Every principal, scored. Every sign-in, explained.
Identity counts what most sign-in tools leave as opinion: 320 identities in the demo directory, MFA coverage at 81.4%, 80 privileged principals, and a posture score that tells you exactly which finding is holding it down.
The critical finding on the Overview is not vague: 30 privileged principals can sign in with push or TOTP only. The fix is named on the same panel as the symptom.
identity.cedxsystems.com — live build
Runs on demo data. Northline Systems in the captures is the software's demo workspace, not a customer.
320 identities in the directory213 active — workforce plus service
81.4% MFA coveragewith 73 principals still on weak factors or none
56 SSO apps assignedand a 97.2% policy pass rate on sign-on evaluations
What it is
Three questions identity has to answer with evidence.
Who can get in, and on what factor
The Users table carries tier, MFA method and last login on every row: 320 identities, filterable to Active, Suspended, Staged and Deprovisioned. The MFA column does not round — Phishing-resistant, App push, TOTP, SMS and None are five different answers, and 73 principals are still on the weak end of that list.
320 rows: user, dept, status, tier, MFA, apps, last login
Tiers run Standard, Elevated, Admin — 2 break-glass
CSV export of the view you are actually looking at
identity — users
Which groups carry the risk
Access ranks 48 groups by a risk score, not by name: break-glass-holders scores 98 with 3 members and 56 apps; org-admins 94; mfa-exempt-legacy 86. Nested inheritance is counted separately — 20 groups inherit risk they did not ask for — and 9 high-risk groups sit in a review queue.
48 groups, 17 of them security groups with privileged paths
Risk, nested flag, owner and review date on every row
High risk (≥70) counted on the screen: 9 in the queue
identity — access
What the sign-on policy actually does
The policy library is 10 policies and 29 rules, each typed Sign-on, MFA, Session or Password, each either enforced or flagged Needs review. Workforce MFA reads like a sentence: any workforce user → MFA required, phishing-resistant preferred — 4 rules, 38 apps, priority 10.
8 of 10 policies active and enforced; 2 in draft or review
Rule stack viewable per policy, not just a toggle
Geo anomaly block sits in Draft, visibly not enforced
identity — policies
Product tour
Four screens, captured from the running build.
Not a mockup and not a concept deck. This is what opens at /app/identity.
identity.cedxsystems.com
01 — Overview
A posture score with its working shown
Posture health reads 73, and the panel says why: MFA coverage 81%, 213 active users, 53 high-reach principals, 56 failed auth events. Below it, findings arrive root-caused — admins without phishing-resistant MFA, counted at 30, marked critical.
Auth success versus failure, daily, on one chart
MFA factor mix: 52 phishing-resistant, 54 with none
Every identity — workforce and service — with department, status, tier, MFA method, app count and last login. Suspended and Staged are chips, not reports. A staged support account on SMS is visible in the same glance as an exec on phishing-resistant keys.
80 privileged principals called out on the header cards
Active · Suspended · Staged · Deprovisioned as filters
Last login on every row, down to the day
03 — Access
Groups, scored by what they can reach
The group table shows members, apps, risk, nesting and owner together, so dyn-core-26 with 81 members and a 94 risk score reads differently from finance-approvers with 14 members at 72. Review dates are on the row — the queue is a list, not a calendar invite.
Security, Application and Dynamic groups in one view
Nested inheritance flagged per group
Owner initials on every row — no orphans in this list
04 — Policies
Rules you can read before they fire
Ten policies, typed and prioritised: Password baseline, Session hardening, MFA enrollment grace, Break-glass monitor. The two that need attention — a grace policy in review and a geo block in draft — are amber on the list, not discovered after an incident.
29 rules across 10 policies
Sign-on · MFA · Session · Password filter chips
Needs-attention count on the header: 2
Who runs it
Three roles keep sign-in honest.
Roles, not references. We have no named customers yet, so nobody in these photographs is quoted, credited or claimed as one.
IT administration
Owns the directory and the factor mix. Watches the 73 principals still on weak MFA and works the list down, staged account by staged account.
MFA coverage · 81.4%
Security review
Works the high-risk group queue — 9 groups at 70 or above — and the review dates on the Access table, where break-glass-holders at 98 is the first row, not a surprise.
review queue · 9
Compliance
Reads posture findings as evidence: 30 admins without phishing-resistant MFA is a finding with a count and a fix, which is what an assessor asks for.
policy pass · 97.2%
The shape of it
What the demo workspace actually looks like.
Every figure below is legible in the captures above. Nothing here is a projection of your estate — it is the state of the demo data.
320identities in the directory213 active
80privileged principalsadmin + break-glass tiers
81.4%MFA coverage73 principals weak or none
73posture scorefindings name what holds it down
Posture findings, counted on screenmisconfiguration queue · click to inspect
Admins without phishing-resistant MFA — 30 privileged principals on push or TOTP only30
AI agents with standing admin scopes — always-on admin, no just-in-time envelope8
Agent principals without an owner — no accountable sponsor, scopes unreviewed6
MFA coveragestrong factors — no SMS, no none
Covered · 81.4% of the directory
Weak or none · 73 principals
Users by privilege tier320 directory identities
65+2
Standard and elevated · 253
Admin · 65, break-glass · 2
How it runs
A principal's life, in the order it actually happens.
01
Stage
An identity enters the directory as Staged — visible on the Users table with its tier and department before it can sign in to anything.
02
Enforce
Sign-on policy applies at login: Workforce MFA requires a factor, phishing-resistant preferred, across the 38 apps in its scope.
03
Score
Groups accumulate risk by what they reach. 48 groups are scored; 9 cross 70 and land in the review queue with an owner and a date.
04
Fix
Posture findings arrive root-caused — the 30 admins on weak factors are a counted list to work down, and the score moves when the list does.
One record
The same principals the rest of the estate acts on.
Identity is not a bolt-on directory. The users, groups and policies it keeps are the ones the other products enforce against.
Finding this out on the third call is worse for you than reading it here, and worse for us.
Identity is not generally available. What opens today is the live build running on demo data — Northline Systems in the captures is the software's demo workspace, not a customer.
We have no named customers to show you, so this page shows none. The people named inside the demo captures are fictional rows in demo data.
The posture score of 73 and the findings behind it are the demo tenant's. We are not claiming your estate would score better or worse — only that the score shows its working.
The captures show SSO assignment and policy evaluation across 56 apps. They do not evidence every provisioning connector you might ask about; the integration catalogue is not something this page claims.
No audit or compliance certification has been issued for Identity. What we can evidence about hosting, encryption and access is on the security page.
Yes. Every screenshot is a capture of the running build and you can open the same build at /app/identity. It runs on demo data, which the page says next to the figures rather than in a footnote.
What does the posture score of 73 actually measure?
The panel shows its components: MFA coverage, active users, high-reach principals and failed auth events. The findings queue underneath names what would move it — 30 admins without phishing-resistant MFA is the critical one, and it is a counted list, not a trend line.
How are privileged accounts handled?
Privilege is a tier on the identity, visible on every row: Standard, Elevated, Admin, and a break-glass tier that holds exactly 2 principals in the demo directory. The 80 privileged principals are counted on the Users header, and groups that grant privileged paths are risk-scored on the Access table.
Can we see what a policy will do before enforcing it?
The policy library separates enforced policies from drafts and review states — 8 active, 2 needing attention in the captures — and each policy expands to its rule stack, type, app count and priority before you change anything.
Does Identity replace our existing sign-in provider?
That is a pilot question, not a page claim. The captures show 56 SSO apps assigned across the demo estate and policy evaluation on sign-on; which systems of yours sit behind that is what the estate map conversation is for.
Is Identity audited or certified?
No certification has been issued. What we can evidence about hosting, encryption, tenant isolation and production access is written up on the security page.
The console is running. Go and look at it.
Live build, demo data, no card. Then check how many of your own admins would pass the phishing-resistant test.