Use the map to see how one person's access connects — use the table to search or audit across everyone.
Drag any node to rearrange, hover for detail. Click a platform access node (teal) to view its role history or request a change — dashed rings/links mark grants pending approval. SSO-backed grants auto-close on approval; shared/local and service-account grants require a person to record completion notes before the ticket closes.
Note: where "Licenses" has no standalone entries for a user, bundled licenses (e.g. Google Workspace, Microsoft Entra) are folded into that user's platform access rows instead.
Register a new system for this directory to sync. The account type is set by whoever connects it — this tool never auto-detects SSO vs local, since that's a fact about the target system, not something it can infer from an API response alone.
Each user's record in this directory is assembled by syncing these systems. This page never talks to them directly — a backend sync service holds the credentials and writes into one identity store, which this page reads.
Accounts that exist in Entra, Google Workspace, or other systems but don't resolve to a person record from the HR platform — service accounts, API keys/app registrations, test accounts, and logins left behind by an incomplete offboarding. These sit outside the per-user map above and need separate review.