IAM
Identity Graph
The identity graph correlates user records across Active Directory, Okta, Workday, and CoreLink local accounts into a unified view. Each person is represented as a single node regardless of how many upstream accounts they have. The graph detects orphaned accounts (upstream record deleted but local access remains), duplicate identities (same person with multiple unlinked accounts), and missing ownership for service accounts.
Graph updates run on the same schedule as connector syncs and produce a correlation confidence score for each link.
Key Configuration
- Correlation attributes (email, employee ID, UPN)
- Minimum confidence threshold for auto-linking
- Manual review queue for low-confidence matches
- Orphan notification recipients