleetdesk.auto.tfvars (generated by Keyscribe)
access_profiles = [
{
name = "Fleetdesk - Dispatcher"
source = "fleetdesk-jdbc"
entitlement = "dispatcher"
owner = "ops-dispatch-lead"
requestable = true
},
{
name = "Fleetdesk - Admin"
source = "fleetdesk-jdbc"
entitlement = "admin"
owner = null # gap: approver not named
requestable = false
}
]
Illustrative output for a fictional application.
Nothing stored. By design.
Discovery notes contain system names, owners and access decisions. Keyscribe is built for teams who can't paste that into any tool that keeps it.
- Processed in your session, not retainedNotes and specs live in your browser session and disappear when you close it.
- Never used for trainingYour content is not used to train AI models, ours or anyone else's.
- No credentials, everSpecs reference secret stores; passwords and keys are never requested or written down.
- This website tracks nothingNo cookies, no analytics, no third-party scripts. Read the privacy notice.
Join early access
We're working with a small group of delivery leads, architects and BAs who onboard applications every month. Bring an anonymised set of discovery notes and see what Keyscribe makes of them.
Or email [email protected]