Every identity in the demo directory — 340 of them — carries a source system, a status, a kind and an owner. The ones that do not are not a discovery project: they are a scored queue of 160 orphan rows.
The alert that matters is one line: 48 identities have source = None. Nothing federates, nothing syncs, and the directory says so on its own front page.
directory.cedxsystems.com — live build
Runs on demo data. Northline Systems in the captures is the software's demo workspace, not a customer.
160 groups, 16 of them emptyarchive candidates, counted on screen
78.8% owner coveragethe 78.8% of groups that have an owner at all
What it is
A directory earns its keep in three places.
Every identity knows where it came from
The Users table carries source on every row — HRIS, LDAP, Cloud IdP or Manual — next to kind, status, group count and a profile-completeness bar. The header does the arithmetic for you: 340 identities, 230 active, and 48 with no source at all.
HRIS · LDAP · Cloud IdP · Manual as source values
Workforce and Contractor separated as kinds
Profile completeness as a percentage on every row
directory — screen-3
Orphan risk is a score, not a hunch
Hygiene scores all 160 orphan rows and puts the worst on top: ghost-hire-09 at 86, three service accounts at 70–80, each with its top signal printed — no authoritative source system. Filter chips at 30, 45 and 70 turn the list into a work queue.
Cleanup simulator and scoring model are tabs, not promises
directory — screen-2
Groups with sprawl measured
160 groups, and the table shows why some are a problem: all-employees with 280 members, tmp-old-81 with 106 and a nested flag, 16 sitting empty. Sprawl has a number — the worst group on the Overview scores 76 — and 34 groups have no owner at all.
Type, members, owner, nested, empty and review on a row
Department · Application · Dynamic · Distribution chips
16 empty groups called out as archive candidates
directory — screen-4
Product tour
Four screens, captured from the running build.
Not a mockup and not a concept deck. This is what opens at /app/directory.
directory.cedxsystems.com
01 — Overview
Hygiene as a score with a queue behind it
Hygiene health reads 84, with the components beside it: owner coverage 79%, 230 active users, 16 high-orphan accounts, 8 high-sprawl groups. The alerts are root-caused — 26 near-duplicate group pairs, 31 leavers past SLA, one service account active with no manager and no source.
176 lifecycle rows open in the joiner-mover-leaver queue
02 — Users
The roster, with provenance
340 rows where the columns do the governance work: source system, kind, status, group count, profile percentage, last login. A suspended engineer sourced from Manual next to an active exec from HRIS is the whole story of the directory in two rows.
1–25 of 340 users, CSV on the view
Active · Suspended · Staged · Deprovisioned chips
Group membership counted per identity
03 — Hygiene
Orphans and sprawl, scored
The orphan tab ranks accounts by score and prints the signal that produced it — no authoritative source system on the top rows. Group sprawl, the cleanup simulator and the scoring model are one tab over, so the rule is inspectable, not magic.
Score filters: all, ≥30, ≥45, ≥70
ghost-hire-09 tops the board at 86
Kind, department and last login on every row
04 — Groups
Where sprawl actually lives
all-employees at 280 members is expected; tmp-old-81 at 106 with a nested flag is not, and the table lets you see both at once. Empty groups are counted (16) and ownerless groups are counted (34), because those are the two ways a group becomes a problem.
160 groups, 32 of them security groups
Owner and review date on every row
8 groups cross the high-sprawl line (≥55)
Who runs it
Three roles keep the record clean.
Roles, not references. We have no named customers yet, so nobody in these photographs is quoted, credited or claimed as one.
People operations
Owns the joiner-mover-leaver queue. The 176 open lifecycle rows and the 31 leavers past SLA are their Monday list, not a quarterly project.
lifecycle open · 176
IT administration
Owns the source mix. Every identity on Manual or None is theirs to reconcile — 110 rows in the demo directory between the two.
no source · 48
Governance
Owns the review dates on the group table and the owner coverage number — 78.8% is the figure they report, and the 34 ownerless groups are the gap.
owner coverage · 78.8%
The shape of it
What the demo workspace actually looks like.
Every figure below is legible in the captures above. Nothing here is a projection of your estate — it is the state of the demo data.
340identities in the directory230 active
48identities with no source systemorphan signal
160groups in the tenant16 empty · 34 ownerless
84hygiene scorecomponents printed beside it
Where identities come fromsource mix · authoritative binding
HRIS — the authoritative feed150
Manual — entered by hand, owned by IT62
None — no source system at all48
Cloud IdP41
LDAP39
Owner coverage on groupsgroups with an accountable owner
Owned · 78.8% of 160 groups
Ownerless · 34 groups
Users by status340 directory identities
230
Active · 230
Staged 37 · suspended 36 · deprovisioned 37
How it runs
Directory hygiene, in the order it actually happens.
01
Join
A hire lands from HRIS as Staged with a source system attached — one of the 150 HRIS-sourced records, not a manual entry someone will forget.
02
Move
Org changes update the record and its groups; the lifecycle queue holds 176 open rows so a mover does not keep last quarter's access by inertia.
03
Score
Nightly, orphans and sprawl get numbers: 160 accounts scored, 16 over the action line, 8 groups past the sprawl threshold.
04
Leave
Leavers deprovision against an SLA. The 31 rows past it are an alert with a cause, not a discovery at the next audit.
One record
The roster every other product reads from.
Directory is the source of truth the rest of the estate consumes — the same identities, scored for hygiene here, secured and priced elsewhere.
Finding this out on the third call is worse for you than reading it here, and worse for us.
Directory is not generally available. What opens today is the live build running on demo data — Northline Systems in the captures is the software's demo workspace, not a customer.
We have no named customers to show you, so this page shows none. The people named inside the demo captures are fictional rows in demo data.
The source mix in the captures is HRIS, LDAP, Cloud IdP and Manual. Which specific HR and identity systems we bind to is a pilot conversation, not a claim this page makes.
The hygiene and orphan scores are computed on the demo tenant's 340 identities. Your scores will differ; the point is that the scoring model is a visible tab, not a black box.
No audit or compliance certification has been issued for Directory. What we can evidence about hosting, encryption and access is on the security page.
Yes. Every screenshot is a capture of the running build and you can open the same build at /app/directory. It runs on demo data, which the page says next to the figures rather than in a footnote.
What is an orphan account, exactly?
An identity nothing authoritative claims. The Hygiene screen scores them — 160 rows in the demo directory — and prints the top signal on each row; the highest-scored ones simply read no authoritative source system, with a score like 86 attached.
How does the directory stay current?
Through the source mix on the Overview: 150 identities arrive from HRIS, 41 from a cloud identity provider, 39 from LDAP, 62 are manual. The lifecycle queue holds 176 open joiner-mover-leaver rows, and leavers past SLA are an alert — 31 of them in the demo data.
What counts as sprawl?
A group whose membership score crosses the threshold — 55 in the demo configuration. Eight groups are past it, led by review and temporary groups at 76, and the 16 empty groups are counted separately as archive candidates.
Can we keep our existing HR system as the source?
That is the design: HRIS is the authoritative feed for most of the demo directory. Which systems bind in your estate is what the estate map conversation works through.
Is Directory audited or certified?
No certification has been issued. What we can evidence about hosting, encryption, tenant isolation and production access is written up on the security page.
The console is running. Go and look at it.
Live build, demo data, no card. Then ask how many identities in your own directory have no source at all.