13 connectors. 778 users.
6 anomalies. One audit-grade gap.
A quarterly access review across 13 identity connectors. The agent surfaced six findings: a test account, three dormancy candidates, and an unjustified-entitlement flag. None rose above Medium risk. The bigger finding was the process gap itself: two SOC2 CC6.3 heuristics could not be evaluated for 778 users because group and role data were unavailable from any connector. The agent surfaced the gap as an audit risk, not as a workaround.
This case never started with an alert. It started with a scheduled compliance obligation. The agent produced audit-shaped evidence, named accounts, named coverage gaps, named remediation actions.
“H3 and H4 not assessable for 778 users” is exactly what auditors need to see, stated explicitly, with a remediation plan, to discharge their CC6.3 review.
13 connectors queried. One review. The same mesh that surfaces threat indicators surfaces entitlement drift. CISOs and auditors read different sections of the same artifact.
Process intent ≠ process evidence.
The agent applied six heuristics from the access-review skill against the 13 connected identity sources. The aggregate evaluation status, not the per-user findings, is what an auditor reads first:
| Heuristic | Threshold | Status | Coverage note |
|---|---|---|---|
| H1 Dormant Accounts | 90 days no login | PARTIAL | No last_login_time field on most connectors |
| H2 Orphaned Accounts | Not in authoritative directory | PARTIAL | Auth0 has 6 users; Entra has 778. Domain mismatch prevents cross-reference |
| H3 Excessive Privilege | Admin on >3 systems | SKIPPED | No group/role data on any connector. CC6.3 audit risk |
| H4 SoD Violations | Common conflict pairs | SKIPPED | Same gap as H3. CC6.3 audit risk |
| H5 Stale Service Accounts | 60 days no activity | PARTIAL | Auth0 only. 1 finding (external gmail account) |
| H6 Unjustified Entitlement | No baseline match | EVALUATED | No baseline document discovered. 6 accounts flagged for certification |
Two of six heuristics could not be applied at all. Both map to what SOC2 CC6.3 specifically requires evidence of: least privilege and separation of duties. The agent did not paper over this. It surfaced the skip as Finding 5: “Heuristics 3 & 4 Not Assessable, Process Gap [High Process Risk].”
Two controls. Three statuses. One honest answer.
The report’s auditor note is the load-bearing sentence: “This review establishes the access review process and demonstrates the intent to comply with CC6.1 and CC6.3. However, the absence of group / role data means least-privilege and SoD evidence cannot be provided at this time. A remediation plan is included in the Coverage Gap Report.”
The agent’s job here is not to invent the evidence the connectors didn’t return. It’s to produce audit-shaped documentation of what we asked, what we got, what we did not get, and what we’ll do about it.
Five accounts. Each with named action.
- F1 [Medium]. External
query.e2e+stage-***@gmail.comin corporate Auth0. Null UID, test-account naming. Action: Investigate; revoke if production. - F2 [Low / Insufficient Data].
aejay.g***@query.aidormancy candidate (72 days no inventory record, approaching 90d threshold). Action: confirm active status in Auth0 admin console. - F3 [Low / Insufficient Data].
akash.s***@query.aidormancy candidate (59 days). Action: investigate. - F4 [Low, Mitigated].
jonathan.r***@query.aidormancy candidate (57 days). Mitigating evidence: Intune device “j.r***” active today. Action: low-priority, confirm device ownership. - F5 [HIGH Process Risk]. Scope: all 778 users. Group / role data unavailable across all connectors. Action: remediate connector configurations.
- F6 [Low]. All 6 Auth0 users lack access-request baseline. Action: certify with manager approval, then establish baseline.
Five named accounts, six findings, every one with an explicit action verb (Investigate / Revoke / Confirm / Remediate / Certify). No “review and assess” hand-waves. No “consult an analyst” deferrals.
Auditor evidence is the schema for the output.
The report’s structure, heuristic x evaluation status, control x coverage assessment, maps directly to what an auditor reads. The agent doesn’t write a narrative and hope the auditor can derive the evidence. The structure is the evidence.
“Cannot assess” is a finding.
SOC2 CC6.3 not assessable on 778 users is the single most important sentence in the report. Hiding that fact would be the worst possible audit outcome. Surfacing it, with a remediation plan, priority, and named root cause, is what good looks like.
Per-user findings name accounts and actions.
Five accounts named. Six findings, each with an action verb. No “review further” placeholders. The auditor and the security team read the same document: the auditor for evidence, the team for the punch list.
Connector remediation is in scope.
The Coverage Gap Report names which connectors need fixing for the next quarter’s review to close CC6.3. The agent treats the platform as part of the review, not an externality.
Key queries
Q1Organization scope, count distinct users across IdPs (30d)SCOPE
Q4Per-user entitlement pull, Auth0 (6 users)ENTITLEMENT
Q8H3 / H4 prerequisite, pull group membershipsDATA GAP
Q12Test-account / external-domain scan in Auth0FINDING F1
query.e2e+stage-***@gmail.com. External domain in corporate IdP with null UID and test-account naming.Q15Intune device cross-reference for F4 mitigationMITIGATING
Showing 5 representative queries. Full audit trail across queries.md, entitlements.md, anomalies.md, coverage-gaps.md.
Sources queried · with status
| Source | Status | Notes |
|---|---|---|
| identity.auth0 (Staging) | HIT | 6 users with full entitlement detail |
| identity.entra (ATB) | OVERFLOW | 778 distinct users via SUMMARIZE; individual records overflow broad queries |
| identity.intune (ATB) | HIT | 6 devices; provided mitigating evidence for one dormancy flag |
| identity.jumpcloud (Events) | GAP | 0 user_inventory records |
| identity.jumpcloud (DI) | GAP | 0 authentication, 0 entity_management. Connector returns empty |
| identity.ct_mgmt_auth | GAP | 0 authentication records |
| entitlements (groups / roles) | GAP | No connector returns entity_management with roles. Blocks H3 + H4 |
Coverage gaps · with priority
- HIGH. Group / role data unavailable. Blocks Excessive Privilege + SoD heuristics. CC6.3 not assessable.
- HIGH. JumpCloud Directory Insights returns 0 events across user_inventory, authentication, entity_management. Either configuration issue or pipeline failure.
- MEDIUM. Last-login fields not populated on most connectors. Dormancy detection limited to inventory timestamps.
- MEDIUM. Domain mismatch between JumpCloud user inventory (
@query.ai) and auth data (@[tenant]). Cross-reference incomplete.
Run a quarterly access review on your stack.
Bring your IdPs.
