Use case · Identity Governance

Identity governance built on observed behavior, not on what the directory says.

Most governance programs start from a list of entitlements and try to reason backward to what people do. CINQUE starts from what identities actually do and builds the persona and role catalog from there.

Human, non-human, and AI-tool identitiesPre-IGA sequencing
Book a Discovery WorkshopGet a demo
The problem

Roles describe permission. They do not describe reach.

An entitlement tells you what an identity is allowed to do. It tells you nothing about what it has done, which systems it has actually touched, or how far one compromised credential would carry across your environment. That gap is why access reviews get certified and nothing changes.

Entitlements without evidence

Every review certifies what an account is permitted to do and never asks whether it uses it.

Roles built in a workshop

Role catalogs assembled from job titles and org charts describe the company you drew, not the one that runs.

Non-human identities with no owner

Service accounts, tokens, keys, and integrations outnumber people and rarely have anyone who can say what normal looks like.

An IGA tool bought too early

Automating a role model nobody trusts makes the wrong answer arrive faster.

What CINQUE does

What CINQUE contributes to the program.

Persona and protect-surface mapping
CINQUE clusters your population into business personas from observed activity, then maps each persona against the surfaces it reaches. Nobody draws a group and assigns people to it.
Behavioral baselines and drift detection
Each persona gets a documented normal across all five control points. When an identity's journey moves away from that normal, the change is visible as a change, not as a policy violation.
Persona membership, with the person attached
Every identity in a persona carries its job title and department, so the persona is legible to the people who have to sign off on it.
The activity map
One timeline per identity: authentication, device, network path, applications, and data touched. This is what gives your access-review team the observed membership and journey for each persona.
Prioritized recommendations
Each correlated finding carries a written recommendation and the evidence behind it, ranked by what it would actually change.
What the program walks away with

Four artifacts you own, whatever you decide about tooling.

The artifact
Who uses it
What it contains
A persona-based role framework
Identity program owner
A role model derived from observed behavior, with membership, journeys, and the surfaces each persona reaches.
A technology rationalization map
Security architecture
Which of your existing tools already answer which questions, and where the same answer is being paid for twice.
A documented ROI and budget case
CISO and finance
The evidence base for the next funding conversation, built from your own environment rather than from a vendor model.
CINQUE as the correlation platform
Security operations
The persona and baseline layer stays in place after the program work is done, so the model does not go stale the week it is signed off.
Scope

What CINQUE does not do.

Stated plainly, so nobody is surprised in month two.

  • CINQUE does not provision, deprovision, or certify access. It is the evidence layer your governance tooling and your reviewers work from.
  • CINQUE replaces no tool in your stack, including your IGA platform. It is the correlation layer above it.
The CINQUE Discovery Workshop · complimentary

Bring your identity export.
Leave with your own persona and role catalog.