Identity Analytics

See Access From the Identity, Application, or Entitlement

Turn complex access relationships into a clearer view of who has access, where that access exists, and which permissions may require further investigation.

Use Identity, Application, and Entitlement Mind Maps to explore connected access data before a review, during an investigation, or when audit teams need a consolidated view.

Mind Map
Identity → App → Entitlement
Mapped
Identity: M. Alvarez
3 apps · 11 entitlements
View
Application: Finance ERP
84 users · 6 unmatched
Investigate
Entitlement: Admin
12 credentials across 4 apps
Target
Start with the question your team needs to answer, then follow the access relationships.
Three Access Perspectives

Start With the Question Your Team Needs to Answer

Access risk can look different depending on where the investigation starts. Use three Mind Map views to analyze the same access data from the identity, application, or entitlement perspective.

Identity Mind Map

What does this person have?

Start with an individual identity and see the applications, credentials, and entitlements associated with that user in one view.

Trace access from the person to the application credential and down to the permissions connected to it.

  • Investigate everything a specific employee can access
  • Review access after a job or responsibility change
  • Understand a user's access before certification
  • Investigate questionable permissions
  • Provide auditors with a consolidated identity view

Application Mind Map

Who has access to this system—and what do they have?

Start with an application and see the identities, credentials, and entitlements associated with it.

Understand how access is actually structured inside the application instead of treating access as simply whether a user has an account.

  • Answer who has access to an application
  • Understand roles and entitlements held by users
  • Investigate unmatched or unexplained credentials
  • Prepare for an application access review
  • Review an application's access population before an audit

Entitlement Mind Map

Who has this permission—and where does it exist?

Start with a specific entitlement and see the credentials and applications connected to that permission.

Use the entitlement-centric view to investigate high-risk or sensitive access such as Admin permissions without reviewing every entitlement in the environment.

  • Find everyone with Admin or another privileged entitlement
  • Investigate sensitive permissions across applications
  • Determine where a specific entitlement is being used
  • Prepare a targeted privileged-access review
  • Give security and audit teams visibility into sensitive rights
Access Relationships

Trace Access From the Person to the Permission

Access can become difficult to understand when identity data, application accounts, and entitlements are viewed separately. Mind Maps connect those relationships so teams can move through:

Identity→ Application→ Credential→ Entitlement

This makes it easier to understand how access was assigned, where a permission exists, and which part of the relationship requires further investigation.

See the Broader Access Footprint

Review access across connected applications instead of checking each system independently.

Understand Application-Level Permissions

Look beyond account existence to the roles and entitlements attached to the credential.

Investigate Unusual Relationships

Use the wider access context to identify credentials, entitlements, or application access that does not look consistent with expectations.

Identity Correlation

Connect Application Accounts Back to the Right Identity

Application access is harder to govern when credentials cannot be clearly connected to a person or System of Record identity. Application Mind Maps help teams understand which identity is associated with each application credential while also surfacing records that require additional investigation.

Matched Credentials

See application credentials connected to identities from the System of Record.

Unmatched Accounts

Identify vendor accounts, older credentials, service-related records, or other accounts that do not automatically match.

Investigate Before You Certify

Bring questionable or unexplained accounts into the appropriate governance or review process before they are simply approved again.

Risk-Focused Investigation

Focus Attention on Access That Looks Different

Not every access relationship requires the same level of investigation. Use identity, application, and entitlement views to explore permissions that appear unexpected, sensitive, privileged, or inconsistent with the user's expected responsibilities.

Unexpected User Access

Investigate applications or entitlements that do not appear consistent with the person's current role.

Sensitive Entitlements

Start with high-risk permissions and see which credentials hold them.

Unmatched Credentials

Find application accounts that cannot be cleanly connected to an identity.

Access Outside Expectations

Use the broader access footprint to determine where a targeted review or deeper investigation may be required.

User Access Reviews

Give Reviewers More Context Before They Make the Decision

Access reviews are more useful when reviewers understand the access relationship behind the certification item. Mind Maps give IAM, security, application owners, and audit teams a wider view of the access population before or during a review.

Identity-Centric Reviews

Understand everything associated with a person before evaluating individual permissions.

Application-Centric Reviews

Give application owners a clearer picture of users, credentials, and entitlements before certification.

Entitlement-Centric Reviews

Identify a sensitive permission and build a focused review around the credentials that hold it.

Explore User Access Reviews →

Sensitive Rights Reviews

Start With the Permission That Carries the Most Risk

Some reviews do not need to include every entitlement in an application. Use the Entitlement Mind Map to identify a sensitive right, understand which credentials hold it, and determine whether a targeted access review is needed.

This creates a more focused way to review privileged or higher-risk permissions instead of treating every entitlement as equally important.

01

Identify

Search for the sensitive entitlement.

02

Understand

See where it exists and which credentials hold it.

03

Review

Bring the selected entitlement into a targeted access review.

04

Decide

Have the appropriate business or application owner certify whether the access should remain.

Export and Analysis

Take the Access View Into Your Investigation or Audit Work

Mind Map results can be exported to CSV when teams need to analyze the access population outside the graphical view.

Use exports to support:

  • Deeper access analysis
  • Audit preparation
  • Targeted investigations
  • Access review planning
  • Reporting and evidence retention

Supporting guidance

Visualize the relationship first. Export the underlying access when deeper analysis is required.

How the Three Mind Maps Work Together

Three Questions. One Access Dataset.

Identity Mind Map

What does this person have?

Start with the identity and follow access across applications, credentials, and entitlements.

Application Mind Map

Who has access to this system, and what access do they have?

Start with the application and understand the identities, accounts, and permissions connected to it.

Entitlement Mind Map

Who has this specific permission, and where does it exist?

Start with the entitlement and find the credentials and applications where that permission appears.

Together, these views give IAM, security, application owners, compliance, and audit teams different ways to investigate the same access data before deciding what should be reviewed, retained, revoked, or investigated further.
Connected Identity Governance

Turn Access Insight Into Governance Action

Identity analytics becomes more useful when the investigation can lead into the appropriate governance workflow.

User Access Reviews

Move questionable or sensitive access into a formal certification process.

Explore User Access Reviews →

Access Analysis

Investigate excessive, dormant, unusual, or higher-risk access across the environment.

Explore Access Analysis →

Segregation of Duties

Evaluate conflicting combinations of access when entitlements create SoD concerns.

Explore Segregation of Duties →

Identity Governance & Administration

Connect access visibility with reviews, requests, lifecycle management, provisioning, and broader governance.

Explore Identity Governance →

FAQ

Identity Analytics FAQs

What Is an Identity Mind Map?

An Identity Mind Map provides an identity-centric view of the applications, credentials, and entitlements associated with a user. It helps teams understand a person's broader access footprint without reviewing each application separately.

What Is an Application Mind Map?

An Application Mind Map starts with an application and shows the users, credentials, and entitlements associated with that system. It helps application owners and IAM teams understand how access is structured inside the application.

What Is an Entitlement Mind Map?

An Entitlement Mind Map starts with a specific entitlement and shows the credentials and applications associated with that permission. It is particularly useful when investigating sensitive or privileged access.

Can Mind Maps Help With User Access Reviews?

Yes. Mind Maps provide additional context around identities, applications, credentials, and entitlements before or during access certification, helping reviewers understand the broader access relationship.

Can Identity Analytics Help Investigate Unmatched Accounts?

Application-centric analysis can help surface credentials that are not automatically matched to an identity in the System of Record so teams can investigate and bring them into the appropriate governance process.

Can High-Risk Entitlements Be Reviewed Separately?

Yes. A sensitive entitlement can be identified first and then used as the basis for a targeted privileged or Sensitive Rights access review.

Can Mind Map Data Be Exported?

Yes. Identity, Application, and Entitlement Mind Map results can be exported to CSV for additional analysis, reporting, investigations, or audit work.

Turn Access Visibility Into Action

Start with the identity, application, or entitlement and follow the access relationships that need attention.