
Quick Summary: Forcing identity teams to manually rewrite routine queries for investigations locks vital operational expertise into individual silos. Integrating Oleria Trustfusion, an AI-native identity security platform, solves this repetition by converting ad-hoc searches into an interactive, parameterized IAM query library that your entire team can share, schedule, and execute automatically.
Save and share queries; build a team library.
The query you wrote yesterday for an investigation is the query someone else needs today. Save it, share it, parameterize it.
IAM engineers solve the same questions over and over: dormant accounts in a specific app, identities matching a particular risk pattern, members of a privileged group. Each engineer rewrites the query; nothing accumulates as team knowledge; the slow learner stays slow.
Most identity tools have ad-hoc query but no concept of a saved, shared, parameterized query library. The result is tribal knowledge that lives in individual engineers' notes — if they take notes — and disappears when they change roles.
The IAM Team Shared Query Library in Oleria turns every saved query into a reusable team asset — parameterized templates your whole team can run, schedule, and build on.
Any query — plain English or structured — can be saved with a name, description, and tags.
Queries support variables: app name, identity type, threshold period, etc. The query is a template the team uses repeatedly.
Saved queries are private by default; shared queries appear in the team library. Permission to edit and run is configurable.
Saved queries can run on schedule; results can route to operator, ITSM, or webhook. The query becomes an automation.
Reused queries vs. rewritten — Step-change shift toward reuse
Team query library size — Grows continuously
Time to onboard a new IAM engineer — Materially reduced (library is tutorial)
Tribal knowledge loss when engineers transition — Minimized

Anything that's been asked more than twice. Common candidates: privileged-access inventory, dormant accounts in specific apps, NHIs without owners, drift events from the last week, members of specific groups, identities matching specific risk profiles. The library grows organically; the most-used queries float to the top.
Queries support variables. "Dormant accounts in {app} unused for {threshold}" becomes a template; the operator runs it with specific values. Parameters can have defaults; high-frequency variations get their own saved query. Same underlying logic, different parameter sets.
Private by default — your saved queries are yours. Shared queries appear in the team library, with permissions: who can run, who can edit, who can see. Most teams have a small number of curated, high-quality shared queries plus everyone's personal sets.
A saved query running on schedule with results routed to a channel becomes an automation. Daily dormant-NHI report to the IAM team's Slack. Weekly privileged-access summary to the architect. Continuous drift monitoring with alerts to PagerDuty. The query infrastructure becomes the foundation for routine reporting.
Queries are versioned; edits create new versions; previous versions remain runnable for reproducibility. Important for audit scenarios where "this was the query we ran last quarter" needs to be reconstructible.