lizar IGA version control
PLATE I

For teams running SailPoint Identity Security Cloud

Know who loses access before they do.

Version history, impact analysis and drift detection for your identity platform.

Your platform will not tell you who a change removes, or when. We compute it from the configuration and tell you in the same minute.

Get early access
Fraxinus excelsior Tenant ACME-PROD Role FINANCE-READER n = 512 identities on 11 grant paths

Cut the stem anywhere. Hover a leaflet to see who hangs off it.

What happens in your tenant What Lizar does
14:22 · criterion saved One line changes Version recorded. Diff computed.
still green 14:22 340 identified, by name of grant, at 14:23.
20:00 · identity processing run The fall You knew five hours and thirty-seven minutes ago.
dieback · distal to the cut 340 identities With the path that granted it, and the one that broke.
PLATE II
What actually
happens

The cut is instant. The fall is scheduled.

Someone edits a role's membership criterion — contractors no longer qualify. They save. No review, no approval, no version created. The screen looks exactly as it did a second ago.

ROLE Finance-Reader membership criterion saved 14:22 by a.moreno
− dept == "Finance"
+ dept == "Finance" && type == "FTE"

340 identities no longer qualify. Nothing on the screen says so.

14:22

The change is saved

Live in production configuration. No draft, no branch, no approval step.

14:22

Still green

Five hours and thirty-eight minutes in which the outcome is fixed and nothing anywhere shows it.

Every affected identity is already knowable at 14:22. It is simply never computed.

20:00

The fall

Identity processing runs. Roles recalculate. Entitlements are removed at the target systems.

20:40

The tickets start

Nobody connects them to a one-line edit made that morning.

No reviewnobody signs it off No approvalnobody is asked No versionnothing to compare No undonothing to roll back
PLATE III
The canopy

Three hundred and forty people. Seven different reasons.

340 is not one group. It is seven separate grant paths, each with its own criterion, each losing access for a different reason. The number is knowable at 14:22 and so is every path behind it. Neither is ever computed.

Fraxinus excelsior Tenant ACME-PROD Row length proportional to identities 340 in dieback
340 of 512 · across 7 grant paths · 0 of them listed anywhere in your tenant
PLATE IV
What each
tool knows

Every tool holds part of the answer.

Each of these is good at its job. We read your tenant and your repository, and compute the part neither of them holds.

Configuration backups

A handful of capped snapshots. Built for disaster recovery, so it keeps the last few states rather than every one.

Terraform

Manages part of the configuration, and tells you a criterion changed. It cannot tell you who that criterion covers.

Git

The record of what you deployed. It cannot see what someone clicked in the tenant at two in the morning — which is the half we fill in.

Sandbox

A different identity population, and it drifts from production. You can test the mechanism there. You cannot find the 340 — they do not exist in that tenant.

Every one of those answers what changed.

None of them answers who is affected.

So we read the tenant and the repository, and compute the rest.

PLATE V
What it
does

Version control for your identity configuration.

Read-only. We resolve the configuration into every grant it produces, keep every version of it, and compare them.

01History

Every version. Not the last few.

Each change to the tenant, kept and diffable — including the ones made by hand at two in the morning.

02Impact

Who each change adds or removes.

Not “a criterion changed”. The people, grouped by the reason they qualified, with the time it takes effect.

340 lose Finance-Reader
criterion now requires type = FTE
effective 20:00
03Drift

The tenant against what you deployed.

Where live configuration has moved away from the version in your repository, and which grants that difference produces.

04Alerts

Told at 14:23. Not by a ticket at 20:40.

The moment a change resolves to a loss of access, with the list, before the processing run reaches anyone.

14:23Lizar 20:40the first ticket

Connects to SailPoint ISC·GitHub

05Provenance

The path, with the broken link marked.

06Coverage

Some leaves are attached to nothing.

99.2% resolve to a configuration path
275 from rules we cannot evaluate
299 orphaned — nothing produces them
PLATE VI
How it
connects

Read-only, by construction.

Never writes

A token carrying write scopes is refused at connection time, not warned about. There is no code path that changes your tenant.

No employee names

Identities are stored as native platform IDs. We do not hold names, email addresses or personal attributes.

Outbound only

Nothing opens a port in your network. Connecting takes about ten minutes.

Get early access.

We are onboarding a small number of teams who run identity platforms. If any of the above sounded familiar, tell us what you run and we will get you in.

Or just write to hello@lizar.id.