Working with Identities and Accounts

This document covers everything you do in the Identities module: browsing each inventory, reading an identity's accounts, applications and entitlements, assigning owners, acting on accounts, and editing identity details.

For what the module is and how it classifies identities, see Identities module overview.

View human identities

Navigate to Identities > Human to open the Human Identities page. Three tabs across the top split the inventory: All, Employees, and External. Employees are the people on your payroll or in your primary directory. External identities are contractors, partners, and anyone else outside the organization who holds access.

Steps

  1. Navigate to Identities > Human.
  2. Select the All, Employees, or External tab.
  3. Select Privileged Identities to narrow the table to identities holding at least one privileged role or permission.
  4. Select the column manager icon to open Modify Columns, then select the columns you want and select Update.
  5. Select an identity name to open its detail view.

View non-human identities

Navigate to Identities > Non Human to open the Non-Human Identities page. Six tabs split the inventory: All, Service Accounts, Workload Identity, Application Identity, Bots, and Secrets. Each tab shows a count of the identities it holds.

Steps

  1. Navigate to Identities > Non Human.
  2. Select the bucket tab you want to review.
  3. Select Orphaned Identities to narrow the table to identities with no valid owner.
  4. Select Privileged Identities to narrow the table to identities holding at least one privileged role or permission.
  5. Select the column manager icon to open Modify Columns, then select the columns you want and select Update.
  6. Select an identity name to open its detail view.

The Secrets tab carries three columns the other buckets do not: Expiry Date, Last Rotation Date, and Next Rotation Due Date.

Review unclassified identities

Navigate to Identities > Unclassified to open the Unclassified Identities page. This page holds identities Zluri discovered from a connected source but could not match to any type it defines. Assigning the correct type moves the identity into the Human or Non Human inventory.

Steps

  1. Navigate to Identities > Unclassified.
  2. Select an identity name to open its detail view.
  3. Select the More actions menu in the top right, then select Change Type.
  4. Select the type that fits the identity.

You can also reclassify without opening the identity. Select the Type cell in the table, select the edit icon, then choose a new type in the Modify Identity Type dialog.

To reclassify several identities at once, select their checkboxes, then select Bulk Edit > Identity Type.

Open an identity's detail view

Select any identity name in a table to open its detail view. The left rail shows the identity's key attributes and four tabs: Overview, Accounts, Applications, and Entitlements. Each tab carries a count. The right panel holds Identity Details, Owners, Description, and Discovery.

Steps

  1. Select an identity name in any identity table.
  2. Read the right panel for the identity's name, native ID, type, native type, status.
  3. Read the Owners section for the people or groups accountable for this identity.
  4. Read the Discovery section for the sources the identity came from, the date Zluri discovered it, the date it was created in the source, and the identity that created it.
  5. Select Accounts, Applications, or Entitlements to go deeper.

What the Overview tab shows

Every identity's Overview tab shows an Applications by Authorization Status chart, an Accounts by type chart, and an Insights section.

A human identity shows all of that, plus a strip of four metric cards above the charts: Accounts owned, Secrets owned, Secrets expiring in 15 days, and Secrets with no expiry. Select the arrow on any card to open the matching list.

Insight cards

Insight cards surface conditions on this identity that are worth acting on. Each card carries a count, a short description of what the count covers, and a Review button that opens the records behind it.

Zluri only shows a card when its count is greater than zero, so the set of cards differs from one identity to the next.

Review an identity's accounts

Select the Accounts tab in an identity's detail view to see every account tied to that identity. Sub-tabs split the accounts by the relationship the identity has with them, and four filter chips narrow the table further: Privileged, Orphaned, Human, and Non Human.

The table below explains each sub-tab.

Sub-tabWhat it holds
AllEvery account related to this identity, across all relationships
LinkedAccounts that represent this identity in a specific application instance
OwnsAccounts this identity is the owner of. Available on human identities only
AccessesAccounts this identity uses, recorded through Assign Accessor in account rows
CreatedAccounts this identity created in the source

A non-human identity cannot own another identity, so the Owns sub-tab does not appear on non-human identities.

Steps

  1. Select the Accounts tab in an identity's detail view.
  2. Select the sub-tab for the relationship you want to review.
  3. Select Privileged, Orphaned, Human, or Non Human to narrow the table.
  4. Select the column manager icon to open Modify Columns, then select the columns you want and select Update.

Review an identity's applications

Select the Applications tab in an identity's detail view to see every application this identity reaches, whether through a linked account, an account it accesses, or an account it owns. The table shows the accounts that grant the access alongside the roles, permissions, groups, and licenses the identity holds in each application.

Steps

  1. Select the Applications tab in an identity's detail view.
  2. Read the Accounts column to see which account grants access to each application.
  3. Select the column manager icon to open Modify Columns, then select the columns you want and select Update.

Review an identity's entitlements

Select the Entitlements tab in an identity's detail view to see everything the identity can do across your applications. Four sub-tabs split the list by entitlement type: All, Roles, Permissions, and Group. The Privileged Entitlements filter chip narrows the table to entitlements Zluri marks as privileged.

Steps

  1. Select the Entitlements tab in an identity's detail view.
  2. Select the All, Roles, Permissions, or Group sub-tab.
  3. Select Privileged Entitlements to narrow the table.
  4. Read the Accounts Assigned To column to see which of the identity's accounts carries each entitlement.

How Zluri determines owners

Zluri populates the Owners field on a account from the connected source wherever it can, so most identities arrive with an owner already set. The table below lists the methods in the order Zluri applies them, and which record each one sets the owner on.

MethodHow Zluri uses itApplies to
Owner from the integrationWhen the source reports an owner for the account, Zluri records that person as the ownerAccount
Created-by attributionWhen the source reports who created the account, Zluri records that identity as the ownerAccount
Traversal to a human ownerWhen the owner Zluri finds is itself a non-human, Zluri follows the ownership chain upward until it reaches a human, then records that person as the ownerAccount
Owner of a linked accountZluri takes the owner of the account that represents this identity in a specific application or application instanceIdentity

The first two methods set the owner on the account. An identity does not take an owner directly from the source: it inherits from its linked accounts, which are what the identity itself represents in a specific application or application instance.

Zluri always resolves ownership to a human, which is why traversal continues past any non-human owner it encounters.

Assign an owner from an identity table

The Owners column is editable in place, so setting an owner on one identity. Use this option when you are working down a filtered list and fixing identities one at a time.

Steps

  1. Select the Owners cell on the identity you want to change.
  2. Select the delete icon next to any owner you want to remove.
  3. Select the owner type selector, then select User to assign a user or Group to assign a group.
  4. Enter a name in Add Owner, then select the owner from the results. Select Next.
  5. Choose the scope of the change, then select Update owner.

Assign an owner to a single identity

Open the identity's detail view and edit the Owners section in the right panel. Use this option when you are fixing one identity and want to see its current owners before you change them.

Steps

  1. Open the identity's detail view.
  2. Select the edit icon next to Owners in the right panel.
  3. Select the delete icon next to any owner you want to remove.
  4. Select the owner type selector, then select User or Group.
  5. Enter a name in Add Owner, then select the owner from the results.
    Select Next.
  6. Choose the scope of the change, then select Update owner.

You can also reach this from the More actions menu in the top right of the detail view: select Modify Owner.

Assign owners in bulk

Select rows in any identity table to reveal the Bulk Edit menu, then assign one owner across the whole selection. Use this option when you have filtered a table down to the identities that need an owner, for example by selecting Orphaned Identities.

Steps

  1. Select Orphaned Identities to narrow the table to identities that need an owner.
  2. Select the checkbox next to each identity you want to update, or select the header checkbox to select every row.
  3. Select Bulk Edit, then select Assign Owner.
  4. Select the owner type selector, then select User or Group.
  5. Enter a name in Add Owner, then select the owner from the results.
    Select Next.
  6. Choose the scope of the change, then select Assign owner.

Choose how far the ownership change cascades

Ownership in Zluri is rarely a single record. Most accounts and identities hold the owner Zluri worked out for them, following the chain from the owner the source reported, through the accounts an identity is linked to, up to a human. See How Zluri determines owners.

That is why changing an owner is not a one-field edit. Zluri needs to know whether you are correcting one record or moving accountability for everything that record feeds. It asks in a confirmation dialog, and it asks on every route: from an identity table, from an identity's detail view, from a bulk edit, and from a single account.

Two Options and the table below explains what each option changes.

OptionWhat it changes
Everything the record affectsThe record you are editing plus everything downstream of it. For an identity, that is its linked accounts, the accounts downstream of those, and the identities that inherit their owner from them. For an account, it is the identity the account is linked to and the accounts downstream of it. Selected by default.
The record onlyThe identity or account you are editing, and nothing else. Every derived owner below it stays where it is.

Take action on an account

Account tables let you assign ownership, record who uses an account apart from the already exisitng actions at account level. Both the controls appear as inline prompts in their respective columns, on both an identity's Accounts tab and an application's Accounts page.

The table below lists the actions available on an account row.

ActionColumnWhat it does
Assign OwnerOwnersSets the person or group accountable for the account
Assign AccessorAccessed ByRecords an identity that uses this account without owning it
Edit NameNameChanges the account display name in Zluri
Change StatusStatusSets the account's status to Active, Inactive, Suspended, or Expired
Change TypeTypeReassigns the account to a different type
Edit DescriptionDescriptionRecords what the account was created for
ArchiveArchival StatusArchives the account and sets its archive status

Steps

  1. Scroll the table sideways to the Owners, Accessed By
  2. Select Assign Owner, Assign Accessor in the row you want to change.
  3. Complete the picker that opens, then confirm.

Open an account's details

Select any cell in an account row to open the account detail side sheet. The header shows the application icon, the account name, and the account's status badge, with the application instance named on the right. Three tabs split the detail: Overview, Sources, and Entitlements. Selecting a cell deep-links to the matching tab, so selecting the Roles cell opens the sheet on Entitlements > Roles.

Steps

  1. Select any cell in the account row.
  2. Read the Overview tab for the account's attributes and licenses.
  3. Select Sources to see every source the account came from.
  4. Select Entitlements to see the roles, permissions, and groups the account holds.

What each tab shows

The table below explains the three tabs.

TabWhat it shows
OverviewAn Account Details grid holding Name, Type, Native ID with a copy icon, Native Type, Status, Discovered on, Accessed by, Owner, Created on, Created by, Last Active on, Linked Identity, and Description, followed by a Licenses Assigned section
SourcesOne row per source the account was found in, naming the source, its category and sub-source, and the Account Status that source reports
EntitlementsSub-tabs for All, Roles, Permissions, and Groups, plus a Privileged Entitlements filter chip

When an account holds no licenses, the Overview tab reads "No licenses assigned to this account".


Review accounts for an application

Navigate to Applications, select the application, then select Accounts in the left rail to see every account Zluri discovered in that application. This is the view to work from when you are focussing on one application rather than one identity, and it is where you record accessors and grant roles.

The instance selector at the top of the left rail reads All Instances with a count. Use it to narrow the table to a single instance of the application.

Steps

  1. Navigate to Applications, then select the application.
  2. Select Accounts in the left rail.
  3. Select the instance selector at the top of the left rail to scope the table to one instance, or leave it on All Instances.
  4. Select Privileged Accounts, Orphaned Accounts, Human, or Non Human to narrow the table.
  5. Select the column manager icon to open Modify Columns, then select the columns you want and select Update.
  6. Select a page arrow to move through the table.

Edit identity details

Correct an identity record without leaving the page you are on. Every identity action is available in three places: the More actions menu on the identity's detail view, inline in the identity table, and, where the action makes sense across many records at once, the Bulk Edit menu.

ActionWhat it doesInline in the tableBulk Edit
Edit NameChanges the identity display name in ZluriYes, select the Name cell then the edit iconNot applicable
Modify OwnerOpens the owner picker and the scope dialogYes, select the Owners cellYes, as Assign Owner
Change StatusSets the identity's status to Active, Inactive, Suspended, or ExpiredYes, select the Status cell then the edit iconYes, as Status
Change TypeReassigns the identity to a different type, which can move it between inventoriesYes, select the Type cell then the edit iconYes, as Identity Type
Edit DescriptionRecords what the identity was created forYes, select the Description cellNot applicable
ArchiveArchives the identity and sets its archive statusYes, from the row menu in the Actions columnYes, as Archive

Edit an identity from its detail view

Use this option when you have the identity open and want its full context on screen before you change anything. The More actions menu in the top right holds every edit action.

Steps

  1. Open the identity's detail view.
  2. Select the More actions menu in the top right.
  3. Select the action you want, then complete the fields shown.

Alternatively, select the edit icon beside Name, Type, Status, Owners, or Description in the right panel to change that field in place. You can also rename an identity directly in a table: select the name cell, then select the pencil icon.

Edit an identity inline in the table

Use this option when you are working down a list and correcting records as you go, without opening each one.

Steps

  1. Select the cell you want to change.
  2. Select the edit icon that appears in the cell.
  3. Complete the control that opens, then save.

Each field opens a different control:

  1. Status opens a dropdown listing Active, Inactive, Suspended, and Expired with a check against the current value.
  2. Type opens a Modify Identity Type dialog reading "Select a new type for [identity name]." with a required Select type field and Cancel and Save buttons.
  3. Owners opens the owner picker described in Assign an owner from an identity table.
  4. Archive sits in the row menu in the Actions column rather than in a cell.

Edit identities in bulk

Use this option when the same change applies to many identities, for example setting a batch of tokens to Inactive.

Steps

  1. Select the checkbox next to each identity you want to change, or select the header checkbox to select every row.
  2. Select Bulk Edit.
  3. Select Status, Archive, Identity Type, or Assign Owner.
  4. Complete the control that opens, then confirm.

Did this page help you?