IDENTITY SECURITY · OLLANDI DIP

Monitor human and machine identity, sessions, credentials, privilege, and access behavior across infrastructure.

Specialized identity security that contributes live evidence and domain actions to Ollandi’s cross-domain defense loop.

Compare all DIPs

From domain telemetry to a decision operators can use.

01 · MONITORS
  • Authentication and MFA activity
  • Human and machine sessions
  • Roles, permissions, and privilege changes
  • Identity reach across cloud, endpoints, workloads, and services
02 · DETECTS
  • Credential misuse and MFA fatigue
  • Unusual privilege use
  • Session and token abuse
  • Service-account behavior outside expected scope
03 · EXPLAINS
  • Whether behavior fits role and history
  • What the identity can reach
  • Which actions followed authentication
  • The evidence supporting legitimate use, drift, or compromise
04 · ENABLES RESPONSE
  • Require step-up authentication
  • Revoke or revalidate sessions
  • Temporarily suspend sensitive privilege
  • Escalate credential rotation or account action
COVERAGE

The context this DIP brings into Ollandi.

The DIP normalizes domain evidence with source and time preserved. Ollandi then relates it to other DIPs, service dependencies, policy, authority, and historical state.

  • Identity-provider logs
  • MFA and device signals
  • Session and token records
  • Access graphs and role policies
  • Cloud, endpoint, and runtime activity
  • Approved change context
IDENTITY DIPPrivilege reach
Session
Role chain
Machine identity
Protected service
IDENTITY
CONTEXT
Connected to shared infrastructure context

See how the Identity DIP moves from signal to verified outcome.

01Observe

A valid MFA session appears from a new device and geography.

02Interpret

Privileged operations follow. Ollandi tests travel, delegated access, and credential misuse.

03Contain

Step-up authentication and temporary privilege suspension are selected as reversible actions.

04Verify

The session state, operator decision, and evidence bundle remain available for review.

The DIP supplies depth. Ollandi supplies the shared state, threat reasoning, action validation, and evidence.

Domain stateCross-domain hypothesisPolicy-checked actionVerified evidence
See the complete Ollandi lifecycle