who
Canonical person, employment context, and manager chain.
Platform capability
Investigate identity reach across connected domains, explain authorization with temporal context, and route findings into governed remediation where paths are declared.
Illustrative workflow — not a live product screenshot. Scope and coverage apply.
Coverage depends on connected sources and declared remediation paths. Full-estate visibility is not implied.
Subject type
Employees, contractors, partners
Illustrative product view — subject types do not imply identical underlying data.
Canonical person, employment context, and manager chain.
Group, role, and entitlement reach with last-change timeline.
Live grant contributors: birthright, request, SoD exception, policy.
Source families feed correlation; the graph retains provenance and uncertainty states.
Normalized identity graph
Not labeled “complete identity” — states reflect correlation quality.
Select a link to view source system and collection time (illustrative).
Illustrative product view — prioritization separates consequence from confidence.
Triage states: New · Investigating · Acknowledged · Suppressed · False positive · Remediation proposed · Verified closed
| Finding | Subject | Consequence | Reason | Confidence | Coverage | Change time | State |
|---|---|---|---|---|---|---|---|
| Standing privilege on agent tool path | FinanceCloseAssistant | External payment field change without step-up | Delegation broader than mission | High | MCP gateway connected | Last 24h | Investigating |
| Orphaned service identity | LegacyServiceAgent | Unknown API scope with standing reference | Owner unresolved | Medium | Partial — graph conflict | Stale signal | New |
| SoD exception nearing expiry | AP Clerk (human) | Create vendor + approve payment overlap | Time-bound exception | High | IGA connected | 7 days | Remediation proposed |
Before and after reach for one change event, with a contributor chain explaining why access changed.
Before
After
Remediation moves from a recorded finding, through a proposed correction with its blast radius shown, to authorization, a governed job that performs the change, verification against the target, and the evidence left behind. Each step is illustrative and depends on connected sources and a configured workflow.
Stage 1 of 6 — Identity and context
Consequence and reason code stored; no automatic remediation.
Requires connected sources and configured workflow.
Stage 2 of 6 — Policy and decision
Expected reduction in reachable effects; reversibility stated.
Illustrative — governed workflow where configured.
Stage 4 of 6 — Execution
Credentials and dispatch held outside investigator context.
Illustrative — declared execution paths only.
Stage 5 of 6 — Evidence and proof
Otherwise marked reconciliation required — not success.
Coverage-dependent.
Stage 6 of 6 — Evidence and proof
Finding linked to decision, job, and verified outcome.
Illustrative — export where connectors and retention are configured.
Each column states what that category optimizes for and what it does not alone provide.
| Capability | IGA | PAM | NHI tooling | SIEM / SOC | Identity Intelligence |
|---|---|---|---|---|---|
| Optimized use case | Lifecycle, certification, SoD | Session and vault control | Machine identity inventory | Detection and investigation | Cross-domain who/what/why + governed fix |
| Does not alone provide | Live action-time authorization proof | Full entitlement graph across SaaS | Human-agent correlation at action | Authoritative remediation execution | Universal estate coverage without connectors |
Five tooling categories side by side, stating what each optimizes for and what it does not alone provide. IGA optimizes for lifecycle, certification and separation of duties, and does not alone provide live action-time authorization proof. PAM optimizes for session and vault control, and does not alone provide the full entitlement graph across SaaS. NHI tooling optimizes for machine identity inventory, and does not alone correlate a human to an agent at the moment of action. SIEM and SOC tooling optimizes for detection and investigation, and does not alone carry out authoritative remediation. Identity Intelligence optimizes for cross-domain who, what and why with a governed fix, and does not alone provide universal estate coverage without connectors.
Visibility without intelligence produces dashboards. Intelligence without visibility produces theory.
Online
Powered by EmpowerID AI