Managed Access Operations

Managed Access Operations

People get the right access when they join, and lose it when they leave. REX5 sets up and runs onboarding, offboarding, permissions, and access reviews across your agency’s agreed tools.

One owner for the access workflow.

For growing remote agencies with staff and freelancers across several business tools. Your agency approves access decisions; REX5 carries them out and records the result.

Join, move, leave

Accounts, groups, role changes, permissions, and verified offboarding across your named systems.

Clean up and document

Initial system and account inventory, agreed cleanup, current procedures, and periodic access reviews with actions and owners.

Automate and check

Reusable role templates and supported integrations handle routine changes. Failed approvals or integrations go to a human for follow-up.

The tech stack we manage.

From everyday collaboration to cloud platforms, we manage accounts, permissions, and access across the tools your team uses.

Productivity suites
  • Google Workspace
  • Microsoft 365
Communication
  • Google Meet
  • Slack
  • Microsoft Teams
Projects & knowledge
  • Jira
  • Confluence
  • Notion
Code collaboration
  • GitHub
  • GitLab
Password managers
  • Keeper
  • LastPass
  • 1Password
  • NordPass
Websites & commerce
  • WordPress
  • Shopify
AI tools
  • ChatGPT
  • Claude
  • Gemini
Cloud
  • AWS
  • Google Cloud
  • Azure
Hosting
  • Hostinger
  • SiteGround
  • Bluehost
Domains & DNS
  • Cloudflare
  • GoDaddy

We agree the specific services or tenants covered before work starts. The monthly plan includes up to eight named systems from your stack; software subscriptions are paid separately. SSO and automation depend on each platform’s capabilities and your subscription plan.

From scattered accounts to a repeatable routine.

  1. 01

    Agree coverage

    Name the systems, people, approval contact, service hours, and escalation path.

  2. 02

    Inventory and clean up

    Map accounts and owners. Resolve agreed access gaps and document the starting point.

  3. 03

    Set up the workflow

    Configure role templates, agreed SSO and MFA, approvals, and supported account integrations.

  4. 04

    Operate and review

    Capture each request once, apply approved changes, verify departures, and keep procedures current.

Supporting services. No separate REX5 fee.

Your password manager, or our vault

Keep your existing password manager or select a REX5-hosted Vaultwarden organization, with setup and migration included. Hosted activation requires verified backups, a tested restore path, client isolation, and organization export access.

REX5 SSO

The optional REX5-operated identity provider at sso.rex5.com is included for agreed integrations, subject to onboarding validation. You can keep your current provider. App capabilities and subscription plans determine where SSO works; you choose whether to upgrade.

MonitorSpider

Agreed checks and alert routing are included without a separate fee. MonitorSpider remains an independent platform. We define checks and response owners during onboarding; continuous monitoring does not mean 24/7 human response.

SSO authenticates a person. The managed access workflow separately creates and removes accounts where provisioning is needed. REX5 validates customer isolation, application trust, sign-in, loss of access, and recovery before activating hosted SSO.

One monthly price for managed access.

Managed Access Operations

$2,400/month

Up to 50 managed identities and eight named systems. Billed monthly in USD.

No setup fee. No per-task or per-user REX5 fee inside this band.

Initial cleanup and ongoing work included.

Inventory, agreed cleanup, procedures, routine access changes, SSO configuration, optional hosted vault setup and migration, and initial agreed MonitorSpider checks all belong in the monthly fee. Your agency pays its own SaaS subscriptions and optional plan upgrades.

Six-month initial term, then monthly with 30 days’ notice. The quoted service price is held for the initial term. Coverage changes are repriced only at renewal or by an agreed amendment, never retroactively.

Larger team: fixed quote. We agree a monthly price for a defined identity and system range before work starts. Fifty identities is a price band, not a service capacity limit.

Coverage you can point to.

People and systems

A managed identity is a staff member or freelancer whose access REX5 administers. A named system is a specific agreed tenant or service, such as Google Workspace, Slack, GitHub, a password manager, or DNS. The agreement lists the systems and your approval contact. Standard DNS record changes are included when DNS is a named system.

Business-hours response

Human support operates during agreed business hours. Before you sign, the service agreement must specify working days, time zone, holiday coverage, acknowledgement targets for routine requests and urgent leavers, and the escalation contact and channel. These service hours and numeric targets are not yet published; obtain the written schedule before starting. Acknowledgement is not a guaranteed resolution time: approvals, application capabilities, and third-party availability can affect completion.

Scope changes, without surprise bills

Routine requests within coverage have no hidden time allowance or hourly charge. For exceptional request volume, a materially larger team, or unusually complex integration, we agree capacity and any scope amendment before extra work begins.

Separate work

Large migrations, custom application development, major infrastructure changes, and unusually complex integrations require a separate fixed quote. Formal audits, certifications, penetration testing, 24/7 incident response, hardware procurement, and general employee helpdesk are excluded unless separately agreed.

Questions before we start.

Is there a setup fee?

No. Initial inventory, agreed access cleanup, and operating procedures are included.

What happens when we add another tool?

Routine access integration and documentation are included while you remain within the agreed eight-system band. A security or scaling review is a separate fixed-price choice.

Does SSO require app upgrades?

Some apps restrict SSO to certain plans. Your agency chooses whether to upgrade and pays the subscription cost. SSO is optional for that app.

Must we use REX5 SSO?

No. sso.rex5.com is an optional identity provider for managed customers, subject to integration validation. You can keep your existing identity provider.

Can we keep our password manager?

Yes. We administer the agreed password manager. The REX5-hosted vault is an included option, not a required migration.

What happens if we leave?

You retain your domains, subscriptions, data, and primary administrative authority. You can export organization vault data. REX5 supplies existing documentation and access for handover; the incoming provider performs migration and new implementation. An export does not automatically migrate every item.

Does monitoring mean 24/7 response?

Checks and alerts run continuously. Human response follows the business hours and escalation path in your agreement. On-call coverage requires a separate arrangement.

Do you provide an employee IT helpdesk?

No. We handle access requests and failures for agreed systems. Device issues, general application troubleshooting, and everyday employee IT support are outside this service.

Tell me about your team.

Email your team size, primary tools, approximate joiner/leaver frequency, and main concern. Sebastian will reply with scoping questions and a next step. A call is optional.

Email Sebastian about your team ↗

No mail app? Write to sebastian@rex5.com.