Konfirmity
Layer 4 of 7 — Access & Identity

// access and identity

Identities judged on what they actually did

L4 does not count accounts. It counts identities whose logged activity was out of scope or needs a human to look at it.

// what it watches

What this layer watches

Access & Identity reports “Set Up” until the right integration is connected, because until then there is nothing honest to say about it. A platform that showed you green here would be describing an environment it cannot see.

  • Single sign-on coverage and the accounts that sit outside it
  • Multi-factor enforcement, and where it is absent
  • Role-based access: who holds what entitlement on which resource, recertified during an access review
  • Session management, and activity logged against each identity

// what turns it red

What turns it red

Each row is a live measurement on your own environment, not a checklist item. The third column is the part a compliance-first tool cannot offer.

What is measuredWhat it saysWhere clicking it takes you
Identities whose logged activity was marked out of scope for what they holdN Users Need FixingThe access review surface, entitlements and activity side by side
Identities whose activity needs a human to review it before it can be judgedN Users Need FixingThe same surface, with the activity in question surfaced
Non-privileged identities taking privileged or destructive actionsN Users Need FixingThe identity record and the actions it took
Privileged identities taking destructive actions against productionN Users Need FixingThe identity record and the resources affected
Entitlements held on real resources, recertified as retain, modify or revokeN Users Need FixingThe entitlement record and its decision history
Whether an identity provider is connected at allSet UpThe integrations directory, pre-filtered to identity providers

This table is not the whole check

Single sign-on coverage, multi-factor enforcement, session policy and joiner-mover-leaver handling all feed the same identity spine. The count above is what is currently wrong, not the full set of things checked.

See how deep we go

// getting to green

What it takes to go green

  1. Connect your identity provider so entitlements and activity land on the same spine.
  2. Activity is assessed against the identity's categorisation, which is how out-of-scope actions surface at all.
  3. Anything questionable becomes a review item with a decision attached: retain, modify or revoke.
  4. The layer clears when no identity carries activity that is out of scope or awaiting review.

// the evidence

The evidence this produces

None of this is collected for the auditor's benefit. It is the by-product of work that had to happen anyway, which is why it holds up when someone checks.

  • Access control evidence required by every framework the platform supports
  • Completed access reviews with a named reviewer, a date and the decisions taken — read the access review playbook
  • Proof that privileged access in particular was reviewed, not sampled

// questions this answers

Access and identity coverage, answered directly

What does L4 actually count?

Identities whose logged activity was marked out of scope or as needing review. It deliberately does not count accounts or permissions, because the number of accounts you hold says nothing about whether they were used appropriately.

How is this different from a standard access review?

A standard review shows a reviewer a list of names and entitlements. Konfirmity puts the entitlement and the identity's real logged activity over the same period side by side, so the reviewer can see whether the access was used and how.

Which identity providers are supported?

Google Workspace and Microsoft Entra back the L4 measurement, alongside the wider identity and access connector catalogue used for entitlement collection.

Want to see this one live?

Book 30 minutes and we will walk through “Identities judged on what they actually did” in the actual platform, using your environment as the example.

Book a demo