
Quick summary: Traditional identity-centric access controls fail to answer a critical question: who has access to your most sensitive data assets? By centralizing unstructured system logs into Oleria Trustfusion, an AI-native identity security platform, security teams can establish resource-centric data access governance across cloud databases, code repositories, and storage buckets. This live architecture exposes hidden group nesting and maps real-time data classification context to instantly eliminate over-exposed access footprints.
Security, IT, and data governance teams gain a continuously maintained, resource-centric view of access across every connected environment — surfacing who can reach any resource, through which entitlements, whether that access is actively used, and whether it is appropriate given the resource's sensitivity and the identity's current role. Resources include databases, schemas, repositories, SharePoint sites, Google Drive folders, cloud storage buckets, APIs, and any other asset whose access is governed through connected applications and platforms.
Why resource-centric visibility matters: Most identity security tools are identity-centric — they start with a person and show their access. But the most important access governance questions are often resource-centric: who has access to this production database, this customer data schema, this repository containing source code, this SharePoint site with board materials? Starting from the resource and asking "who can reach it?" is the natural question for data governance, compliance, and incident investigation — and it is the question that most tools cannot answer without significant manual effort.
Producing a complete, accurate answer to "who can access this resource?" is one of the most consistently difficult questions in enterprise identity security:
· Access is granted through multiple indirect paths. A user may reach a Snowflake schema through a direct role assignment, through a Snowflake role granted to an Entra ID group they belong to, or through an application account they control. Flat permission reports from the resource's admin console show only direct assignments — missing every indirect path. The true access population is almost always larger than a direct-permission export reveals.
· Resources span applications with no unified view. Sensitive resources exist across Snowflake schemas, GitHub repositories, SharePoint libraries, Google Drive shared drives, AWS S3 buckets, Salesforce record types, and more — each with its own permission model and admin console. No native tool spans all of them to produce a unified resource-centric access view.
· Data classification is not connected to the access model. Data governance and DLP tools identify where sensitive data exists but do not connect that classification to the identity layer to answer "who has access to this classified data?" That connection requires joining classification signals with the access model — a capability neither governance tools nor IDPs provide natively.
· Over-permissioned access to resources is never measured. Organizations rarely know the ratio of identities with access to a sensitive resource to those who actively use it. A Snowflake schema with 150 identities holding access but only 20 active users has 130 identities with standing access serving no current business purpose — invisible without a platform that joins access data with activity signals.
· Resource access changes without triggering a review. When a new user is added to a role that grants access to a sensitive resource, or when a resource is newly assigned to a large group, the change happens silently. There is no native mechanism to surface "this resource now has a larger access population" as an event requiring review.
Oleria Trustfusion models every resource in every connected application as a first-class object in the composite Access Graph — with every identity that can reach it, through every access path, enriched with activity signals, data classification context, and risk posture. Resource insights are queryable from the Access Inventory at any time, for any resource, without manual data assembly.

· Complete access population including indirect paths. For any resource in any connected application, the Access Graph surfaces every identity that can reach it: direct permission holders, role-based access holders, and group-inherited access holders — with full nesting resolution. No access path is hidden by indirect assignment.
· Full access path resolution per identity. The path by which each identity reaches the resource is shown — direct assignment, through which role, through which group, or through which combination of inherited relationships. Understanding the path matters for remediation: removing a direct permission requires a different action than removing a group membership that grants the same access.
· Active vs. dormant access population. For each resource, the access population is segmented by activity status: identities that have accessed the resource within the configured window, and those that hold access but have not used it. The ratio of active to dormant access holders is a direct measure of over-provisioning at the resource level.
· External and guest identity exposure. External identities — contractors, partners, guests — with any access to each resource are identified and highlighted. Resources with external access holders are flagged for review, particularly where the resource carries a sensitive or regulated data classification.
· Access population segmented by identity type and privilege. The resource profile distinguishes employees from contractors and guests, standard users from privileged account holders, and internal from external identities. Privileged account access to sensitive resources is highlighted as a distinct governance consideration.
· Data classification-aware resource posture. Resources tagged with sensitivity labels — from Microsoft Purview, Google Workspace classification, or administrator-applied tags — carry their classification tier in the resource profile. A classified resource with a large access population, dormant access holders, or external identity exposure generates posture findings that reflect the elevated risk of that combination.
· Over-exposure detection. Resources where the access population significantly exceeds the expected scope — a sensitive schema accessible to 200 identities when the owning team has 15 members, or a confidential library accessible organization-wide through a broad group — are flagged as over-exposed for governance review.
· Privileged access to sensitive resources. Identities that hold both a privileged role and access to a sensitive resource are surfaced as a compound risk finding. This intersection of high privilege and sensitive data access warrants the tightest governance.
· Access change detection for sensitive resources. When the access population of a classified resource grows — a new identity added, a large group newly assigned, an external member granted access — Trustfusion detects the change and generates a posture finding for review. Sensitive resource access does not expand silently between audits.
Stage 1 —Continuous Ingestion of Resource Configurations and Data Sensitivity Classifications: Oleria connectors ingest resource definitions and access assignments from every connected application: Snowflake schemas and databases, GitHub repositories, SharePoint sites and document libraries, Google Drive shared drives, Salesforce objects and record types, ServiceNow tables, AWS S3 buckets, Azure storage accounts, GCP storage buckets, and more. Data classification signals are ingested from Microsoft Purview and Google Workspace classification where available. All connections are read-only, using standard API credentials.
Stage 2 — Structural Representation of Data Nodes and Identity Edges Within the Access Graph: Resources are loaded as typed nodes in the Access Graph, classified by type and enriched with data classification tags. Every identity that can reach each resource is linked via typed access edges — direct, role-based, and group-inherited — with full nesting resolution. Activity data is applied per identity-resource pair to calculate active vs. dormant status.
Stage 3 — Automated Resource Posture Assessment and Exposure Event Detection: Oleria Trustfusion evaluates each resource's access posture: population size relative to sensitivity, dormant access holder thresholds, external identity presence in classified resources, privileged account access to high-sensitivity assets, and population growth events for monitored resources. Each violation generates a typed posture finding with resource context and remediation guidance.
Stage 4 — Multi-Dimensional Population Visualization and Targeted Posture Campaigns: Resource profiles surface in the Access Inventory with the full access population, dormancy status, and open findings in one view. Posture Campaigns drive right-sizing and access review assignments. Resource access history is retained for point-in-time queries, investigation support, and compliance evidence production.
· "Who can access this resource?" answered in seconds. The complete current access population — every identity, every access path, active vs. dormant — is available from the Access Inventory in seconds. No admin is needed, no exports required, no manual reconciliation.
· Sensitive resources have known, appropriate access populations. Every classified resource has a documented, reviewed access population proportionate to its business purpose. Dormant access holders are removed on a defined cadence. External access is documented with business justification.
· No unexplained growth in sensitive resource access populations. Access population changes for monitored resources generate immediate posture findings. Sensitive resource access does not expand silently.
· Dormant resource access trending to zero. The ratio of dormant to active access holders across sensitive resources is tracked as a metric and trends downward as right-sizing campaigns remove standing access with no active business purpose.
· Resource-centric access reviews from live data. Reviews use current, complete population data with activity status pre-populated. Data owners certify against live information, not a manually assembled quarterly export.
· Point-in-time resource access evidence on demand. Any investigation or audit question about resource access at a past point in time is answerable from Trustfusion directly — without log reconstruction.

DLP tools tell you where sensitive data sits, and IDPs tell you who logged into the network—but neither tool exposes the nested group paths giving unapproved identities access to your core infrastructure. Eliminate your standing data risk—book a personalized demo today to see Oleria Trustfusion's resource-centric visibility in action.
Oleria models resources based on what each application connector exposes via API. Current coverage includes: Snowflake databases, schemas, and tables; GitHub repositories and organizations; SharePoint sites, subsites, and document libraries; Google Drive shared drives and folders; Salesforce objects and record types; ServiceNow tables and applications; AWS S3 buckets and IAM policy scopes; Azure storage accounts and RBAC-governed resources; GCP storage buckets and IAM bindings; and Microsoft 365 Teams and channels. Coverage expands with each new connector added.
The Access Graph resolves all access paths, not just direct assignments. For a Snowflake schema accessible through a Snowflake role that is granted to an Entra ID group, Trustfusion traverses the full path: identifies every member of the group, follows the group-to-role assignment, and attributes schema access to every identity in the group. The resource's access population therefore includes all direct and indirect access holders — with the full derivation path shown for each.
Oleria ingests data classification signals from Microsoft Purview sensitivity labels, Google Workspace data classification, and administrator-applied tags in Trustfusion. Classified resource nodes carry their tier as an attribute — enabling filtering, posture evaluation, and audit evidence production based on classification level across all resource types and applications.
Oleria uses the most specific activity signal available from each connector — last-access events for the specific resource where available, falling back to application-level last-activity. An identity-resource pair is classified as dormant when no activity signal falls within the configured window for that resource type. Thresholds are configurable by resource type and sensitivity tier.
Yes. The Access Graph tracks access population over time. When a new identity is granted access, a group assignment adds a large population, or a role modification brings new members in scope, the change is detected and evaluated. For classified resources, any population growth generates an immediate posture finding regardless of size. For standard resources, growth beyond a configured threshold triggers a review finding.
SOX ITGC requires evidence that access to financially significant systems is restricted to authorized personnel and reviewed. SOC 2 Type II (CC6.1 and CC6.3) requires appropriate access controls and evidence of review. HIPAA requires minimum-necessary access to PHI systems with review evidence. PCI DSS v4.0 (Requirement 7) requires access to cardholder data restricted to need-to-know. GDPR and CCPA require demonstrable controls over access to personal data. ISO/IEC 27001 (A.9.4) requires access control to systems and applications. Trustfusion's resource access inventory, posture findings, and point-in-time query capability provide the evidence these frameworks require.