Identity Analysis & Hygiene
Find stale access before the auditor — or the attacker — does.
On-demand hygiene scans score inactive users, empty groups, stale devices, privileged exposure, and Entra license waste, then remediate with dry-run defaults and privileged-role guards. Role discovery promotes clean cohorts into access roles.
Product review
Interactive preview of the Rivitan portal — the same navigation and surfaces operators use, filled with realistic demo data.
Identity Analysis — scored hygiene findings, severity mix, and dry-run remediation on demo Rivitan data.
What this portal covers
- Hygiene scans with severity scoring
- Inactive / zombie identities (incl. privileged)
- Empty & unused / circular groups
- Stale devices (>180d)
- Privileged guest & nested exposure
- Entra license waste (E5 reclaim)
- Users / Groups / Devices drill-down views
- Role discovery with coverage %
- Promote cohorts into access roles
- Dry-run remediation · Preview / Apply / Export CSV
- Settings & activity trail
The problem
Directory debt accumulates quietly: disabled users still in groups, empty security groups nobody owns, stale devices, and over-licensed Entra seats. Spot checks miss it; annual audits rediscover the same mess.
What the platform does
- Unified hygiene scans with scored findings
- Inactive users, empty/zombie groups, stale devices
- Privileged exposure and Entra license waste signals
- Dry-run remediation by default (disable, delete empty group, retire device, dismiss)
- Confirm step and privileged-role guards on destructive actions
- Role discovery with coverage thresholds and catalog overlay
- Promote discovered roles into Access Roles
- Dedicated Identity Analysis portal
Who this is for
Identity and security teams that need directory hygiene and role discovery without a separate analytics product.
See Identity Analysis against your own environment
Book a walkthrough and we will show this capability end to end, then talk about what a pilot would look like for your estate.