For teams running SailPoint Identity Security Cloud
Know who loses access before they do.
Version history, impact analysis and drift detection for your identity platform.
Your platform will not tell you who a change removes, or when. We compute it from the configuration and tell you in the same minute.
Get early accessCut the stem anywhere. Hover a leaflet to see who hangs off it.
happens
The cut is instant. The fall is scheduled.
Someone edits a role's membership criterion — contractors no longer qualify. They save. No review, no approval, no version created. The screen looks exactly as it did a second ago.
− dept == "Finance" + dept == "Finance" && type == "FTE"
340 identities no longer qualify. Nothing on the screen says so.
The change is saved
Live in production configuration. No draft, no branch, no approval step.
Still green
Five hours and thirty-eight minutes in which the outcome is fixed and nothing anywhere shows it.
Every affected identity is already knowable at 14:22. It is simply never computed.
The fall
Identity processing runs. Roles recalculate. Entitlements are removed at the target systems.
The tickets start
Nobody connects them to a one-line edit made that morning.
Three hundred and forty people. Seven different reasons.
340 is not one group. It is seven separate grant paths, each with its own criterion, each losing access for a different reason. The number is knowable at 14:22 and so is every path behind it. Neither is ever computed.
tool knows
Every tool holds part of the answer.
Each of these is good at its job. We read your tenant and your repository, and compute the part neither of them holds.
Configuration backups
Terraform
Git
Sandbox
Every one of those answers what changed.
None of them answers who is affected.
So we read the tenant and the repository, and compute the rest.
does
Version control for your identity configuration.
Read-only. We resolve the configuration into every grant it produces, keep every version of it, and compare them.
Every version. Not the last few.
Each change to the tenant, kept and diffable — including the ones made by hand at two in the morning.
Who each change adds or removes.
Not “a criterion changed”. The people, grouped by the reason they qualified, with the time it takes effect.
criterion now requires type = FTE
effective 20:00
The tenant against what you deployed.
Where live configuration has moved away from the version in your repository, and which grants that difference produces.
Told at 14:23. Not by a ticket at 20:40.
The moment a change resolves to a loss of access, with the list, before the processing run reaches anyone.
Connects to SailPoint ISC·GitHub
The path, with the broken link marked.
Some leaves are attached to nothing.
275 from rules we cannot evaluate
299 orphaned — nothing produces them
connects
Read-only, by construction.
Never writes
A token carrying write scopes is refused at connection time, not warned about. There is no code path that changes your tenant.
No employee names
Identities are stored as native platform IDs. We do not hold names, email addresses or personal attributes.
Outbound only
Nothing opens a port in your network. Connecting takes about ten minutes.
Get early access.
We are onboarding a small number of teams who run identity platforms. If any of the above sounded familiar, tell us what you run and we will get you in.
Or just write to hello@lizar.id.