What is Nova
Nova IAM is an Identity & Access Management platform. Nova manages identities – people, technical identities and AI agents –, their accounts in the connected target systems and the entitlements they hold there. Nova grew out of decades of practice with SAP Identity Management.
What Nova does
- Lifecycle: Nova takes over personnel data from the HR system and handles joiners, movers, leavers and rehires through configurable routines – see HR integration and Joiners, movers, leavers.
- Access model: entitlements from the target systems can be bundled into business roles and assigned to identities, organisational units or positions – see Access model.
- Access requests: requests for entitlements and business roles go through defined approval workflows – see Requesting access.
- Provisioning and reconciliation: Nova creates accounts in the target systems, transfers entitlements, locks accounts and compares the state in Nova with the state in the target system – see How access is granted and removed.
- Governance: recertification, segregation of duties (SoD) and risk assessment.
- Traceability: audit log, provisioning log and change journal.
Architecture
| Building block | Purpose |
|---|---|
| Web interface | used in the browser, in German and English; nothing to install on workstations |
| Application | Python application (Flask) holding the business logic: checks permissions, runs procedures, writes logs and provides the interface the web UI works with |
| Database | PostgreSQL for identities, roles, assignments, configuration and history; Nova updates the schema itself on start-up |
| Connectors | target systems SAP (via RFC), Active Directory and LDAP, Microsoft Entra ID, Keycloak and SCIM; source systems “Nova HR Stage” for personnel data and “SAP OM” for the organisational structure – see Target systems overview |
| Background jobs | scheduled tasks with a cron schedule in the Europe/Berlin time zone, such as the HR import or the leave-date scan; found under “Monitoring” → “Background Jobs” |
| Notifications | by e-mail; through an add-on also in Microsoft Teams |
| AI (optional) | local models via Ollama or a cloud provider; the core works without AI – see AI in Nova |
Add-ons
Add-ons (plugins) extend Nova with further functions. After installation they are switched off; administrators enable them one by one under “Administration” → “Plugins”. Add-ons with their own interfaces require a restart afterwards. The add-ons include:
| Add-on | Function |
|---|---|
| “Planstellen (OSP)” | positions between organisational units and people, with their own business roles |
| “SoD-Analyse (SAP ABAP)” | checks SAP roles against an SoD ruleset |
| “GRC-Berechtigungsanalyse (SAP Access Control)” | uses an existing SAP GRC Access Control as a source for risk analysis |
| “Native MFA (TOTP)” | second factor for password sign-in |
| “OIDC Identity Provider” | other applications sign people in through Nova (OpenID Connect) |
| “Microsoft Teams Notifications” | notifications in Microsoft Teams |
How data flows
- Source system → Nova. The HR system supplies personnel data. Nova creates identities from it, keeps them up to date and detects joiners and movers.
- Intended state in Nova. Which entitlements an identity should have, and for which period, Nova records as assignments – from business roles, organisational units, positions, approved access requests and direct assignments.
- Nova → target systems. Provisioning runs create accounts, transfer entitlements and lock accounts.
- Target systems → Nova. Nova reads accounts and entitlements from the target systems. Where the intended state in Nova and the actual state in the target system differ, reconciliation shows the differences; administrators resolve them in either direction.
Operation
Today, Nova runs on the operator's own servers: as a container application with a PostgreSQL database, used through the browser. The editions available and those announced are described in Editions and deployment.