
Quick summary: Traditional, spreadsheet-based access matrices fail the moment a provisioning change occurs in an enterprise environment. Transitioning to a continuously updated system of record provides security and compliance teams with instant clarity on every active relationship between identities, applications, and data. By resolving complex indirect access paths, organizations can execute rapid risk investigations and generate audit-ready evidence on demand.
Security, IT, and compliance teams replace manually maintained access matrices and point-in-time system exports with a single, continuously maintained Access Inventory that reflects the live state of every access relationship across the environment. Every identity — human and non-human — is mapped to every entitlement it holds across every connected application. The inventory is always current, always queryable, and always ready to serve as the source of truth for access reviews, risk investigations, audit evidence, and operational decisions.
What the Access Inventory replaces: Most organizations today maintain access knowledge in a combination of IDP admin consoles, SaaS application exports, spreadsheets assembled for quarterly reviews, and the institutional memory of a few overloaded IT administrators. None of these is complete. None is current. And none can answer "who has access to what, right now, across all of our systems?" in under a day. The Oleria Access Inventory is built to answer that question in seconds — and to keep answering it accurately as the environment changes.
Building and maintaining an accurate access inventory without a purpose-built platform is one of the most persistently unsolved problems in enterprise identity management. The core obstacles are structural, not just operational:
· Access data is fragmented across dozens of disconnected systems. Every IDP, SaaS application, cloud IAM platform, and on-premises directory holds a partial view of access — in its own schema, its own terminology, and its own export format. There is no native mechanism to unify these views into a single coherent picture of who can access what.
· Manual inventories are stale before they are finished. Access changes continuously. A spreadsheet assembled from system exports on Monday is already inaccurate by Thursday — new accounts provisioned, roles changed, group memberships updated, access granted for a project and never revoked. Manual inventory efforts produce a snapshot, not a system of record.
· Indirect access paths are invisible to flat exports. Most access inventory efforts capture direct permissions only. A user who can reach a sensitive application through a group membership, a role hierarchy, or an OAuth grant does not appear in a direct-permission export of that application — making the inventory structurally incomplete regardless of how carefully it is assembled.
· Non-human identities are routinely excluded. Service accounts, shared accounts, API keys, OAuth application grants, and managed identities hold significant access and represent significant risk — but they are rarely included in access inventory efforts that are designed around human user certification workflows. The NHI access footprint is a systematic blind spot.
· No common identity across systems. The same person exists as different records in different systems — different usernames, different email formats, different display names. Without identity correlation, an access inventory across multiple systems cannot be reliably attributed to the correct individual.
· Inventory effort is not proportional to risk. Manual inventory processes apply the same effort to every account, regardless of risk level. There is no mechanism to prioritize the inventory of privileged accounts, accounts with access to regulated data, or external identities — the access categories that matter most for security and compliance.
The Oleria Access Inventory is a structured, continuously maintained record of every access relationship in the environment — built from the composite Access Graph and designed to serve as the authoritative source of truth for access visibility, risk assessment, and compliance evidence.
.jpeg)
· Every identity type in scope. The Access Inventory covers human identities (employees, contractors, guests, service accounts), non-human identities (OAuth application grants, API keys, managed identities, shared accounts, automated pipeline identities), and application accounts — all correlated to canonical identity objects and organized in a consistent structure across every connected system.
· Every entitlement type captured. The inventory records direct permissions, role assignments, group memberships that confer access, OAuth scopes, sharing configurations, and inherited or delegated permissions — not just the top-level account existence. Every mechanism by which an identity can reach a resource is represented as a typed access relationship in the inventory.
· Full indirect access path resolution. Where an identity reaches a resource through multiple layers — group → role → application permission — the full path is resolved and recorded. The inventory does not flatten indirect access into invisibility; it shows the complete access chain for every relationship.
· Enriched with operational context. Each access relationship in the inventory is enriched with: employment or engagement status from HR, last-activity timestamp at the application level, MFA enrollment and enforcement status, account dormancy status, license assignment, privilege tier, and open posture findings. The inventory is not just a list of who has what — it is a risk-aware access record.
· Multidimensional filtering. The Access Inventory is browsable and filterable along any combination of dimensions: identity type (human, NHI, external, privileged), application, entitlement type, dormancy status, MFA status, data classification tier, risk level, department, and more. A compliance analyst, a security engineer, and an IT administrator each see the slice of the inventory most relevant to their work — without building custom queries.
· Point-in-time access queries. The inventory retains a timestamped history of every access state and every change. Security and compliance teams can query the inventory as of any past date — answering questions like "who had access to this application on the date of the incident?" or "what was this identity's access profile at the start of the audit period?" — without relying on log reconstruction.
· Exportable for audits and reviews. Any view of the Access Inventory — filtered by application, identity type, privilege tier, or data classification — is exportable as structured data for use in formal access certification campaigns, regulatory evidence packages, or risk reporting. Exports reflect the live or point-in-time state of the inventory, not a manually assembled approximation.
· Foundation for posture evaluation. The Access Inventory is the data layer that powers all posture findings in Trustfusion. Dormancy detection, MFA gap analysis, external identity risk scoring, access drift detection, and regulated data access visibility are all computed against the live inventory — ensuring that posture findings always reflect current access state.
· Feeds access certification campaigns. When a periodic access review or certification campaign is initiated, Trustfusion pre-populates it with current, complete data from the Access Inventory — eliminating the manual export-and-reconcile step that makes certification campaigns slow and error-prone. Reviewers certify against live data, not a stale snapshot.
· Supports incident response. During a security incident, the Access Inventory provides immediate answers to blast-radius and access-scope questions. Investigators can query the inventory for the compromised identity's full access footprint, the full population of accounts with access to the affected resource, and the access change history leading up to the incident — all from a single platform.
Stage 1 — Continuous API Ingestion Across Cloud and Identity Providers: Oleria connectors integrate with IDPs (Okta, Microsoft Entra ID), SaaS applications (Salesforce, GitHub, Snowflake, Microsoft 365, Google Workspace, ServiceNow, and others), cloud IAM (AWS IAM, Azure RBAC, GCP IAM), HR systems (Workday, BambooHR), and on-premises directories. Every entitlement record — account, role, group membership, permission, OAuth grant — is ingested via read-only API connections on a continuous basis. Changes are reflected in the inventory as they occur.
Stage 2 — Schema Normalization and Multi-Layer Identity Correlation: Ingested data is normalized into a common schema and loaded into the Access Graph. Identity records from different systems are correlated into canonical identity objects — resolving the same person's accounts across Okta, Salesforce, GitHub, and Workday into a single record. Indirect access paths (group → role → permission) are resolved and represented as typed edges in the graph. The resulting structure is the foundation of the Access Inventory.
Stage 3 — Contextual Enrichment and Identity Posture Scoring: Each access relationship in the inventory is enriched with operational and risk context: HR employment status and organizational attributes, application-level last-activity timestamps, MFA enrollment and enforcement state, license assignment data, privilege tier classification, data classification tags, and active posture findings. Enrichment transforms the inventory from a raw access list into a risk-aware, actionable record.
Stage 4 — Multi-Dimensional Querying and Historical State Retention: The enriched Access Inventory is surfaced through the Trustfusion UI with multidimensional browsing, filtering, and search. Every access state and change is timestamped and retained for point-in-time queries. The inventory is the source of truth for every other Trustfusion capability — posture campaigns, Identity 360 View, access certifications, and incident investigation all read from and write back to the same live inventory record.
A mature Access Inventory implementation eliminates the manual access management overhead that consumes security and IT team capacity, and produces outcomes that are directly visible to auditors and risk leadership:
· The access spreadsheet is retired. No team maintains a manual access matrix for any connected system. The Oleria Access Inventory is the single source of truth for all access data, and it is more current, more complete, and more queryable than any spreadsheet-based alternative has ever been.
· "Who has access to X?" answered in under a minute. For any application, resource, data asset, or identity in the environment, the access inventory answer is available in Trustfusion within seconds — at any time, without requiring a system admin to pull and reconcile exports.
· NHIs fully inventoried alongside human accounts. Every non-human identity with any access relationship in any connected system is in the inventory with its full entitlement scope, assigned human steward, last-activity data, and risk profile. There are no undocumented NHIs outside the inventory boundary.
· Indirect access paths fully resolved. The inventory reflects actual access — not just direct permissions. A user who can reach a sensitive resource through three layers of group membership is in the inventory for that resource, with the full path shown.
· Access certifications run from live data. Periodic access reviews and certification campaigns are initiated from the Access Inventory directly — with current, complete data pre-populated and obvious anomalies already addressed continuously. Certification time is reduced significantly; reviewer confidence is significantly higher.
· Audit evidence produced on demand, not assembled under pressure. Any access-related question from an internal auditor, external auditor, or regulator is answered from Trustfusion directly — with current state, historical access records, and remediation history available as structured, exportable evidence.

A report or snapshot captures the state of access at a single point in time and immediately begins aging. The Oleria Access Inventory is a live, continuously maintained data model that reflects the current state of access at all times. When a role is assigned, a group membership changes, or a license is revoked, the inventory is updated — typically within hours. It also retains a full timestamped history, so it can answer both "what is the current state?" and "what was the state at any past point in time?" Neither question requires manual effort to answer.
The Access Graph is the underlying data model — a graph structure of nodes (identities, applications, roles, groups, resources) and edges (access relationships between them). The Access Inventory is the structured, browsable, filterable, and exportable interface to that graph, designed for human consumption by security analysts, IT administrators, compliance officers, and auditors. The graph is the engine; the inventory is the view that practitioners interact with.
Resolving indirect access is one of the core capabilities of the Access Inventory. The underlying Access Graph traces every path from an identity to a resource — including paths that traverse group memberships, role hierarchies, delegated permissions, and OAuth application grants. Every such path is resolved and represented in the inventory as a typed access relationship with full path provenance shown. An inventory that only captures direct assignments is structurally incomplete; Oleria's inventory captures all access, regardless of how it is conferred.
Yes. Access certifications can be initiated directly from the Access Inventory in Trustfusion. The inventory pre-populates the certification scope with current, complete access data — filtered to the application, identity type, or risk tier the review covers. Reviewers certify or flag access within the Trustfusion UI, and their decisions are tracked to closure with a full audit trail. Because the inventory is live rather than a static export, reviewers are certifying actual current access — not a snapshot that was assembled weeks before the review began.
Yes, and this is a meaningful differentiator. Service accounts, shared accounts, OAuth application grants, API keys, managed identities, and automation pipeline identities are fully represented in the inventory alongside human identities. Each NHI shows its entitlement scope, assigned human steward, last-activity data, and open posture findings. NHIs are included in all inventory filters, exports, and certification workflows — not siloed into a separate tool or excluded from scope.
Oleria connectors poll source systems on a regular cadence and process event-based notifications where available. Access changes — new grants, role modifications, group membership updates, account deprovisioning — are typically reflected in the Access Inventory within hours of occurring in the source system. The inventory is designed to be operationally current, not just periodically refreshed.
SOX ITGC (IT General Controls) requires demonstrable evidence of who has access to financially significant systems, reviewed and certified regularly. SOC 2 Type II (CC6.1–CC6.3) requires logical access controls with evidence of provisioning, review, and revocation. ISO/IEC 27001 (A.9 Access Control) requires a maintained record of user access rights. NIST SP 800-53 (AC-2) mandates account management with documented access inventories. PCI DSS (Requirements 7 and 8) requires access to cardholder data restricted to need-to-know, with review evidence. Trustfusion's Access Inventory, combined with its certification and remediation history, provides the structured evidence these frameworks require — without the manual assembly effort that makes compliance programs expensive and error-prone.