Visibility
All NHI
IAM Engineer

Give every IAM engineer the same shared query library instead of rebuilding the same views from scratch

Summary: Allowing critical identity queries and audit logic to live exclusively in the isolated personal notes of individual engineers risks massive reporting inconsistencies and total knowledge loss during team turnover. Integrating Oleria Trustfusion, an AI-native identity security & governance platform, eliminates this operational risk by establishing a centralized, team-wide shared IAM query library that standardizes canonical security views, accelerates new-engineer onboarding, and preserves critical institutional data.

Outcome

Every IAM team has a working set of canonical identity queries - dormant NHIs with admin scope, privileged accounts not reviewed in 90 days, OAuth consents from the last 30 days, departed-user credentials still active. The problem is that every engineer holds their own version. Oleria's shared saved views let the team codify those definitions once, share them across every team member instantly, and keep the knowledge alive regardless of who joins or leaves.

The reality

Every IAM team runs the same set of reviews on a cycle - dormant NHIs, privileged-account exposure, scope-sensitive queues, departed-user credential cleanup. The queries that drive those reviews are almost never written down formally. Senior engineers carry them in memory. Junior engineers learn by asking, then build their own variations. Over time, every engineer on the team has a slightly different version of "the same" query.

The gap shows up in audits: two engineers ran "the same" review and got different results. It shows up in onboarding: the new hire takes three months to get productive because the canonical queries live in a Slack thread from 2022 and a senior engineer's personal notes. It shows up in turnover: when the senior engineer leaves, the queries leave with them.

This isn't a cultural feature of experienced teams - it's accumulated technical debt. Saved views are how the team pays it off.

What you get with Oleria

Oleria's shared saved view library lets the IAM team codify its canonical query definitions and make them available to every team member - instantly, without any configuration or access request. A shared IAM query library for identity teams replaces the fragmented per-engineer knowledge that degrades with every hire and departure.

What Oleria delivers

Team-shared saved view library

Canonical query definitions saved and visible to the whole team the moment they are created. The "dormant NHIs with admin scope" view is the team's agreed definition - not one engineer's memory of it. Every team member starts from the same place.

Institutional knowledge that outlasts turnover

When an engineer leaves, their saved views stay in the team library. The queries they built and shared over years remain available to whoever joins next - no knowledge transfer meeting required, no queries reconstructed from memory.

Foundation for scheduled reporting

Saved views connect directly to automated reports. The same shared definition that powers ad-hoc review also drives the team's weekly scheduled reporting - one definition, consistent results across every consumption pattern.

Outcomes at a glance

Shared saved views
Canonical identity query definitions shared across the whole IAM team - one definition, consistent results for every engineer who runs it
Categorized library
Views organized by category - dormancy, privilege, hygiene, compliance - so any team member can find and run the right query without asking around
Knowledge that survives turnover
Saved views persist in the team library - when an engineer leaves, their queries stay and are immediately available to whoever joins next
Report foundation
Saved views power scheduled reports - the same shared definition drives both ad-hoc review and automated weekly reporting
New engineer ramp
New hires inherit the team's canonical query library on day one - productive in days, not months of asking senior engineers what to run

How it works

  1. Define - The team agrees on a canonical query definition - what counts as a dormant NHI, what scope threshold triggers a privileged review.
  2. Save - The agreed definition is saved as a shared view. The agreement persists beyond any individual.
  3. Share - Visible to every team member immediately. New engineers inherit the team's knowledge on day one.
  4. Refine - As the team's understanding evolves, the shared view gets updated. The team learns together rather than per individual.

What it looks like in your environment

A new IAM engineer joins. In the old model, their first week involves asking senior engineers "what query do I run for X," collecting answers that vary slightly depending on who they asked, and gradually building their own mental model of what the team's canonical reviews actually are.

With Oleria saved views, day one looks different. They open the shared library, find the team's categorized query definitions - dormancy, privilege, hygiene, compliance - and start running the same reviews the rest of the team runs. Within a week they are contributing observations on the queue rather than still figuring out what to query.

Six months later, a senior engineer leaves. Their institutional knowledge used to leave with them. This time, the queries they built and shared over two years are still in the library - organized, named, and available to whoever joins next.

What good looks like

  • Two engineers running "the same" review get the same result - because they are running the same saved view, not their own versions of the same query.
  • New engineers are productive within days because canonical queries are in the library, not locked in someone's head.
  • When a senior engineer leaves, their query library stays - available to the whole team, no reconstruction required.
  • The "what query do I run for X" question gets a saved view, not a hallway conversation.

Stop rebuilding the same queries every time someone joins or leaves.

Oleria's shared saved views give every IAM engineer the same canonical library on day one — consistent results, preserved knowledge, faster reviews.

Frequently Asked Questions

What kinds of identity queries can be saved as views?

Any filter or combination of criteria the team uses regularly - dormancy thresholds, privilege scope, review status, credential type, environment, owner attribution. If the team runs it more than once, it can be a saved view.

Can saved views be shared across teams, not just within one team?

Yes, but cross-team sharing is explicit opt-in rather than the default. Teams control what they share externally, which prevents one team's experimental views from appearing in another team's canonical library without intent.

How does this interact with scheduled reports?

Saved views are the query foundation; scheduled reports run them on a schedule and distribute results. Same definition, multiple consumption patterns - a saved view can power both ad-hoc review and weekly automated reporting without duplicating the definition.

What happens to saved views when an engineer who created them leaves?

Saved views belong to the team library, not to the individual who created them. They remain available to the whole team after someone leaves - no admin action required.