๐ Recent activity
Identity
Cross-system policy intelligence over Okta, Entra, ISE, ClearPass, and AD.
Auto-detect
Scan email DNS, LAN, and Graph to find Okta / Entra / ISE / ClearPass / AD reachable from this host. Read-only.
Connect a system
Add credentials for one of the 5 supported identity systems. Stored in the encrypted vault, never sent off this host.
Add an NHI manually
Service accounts, API keys, IAM roles. Track owner + rotation cadence even before adapters are connected.
Non-human identities
Service accounts, API keys, IAM roles. Owner + rotation cadence drive the stale-NHI finder and rotation-overdue alerts.
Translate intent → per-system change
Plain English in, unified policy IR out, per-system change preview at the
bottom. Submitting calls /api/identity/translate; nothing
is committed without an explicit dry-run + confirm-token review.
Just-in-Time access
Time-boxed grants. Issued through /api/identity/jit/grant,
auto-expired by the daemon. Apply step still requires confirm-token.
A JIT record is persisted locally; pushing the grant to the target system requires a separate dry-run + confirm-token from /findings.