
Quick summary: Knowing which identities hold access to sensitive systems only tells half the story; true risk is hidden within what they choose to do with those permissions. By fusing raw corporate audit logs with Oleria Trustfusion, an AI-native identity security platform, security teams achieve granular action-level activity visibility across SaaS applications and data lakes. This combined framework maps entitlements directly against observed actions to uncover standing data exposure, catch insider risk, and enforce empirical least-privilege guardrails.
Security and data governance teams gain continuous, action-level visibility into what each identity is actually doing with every resource they have access to — reading, downloading, editing, deleting, creating, querying, sharing, and more. Oleria Trustfusion surfaces observed actions per identity per resource, alongside each identity's entitlement scope, enabling teams to distinguish access that is actively and appropriately used from access that is standing, over-scoped, or being exercised in ways that warrant governance attention.
Knowing that a user has access to a sensitive database is useful. Knowing that they queried it 400 times last month, downloaded records in bulk twice, and deleted rows once — is actionable. Activity insights transform resource governance from a static permission audit into a continuous, evidence-based understanding of what is actually happening on your most sensitive systems.
Access tells you blast radius. Activity tells you real risk: Knowing that 200 identities have access to a production database is useful. Knowing that only 12 have performed any query in the past 90 days, that 3 have downloaded records in bulk, that 1 has deleted rows, and that the remaining 188 have never touched it — is actionable. Oleria brings both dimensions into the same resource profile, continuously, for every resource.
Surfacing what users are doing with resources — not just that they have access — requires joining entitlement data and action-level activity logs that almost never live in the same tool:
· Access data and activity data live in completely separate systems. The IDP holds entitlement data — who is assigned to which role or group. The SaaS application or data platform holds activity logs — who queried which table, who downloaded which file, who deleted which record. Joining these two data sources to produce a per-identity, per-resource view of both entitlement and observed action requires custom integration work that most security teams cannot sustain at scale.
· Activity logs are noisy without an access context layer. Raw activity logs from Snowflake, SharePoint, GitHub, or Salesforce record every action against every object. Without an access context layer that knows who each log actor is, what role they hold, and what resource sensitivity applies — the logs are difficult to turn into actionable governance insights. Volume is high; signal-to-noise is low.
· There is no standard way to measure whether access scope matches actual use. Even when activity data is available, comparing it to entitlement scope requires a purpose-built correlation: which actions is each identity authorized to perform, which have they actually performed, and is there a material gap? This analysis is not produced by any native tool.
· High-risk actions are not surfaced proactively. Bulk data downloads, record deletions, file exports, and permission changes are recorded in application audit logs but never proactively surfaced as security signals without a governance layer that knows which identities hold sensitive resource access and can flag high-risk action patterns.
· No visibility into first-time or anomalous action patterns. An identity that has always read from a resource and then performs a first-ever delete or bulk export represents a behavioral change worth reviewing — but this pattern is invisible without a system that tracks action type history per identity per resource.
Oleria Trustfusion joins entitlement data and action-level activity signals in the composite Access Graph — producing a resource profile that shows not only who can reach a resource but what they have done, how recently, and whether their observed activity is proportionate to their entitlement scope. This combined view is available continuously for every connected resource.
.webp)
· Action type visibility: what each identity is doing. Where application connectors expose action-level activity data, Trustfusion surfaces the types of actions each identity has performed against a resource within the configured activity window. Action types include: read and query (viewed or retrieved data), download and export (moved data outside the application), edit and modify (changed existing records or content), create (added new records or files), delete and destroy (removed records or content), share and permission changes (modified who can access the resource), and administrative actions (configuration changes affecting the resource). Each action type is classified by risk — destructive and exfiltration-risk actions receiving the highest weighting.
· Last action timestamp and type per identity per resource. The most recent recorded action for each identity against each resource is surfaced in the resource profile — enabling dormancy calculation at the action level. An identity whose last action was a read two years ago is a different risk profile from one whose last action was a bulk download last week.
· Action frequency and volume signals. Where available, Trustfusion surfaces action frequency and volume signals per identity per resource — enabling the detection of unusual access patterns: a spike in read queries on a regulated data schema, a bulk export from a document library by an identity approaching offboarding, or a first-ever delete from an account that has only ever read data. These signals complement SIEM behavioral detections by grounding them in entitlement and governance context.
· Entitlement vs. activity gap analysis. For each identity with access to a resource, Trustfusion compares the actions they are authorized to perform (based on role and permission scope) against those they have actually performed. Identities authorized to write, delete, and export but observed only reading — or never active at all — are flagged as over-entitled relative to observed use. This gap is the empirical basis for least-privilege right-sizing.
· High-risk action detection. Actions in the highest-risk categories — bulk downloads, mass deletions, permission modifications, and administrative changes — performed by any identity against a classified or sensitive resource are surfaced as posture findings. These are governance signals: this entitled identity performed a high-risk action on a sensitive resource, and that warrants review.
· Activity by privileged accounts on sensitive resources. When a privileged account performs write, delete, export, or permission-change actions on a sensitive resource, those actions are surfaced with elevated visibility. Privileged accounts performing destructive or exfiltration-risk actions on classified data assets generate findings that feed into both the resource governance workflow and the privileged account oversight program.
· First-time high-risk action patterns. An identity that has accessed a resource many times in a read-only capacity and then performs a first-ever delete or export action represents a behavioral change worth surfacing. Trustfusion identifies first-time occurrences of high-risk action types per identity per resource.
· Dormant-then-active reactivation events. An account that has been dormant on a resource for an extended period and then performs a high-risk action — particularly near the time of an employee offboarding or a role change — is flagged as a dormant reactivation event. This pattern is consistent with insider risk scenarios and warrants immediate governance attention.
· Right-sizing driven by observed use. Entitlement-activity gap analysis produces concrete right-sizing recommendations: which action types are authorized but never used, per identity per resource. Removing unused action types from the entitlement scope reduces blast radius without removing access entirely — a less disruptive and more defensible least-privilege intervention.
· Activity history for investigation and audit. The complete action history per identity per resource is retained with timestamps. During incident investigation, investigators can query who performed which actions on a resource in any time window — without pulling and parsing application audit logs independently. Compliance teams can demonstrate not only who had access but what they did with it.
Stage 1 — Continuous Ingestion of Action-Level Activity Streams from Connected APIs: Oleria connectors pull action-level event data from application audit logs where available via API: SharePoint audit logs (file view, download, edit, delete, share, permission change via Microsoft Graph); Google Drive activity events (view, download, edit, comment, share, delete via the Drive activity API); Snowflake query history and access events (query execution, data export, role grant, schema modification); GitHub events (commit, push, pull request, clone, repository create/delete, admin actions); Salesforce event monitoring (record view, create, edit, delete, export where licensed). For applications that expose only last-login timestamps, the coarser signal is surfaced with appropriate context.
Stage 2 — Contextual Joining of Event Audits to Identity Entitlement Layers: Activity data is joined to entitlement data at the identity-resource level. Each identity-resource relationship is enriched with: authorized action scope (what the entitlement permits), observed action history (what has been performed, with action type and timestamp), last action timestamp and type, and entitlement-activity gap (authorized but never-used action types). Resource nodes are enriched with the action-level activity summary across their entire access population.
Stage 3 — Automated Posture Assessment and Identity Behavior Risk Scoring: Trustfusion evaluates activity patterns against configurable policy: dormant access holders (no action within the threshold), entitlement-activity gap (authorized scope significantly exceeds observed use), high-risk action types on sensitive resources, first-time high-risk actions, bulk operations near offboarding events, and dormant-then-active reactivation patterns. Each signal generates a typed posture finding with resource context, the specific identity and action pattern, and remediation guidance.
Stage 4 — Granular Behavioral Visualization and Empirical Right-Sizing Campaigns: The resource profile in the Access Inventory shows entitlements and action-level activity side-by-side in one view. Posture Campaigns drive right-sizing for entitlement-activity gaps and review for high-risk action patterns. The complete activity record is retained for investigation support, compliance evidence, and historical activity queries at any past point in time.
· "What is this user doing on this resource?" answered in seconds. The action-level activity profile for any identity against any resource — action types performed, frequency, last action, and entitlement gap — is available from Trustfusion immediately. No log queries, no manual joins, no multi-system reconciliation required.
· Entitlement scope matches observed use. Identities authorized for write, delete, and export on a resource but observed only reading — or never acting — are identified and right-sized. Over time, authorized action scope converges toward what identities actually need, reducing blast radius across the resource population.
· High-risk actions on sensitive resources surfaced and reviewed. Every bulk download, mass delete, permission change, or export against a classified resource is surfaced as a posture finding with an owner, SLA, and audit trail. These actions are not invisible in a log — they are governance findings that are tracked to resolution.
· Activity history supports investigations without log reconstruction. When an incident involves a sensitive resource, Trustfusion provides the complete action history for every identity that accessed it — what they did, when, and how often. Mean time to blast-radius and impact assessment drops from hours to minutes.
· Compliance evidence includes both access and activity. Audit evidence from Trustfusion shows not only who had access but what actions were performed — giving auditors a richer, more defensible access governance record than a permission list alone provides.
· First-time high-risk actions flagged before they become incidents. Behavioral changes — first delete, first bulk export, dormant-then-active reactivation — are surfaced as governance findings while there is still time to review and act, rather than discovered during post-incident analysis.

Access charts dictate your absolute blast radius, but they fail to show actual operational risk. Stop guessing if your teams are over-permissioned—book a personalized demo today to see how Oleria Trustfusion delivers clear, action-level activity visibility.
Yes — the depth of action-level activity data varies by application. Richer connectors include SharePoint (file view, download, edit, delete, share, permission change via the SharePoint audit log API), Google Drive (view, download, edit, comment, share, delete via Drive activity API), Snowflake (query execution, data export, role grant, schema modification via query history), GitHub (commit, push, pull request, clone, repository create/delete, admin events), and Salesforce (record view, create, edit, delete, export via event monitoring where licensed). For applications exposing only last-login or last-activity timestamps, Trustfusion surfaces the coarser signal with appropriate context. Action depth per application is documented in the connector specification.
The entitlement-activity gap is the difference between what an identity is authorized to do on a resource and what they have actually done. An identity authorized to read, write, delete, and export from a Snowflake schema who has only ever run read queries has a large gap: write, delete, and export permissions that are standing but unused. That gap is the empirical definition of over-provisioning at the action level — and removing the unused action types from the entitlement scope is a direct, evidence-based least-privilege intervention that reduces blast radius without removing access entirely.
Trustfusion's activity analysis is a governance capability, not a behavioral anomaly detection capability. It answers "what is each entitled identity doing on this resource?" — enabling right-sizing, dormancy detection, and governance review of high-risk action types. SIEM and UEBA answer a different question: "does this activity pattern deviate from baseline in a way suggesting a threat?" The two are complementary — Trustfusion provides the entitlement and governance context that makes SIEM/UEBA alerts more actionable, and those tools provide the anomaly signal that may prompt an investigator to use Trustfusion for deeper access investigation.
Trustfusion surfaces high-risk action types as governance findings — not real-time enforcement decisions. When action-level activity data includes volume or frequency signals (Snowflake query history showing a large-volume SELECT or COPY INTO, SharePoint audit logs showing multiple file downloads in a short window), Trustfusion evaluates that signal against the identity's entitlement context and the resource's sensitivity classification and surfaces it as a posture finding for governance review. The finding is not a block — it is an observation that a high-risk action occurred on a sensitive resource by a specific entitled identity, warranting human review.
Activity is attributed at the individual identity level regardless of how access was granted. An identity who accesses a Snowflake schema through a role assigned to an Entra ID group will have their query activity attributed to their canonical identity record — not anonymized in group attribution. The entitlement derivation path (direct, role-based, or group-inherited) is retained alongside the activity record so both the access context and the observed action are visible together.
Yes, within the scope of activity data available from each connector and the configured retention window. For resources where action-level activity is ingested, the activity record for any identity can be queried for any time period — showing which action types were performed, when, and by which identity. This supports both incident investigations ("who accessed this schema and what did they do in the 48 hours before the breach?") and compliance audits ("demonstrate that access to this regulated resource was used appropriately during the audit period").