// access and identity
Identities judged on what they actually did
L4 does not count accounts. It counts identities whose logged activity was out of scope or needs a human to look at it.
// what it watches
What this layer watches
Access & Identity reports “Set Up” until the right integration is connected, because until then there is nothing honest to say about it. A platform that showed you green here would be describing an environment it cannot see.
- Single sign-on coverage and the accounts that sit outside it
- Multi-factor enforcement, and where it is absent
- Role-based access: who holds what entitlement on which resource, recertified during an access review
- Session management, and activity logged against each identity
// what turns it red
What turns it red
Each row is a live measurement on your own environment, not a checklist item. The third column is the part a compliance-first tool cannot offer.
| What is measured | What it says | Where clicking it takes you |
|---|---|---|
| Identities whose logged activity was marked out of scope for what they hold | N Users Need Fixing | The access review surface, entitlements and activity side by side |
| Identities whose activity needs a human to review it before it can be judged | N Users Need Fixing | The same surface, with the activity in question surfaced |
| Non-privileged identities taking privileged or destructive actions | N Users Need Fixing | The identity record and the actions it took |
| Privileged identities taking destructive actions against production | N Users Need Fixing | The identity record and the resources affected |
| Entitlements held on real resources, recertified as retain, modify or revoke | N Users Need Fixing | The entitlement record and its decision history |
| Whether an identity provider is connected at all | Set Up | The integrations directory, pre-filtered to identity providers |
This table is not the whole check
Single sign-on coverage, multi-factor enforcement, session policy and joiner-mover-leaver handling all feed the same identity spine. The count above is what is currently wrong, not the full set of things checked.
// getting to green
What it takes to go green
- Connect your identity provider so entitlements and activity land on the same spine.
- Activity is assessed against the identity's categorisation, which is how out-of-scope actions surface at all.
- Anything questionable becomes a review item with a decision attached: retain, modify or revoke.
- The layer clears when no identity carries activity that is out of scope or awaiting review.
// the evidence
The evidence this produces
None of this is collected for the auditor's benefit. It is the by-product of work that had to happen anyway, which is why it holds up when someone checks.
- Access control evidence required by every framework the platform supports
- Completed access reviews with a named reviewer, a date and the decisions taken — read the access review playbook
- Proof that privileged access in particular was reviewed, not sampled
// questions this answers
Access and identity coverage, answered directly
What does L4 actually count?
Identities whose logged activity was marked out of scope or as needing review. It deliberately does not count accounts or permissions, because the number of accounts you hold says nothing about whether they were used appropriately.
How is this different from a standard access review?
A standard review shows a reviewer a list of names and entitlements. Konfirmity puts the entitlement and the identity's real logged activity over the same period side by side, so the reviewer can see whether the access was used and how.
Which identity providers are supported?
Google Workspace and Microsoft Entra back the L4 measurement, alongside the wider identity and access connector catalogue used for entitlement collection.
// keep reading
Where this goes deeper
Want to see this one live?
Book 30 minutes and we will walk through “Identities judged on what they actually did” in the actual platform, using your environment as the example.