Open Identity & Access Governance Hub

Identity & Access Governance for the Open Source World

OpenCrowd is an open-source Identity Governance & Administration platform that centralizes users, roles, access profiles, approvals, audit, and compliance across xWiki, OpenProject, Nextcloud, GitLab, and the open-source digital workplace.

Open source Enterprise-ready Self-host first
OpenCrowd
Dashboard Applications Identity Access Matrix Access Profiles Requests Audit Reports Settings
Dashboard Unified view of your governance landscape
Users4,782+12.5%
Groups286+8.1%
Connected Apps14+2
Governance Score72Medium risk
Access Overview Last 30 days
User Access Admin Access External Access
Applications HealthLive
xWiki Healthy
OpenProject Warning
Nextcloud Healthy
GitLab Healthy
Mattermost Review
Unified Access MatrixReview-ready
Team xWiki OpenProject Nextcloud
Finance
HR
External×
Risk Alerts8

12 Dormant admin accounts

5 Over-privileged users

3 Spaces without owner

Access ReviewsQuarterly

42 permissions waiting for owner review

18 external users due for recertification

7 roles with unused privileged access

Designed for organizations using open-source collaboration tools

xWiki OpenProject Nextcloud GitLab Mattermost openDesk ecosystem

Connected open-source stack

OpenCrowd sits at the center of your workspace ecosystem.

Bring users, roles, groups, projects, spaces, folders, and audit trails into one governance hub without replacing the tools your teams already use.

One access view across applications Connector-ready for open workspaces Designed for no vendor lock-in
Animated OpenCrowd governance hub connecting to xWiki, OpenProject, Nextcloud, GitLab, Mattermost, and any app.

The problem

Open-source collaboration is growing. Governance is still fragmented.

Organizations are adopting sovereign collaboration stacks for privacy, auditability, self-hosting, and control. But users, groups, roles, and permissions are still managed separately in every tool.

Manual onboarding and offboarding across every tool.
Spreadsheet-based access requests with limited auditability.
No unified answer to who has access to what.
Overprivileged users that are difficult to spot.
Cross-application audits that take too much coordination.
Access reviews that depend on tribal knowledge.

The solution

One governance layer above your open-source stack.

Identity providers answer "Who are you?" OpenCrowd answers "Who has access to what, why, who approved it, and is it still valid?"

OpenCrowd Governance Layer Roles, profiles, requests, approvals, reviews, audit
KeycloakAuthentication
NubusIdentity services
LDAP / ADDirectory source
xWikiApplication access
OpenProjectApplication access
NextcloudApplication access
GitLabApplication access

Key features

Governance made simple, powerful by design.

Unified Access Matrix

View and manage every permission across xWiki, OpenProject, and Nextcloud from one screen. Grant or revoke with a single click.

Joiner / Leaver Flows

Onboard a user once — provisioned to all apps with correct groups automatically. Offboard with one click — access revoked everywhere.

Access Profiles

Predefined templates that assign the right groups and permissions for each role. No more copying from spreadsheets.

3+ Connectors (Bidirectional)

Full bidirectional sync with xWiki, OpenProject, Nextcloud, and more coming. Users, groups, permissions, and memberships flow both ways. Connector SDK for building your own.

Access Request Workflow

Users submit requests via a public form. Admins approve — and the system auto-creates the user, provisions to apps, and grants access.

Audit & Compliance

Every action logged with full trail. Governance score, risk alerts, exportable reports. Built for ISO 27001 and GDPR readiness.

Sovereignty by Design

Self-hosted, European-built, open standards. Powered by Mistral AI (Paris). No data leaves your infrastructure.

Governance Alerts & Reports

Detect over-privileged users, dormant accounts, duplicate identities, and incomplete profiles automatically.

Access profiles

From manual spreadsheets to role-based access profiles.

When a new employee joins, teams should not have to copy permissions from an old spreadsheet. OpenCrowd maps business roles to reusable access profiles and keeps an audit record of every decision.

Manual processNew employee joins -> fills access sheet -> HR/IT manually creates accounts and permissions
OpenCrowd processAssign Business Role -> apply Access Profile -> provision across xWiki, OpenProject, Nextcloud -> audit record created
Example: Taxation Business Analyst
  • xWiki Taxation Space Editor
  • OpenProject Taxation Project Member
  • Nextcloud Taxation Folder Read/Write
  • Review every 12 months

Digital sovereignty

Built for digital sovereignty.

Your identities, policies, audit records, and governance data remain under your control.

Self-host first Customer-owned data Open APIs Open standards Bring your own identity provider On-prem, cloud, hybrid, or air-gapped No mandatory telemetry No vendor lock-in

Open core

Community-friendly and transparent.

OpenCrowd can support a clear open core path: a useful community foundation with professional capabilities for organizations that need advanced governance, reporting, and support.

Community Edition — Free

  • Unlimited users and groups
  • xWiki, OpenProject, Nextcloud connectors
  • Access Matrix, Joiner/Leaver flows
  • Basic audit and governance dashboard
  • Self-hosted (Docker Compose)

Professional — $15/user/month

  • Everything in Community, plus:
  • Kai AI Assistant (powered by Mistral)
  • Advanced governance reports and alerts
  • Email notifications and scheduled reports
  • Priority support (48h SLA)

Roadmap

A focused path toward open access governance.

Phase 1 ✓ Released

Core platform, xWiki connector, OpenProject connector, Nextcloud connector, Access Matrix, Access Profiles, Joiner/Leaver flows, Audit, Governance Dashboard, AI Assistant (Mistral).

Phase 2 — In Progress

Production hardening, email notifications, role-based UI (admin/manager/user), connector health dashboard, data export (GDPR), API rate limiting.

Phase 3 — Planned

Custom approval workflows, access certification campaigns, SCIM 2.0 provisioning, compliance dashboards (SOX, ISO 27001), GitLab connector, openDesk integration.

Get started

Try OpenCrowd today.

Self-hosted and free. Deploy with Docker in minutes. Connect your apps. Govern your access.