An IT administrator holding an employee badge at a wall-mounted prox reader in a fluorescent corridor, a laptop cart and cable mess beside him.

CEDX Identity · Platform

Every principal, scored.
Every sign-in, explained.

Identity counts what most sign-in tools leave as opinion: 320 identities in the demo directory, MFA coverage at 81.4%, 80 privileged principals, and a posture score that tells you exactly which finding is holding it down.

The critical finding on the Overview is not vague: 30 privileged principals can sign in with push or TOTP only. The fix is named on the same panel as the symptom.

identity.cedxsystems.com — live build
CEDX Identity overview: active users, MFA coverage, high-reach principals, failed sign-ins, SSO apps, policy pass rate, posture health score and root-caused posture findings.

Runs on demo data. Northline Systems in the captures is the software's demo workspace, not a customer.

320 identities in the directory213 active — workforce plus service
81.4% MFA coveragewith 73 principals still on weak factors or none
56 SSO apps assignedand a 97.2% policy pass rate on sign-on evaluations

What it is

Three questions identity has to answer with evidence.

Who can get in, and on what factor

The Users table carries tier, MFA method and last login on every row: 320 identities, filterable to Active, Suspended, Staged and Deprovisioned. The MFA column does not round — Phishing-resistant, App push, TOTP, SMS and None are five different answers, and 73 principals are still on the weak end of that list.

  • 320 rows: user, dept, status, tier, MFA, apps, last login
  • Tiers run Standard, Elevated, Admin — 2 break-glass
  • CSV export of the view you are actually looking at
identity — users
Who can get in, and on what factor

Which groups carry the risk

Access ranks 48 groups by a risk score, not by name: break-glass-holders scores 98 with 3 members and 56 apps; org-admins 94; mfa-exempt-legacy 86. Nested inheritance is counted separately — 20 groups inherit risk they did not ask for — and 9 high-risk groups sit in a review queue.

  • 48 groups, 17 of them security groups with privileged paths
  • Risk, nested flag, owner and review date on every row
  • High risk (≥70) counted on the screen: 9 in the queue
identity — access
Which groups carry the risk

What the sign-on policy actually does

The policy library is 10 policies and 29 rules, each typed Sign-on, MFA, Session or Password, each either enforced or flagged Needs review. Workforce MFA reads like a sentence: any workforce user → MFA required, phishing-resistant preferred — 4 rules, 38 apps, priority 10.

  • 8 of 10 policies active and enforced; 2 in draft or review
  • Rule stack viewable per policy, not just a toggle
  • Geo anomaly block sits in Draft, visibly not enforced
identity — policies
What the sign-on policy actually does

Product tour

Four screens, captured from the running build.

Not a mockup and not a concept deck. This is what opens at /app/identity.

identity.cedxsystems.com
CEDX Identity Overview screen.CEDX Identity Users screen.CEDX Identity Access screen.CEDX Identity Policies screen.

01 — Overview

A posture score with its working shown

Posture health reads 73, and the panel says why: MFA coverage 81%, 213 active users, 53 high-reach principals, 56 failed auth events. Below it, findings arrive root-caused — admins without phishing-resistant MFA, counted at 30, marked critical.

  • Auth success versus failure, daily, on one chart
  • MFA factor mix: 52 phishing-resistant, 54 with none
  • Privilege tiers: 152 standard, 101 elevated, 65 admin, 2 break-glass

02 — Users

The directory as a table you can act on

Every identity — workforce and service — with department, status, tier, MFA method, app count and last login. Suspended and Staged are chips, not reports. A staged support account on SMS is visible in the same glance as an exec on phishing-resistant keys.

  • 80 privileged principals called out on the header cards
  • Active · Suspended · Staged · Deprovisioned as filters
  • Last login on every row, down to the day

03 — Access

Groups, scored by what they can reach

The group table shows members, apps, risk, nesting and owner together, so dyn-core-26 with 81 members and a 94 risk score reads differently from finance-approvers with 14 members at 72. Review dates are on the row — the queue is a list, not a calendar invite.

  • Security, Application and Dynamic groups in one view
  • Nested inheritance flagged per group
  • Owner initials on every row — no orphans in this list

04 — Policies

Rules you can read before they fire

Ten policies, typed and prioritised: Password baseline, Session hardening, MFA enrollment grace, Break-glass monitor. The two that need attention — a grace policy in review and a geo block in draft — are amber on the list, not discovered after an incident.

  • 29 rules across 10 policies
  • Sign-on · MFA · Session · Password filter chips
  • Needs-attention count on the header: 2

Who runs it

Three roles keep sign-in honest.

Roles, not references. We have no named customers yet, so nobody in these photographs is quoted, credited or claimed as one.

IT administration

Owns the directory and the factor mix. Watches the 73 principals still on weak MFA and works the list down, staged account by staged account.

MFA coverage · 81.4%

Security review

Works the high-risk group queue — 9 groups at 70 or above — and the review dates on the Access table, where break-glass-holders at 98 is the first row, not a surprise.

review queue · 9

Compliance

Reads posture findings as evidence: 30 admins without phishing-resistant MFA is a finding with a count and a fix, which is what an assessor asks for.

policy pass · 97.2%

The shape of it

What the demo workspace actually looks like.

Every figure below is legible in the captures above. Nothing here is a projection of your estate — it is the state of the demo data.

320identities in the directory213 active
80privileged principalsadmin + break-glass tiers
81.4%MFA coverage73 principals weak or none
73posture scorefindings name what holds it down
Posture findings, counted on screenmisconfiguration queue · click to inspect
  • Admins without phishing-resistant MFA — 30 privileged principals on push or TOTP only30
  • AI agents with standing admin scopes — always-on admin, no just-in-time envelope8
  • Agent principals without an owner — no accountable sponsor, scopes unreviewed6
MFA coveragestrong factors — no SMS, no none
  • Covered · 81.4% of the directory
  • Weak or none · 73 principals
Users by privilege tier320 directory identities
65+2
  • Standard and elevated · 253
  • Admin · 65, break-glass · 2

How it runs

A principal's life, in the order it actually happens.

01

Stage

An identity enters the directory as Staged — visible on the Users table with its tier and department before it can sign in to anything.

02

Enforce

Sign-on policy applies at login: Workforce MFA requires a factor, phishing-resistant preferred, across the 38 apps in its scope.

03

Score

Groups accumulate risk by what they reach. 48 groups are scored; 9 cross 70 and land in the review queue with an owner and a date.

04

Fix

Posture findings arrive root-caused — the 30 admins on weak factors are a counted list to work down, and the score moves when the list does.

One record

The same principals the rest
of the estate acts on.

Identity is not a bolt-on directory. The users, groups and policies it keeps are the ones the other products enforce against.

All 132 applications

Limits

What Identity does not do yet.

Finding this out on the third call is worse for you than reading it here, and worse for us.

Start

Open it before you talk to anyone.

Pilot

Your directory, your policies

  • Everything in Try
  • Directory-import plan
  • Policy-design workshop
  • Estate map
Talk to sales

Estate

Identity with the rest of it

  • Identity with Directory, Admin and Audit
  • One sign-in, one bill
  • CEDX delivery
Book an estate map

Questions

Before you pilot Identity.

Is the software on this page real?

Yes. Every screenshot is a capture of the running build and you can open the same build at /app/identity. It runs on demo data, which the page says next to the figures rather than in a footnote.

What does the posture score of 73 actually measure?

The panel shows its components: MFA coverage, active users, high-reach principals and failed auth events. The findings queue underneath names what would move it — 30 admins without phishing-resistant MFA is the critical one, and it is a counted list, not a trend line.

How are privileged accounts handled?

Privilege is a tier on the identity, visible on every row: Standard, Elevated, Admin, and a break-glass tier that holds exactly 2 principals in the demo directory. The 80 privileged principals are counted on the Users header, and groups that grant privileged paths are risk-scored on the Access table.

Can we see what a policy will do before enforcing it?

The policy library separates enforced policies from drafts and review states — 8 active, 2 needing attention in the captures — and each policy expands to its rule stack, type, app count and priority before you change anything.

Does Identity replace our existing sign-in provider?

That is a pilot question, not a page claim. The captures show 56 SSO apps assigned across the demo estate and policy evaluation on sign-on; which systems of yours sit behind that is what the estate map conversation is for.

Is Identity audited or certified?

No certification has been issued. What we can evidence about hosting, encryption, tenant isolation and production access is written up on the security page.

The console is running. Go and look at it.

Live build, demo data, no card. Then check how many of your own admins would pass the phishing-resistant test.