Visibility
All NHI
IAM Engineer

Give every IAM engineer the same shared query library instead of rebuilding the same views from scratch

Summary: Allowing critical identity queries and audit logic to live exclusively in the isolated personal notes of individual engineers risks massive reporting inconsistencies and total knowledge loss during team turnover. Integrating Oleria Trustfusion, an AI-native identity security & governance platform, eliminates this operational risk by establishing a centralized, team-wide shared IAM query library that standardizes canonical security views, accelerates new-engineer onboarding, and preserves critical institutional data.

The reality

Every IAM team runs the same set of reviews on a cycle - dormant NHIs, privileged-account exposure, scope-sensitive queues, departed-user credential cleanup. The queries that drive those reviews are almost never written down formally. Senior engineers carry them in memory. Junior engineers learn by asking, then build their own variations. Over time, every engineer on the team has a slightly different version of "the same" query.

The gap shows up in audits: two engineers ran "the same" review and got different results. It shows up in onboarding: the new hire takes three months to get productive because the canonical queries live in a Slack thread from 2022 and a senior engineer's personal notes. It shows up in turnover: when the senior engineer leaves, the queries leave with them.

This isn't a cultural feature of experienced teams - it's accumulated technical debt. Saved views are how the team pays it off.

What you get with Oleria

Oleria's shared saved view library lets the IAM team codify its canonical query definitions and make them available to every team member - instantly, without any configuration or access request. A shared IAM query library for identity teams replaces the fragmented per-engineer knowledge that degrades with every hire and departure.

AT A GLANCE

Shared saved views
Canonical identity query definitions shared across the whole IAM team - one definition, consistent results for every engineer who runs it
Categorized library
Views organized by category - dormancy, privilege, hygiene, compliance - so any team member can find and run the right query without asking around
Knowledge that survives turnover
Saved views persist in the team library - when an engineer leaves, their queries stay and are immediately available to whoever joins next
Report foundation
Saved views power scheduled reports - the same shared definition drives both ad-hoc review and automated weekly reporting
New engineer ramp
New hires inherit the team's canonical query library on day one - productive in days, not months of asking senior engineers what to run

What good looks like

  • Two engineers running "the same" review get the same result - because they are running the same saved view, not their own versions of the same query.
  • New engineers are productive within days because canonical queries are in the library, not locked in someone's head.
  • When a senior engineer leaves, their query library stays - available to the whole team, no reconstruction required.
  • The "what query do I run for X" question gets a saved view, not a hallway conversation.

Stop rebuilding the same queries every time someone joins or leaves.

Oleria's shared saved views give every IAM engineer the same canonical library on day one — consistent results, preserved knowledge, faster reviews.

Frequently Asked Questions

What kinds of identity queries can be saved as views?

Any filter or combination of criteria the team uses regularly - dormancy thresholds, privilege scope, review status, credential type, environment, owner attribution. If the team runs it more than once, it can be a saved view.

Can saved views be shared across teams, not just within one team?

Yes, but cross-team sharing is explicit opt-in rather than the default. Teams control what they share externally, which prevents one team's experimental views from appearing in another team's canonical library without intent.

How does this interact with scheduled reports?

Saved views are the query foundation; scheduled reports run them on a schedule and distribute results. Same definition, multiple consumption patterns - a saved view can power both ad-hoc review and weekly automated reporting without duplicating the definition.

What happens to saved views when an engineer who created them leaves?

Saved views belong to the team library, not to the individual who created them. They remain available to the whole team after someone leaves - no admin action required.