Identity governance built on observed behavior, not on what the directory says.
Most governance programs start from a list of entitlements and try to reason backward to what people do. CINQUE starts from what identities actually do and builds the persona and role catalog from there.
Roles describe permission. They do not describe reach.
An entitlement tells you what an identity is allowed to do. It tells you nothing about what it has done, which systems it has actually touched, or how far one compromised credential would carry across your environment. That gap is why access reviews get certified and nothing changes.
Entitlements without evidence
Every review certifies what an account is permitted to do and never asks whether it uses it.
Roles built in a workshop
Role catalogs assembled from job titles and org charts describe the company you drew, not the one that runs.
Non-human identities with no owner
Service accounts, tokens, keys, and integrations outnumber people and rarely have anyone who can say what normal looks like.
An IGA tool bought too early
Automating a role model nobody trusts makes the wrong answer arrive faster.
What CINQUE contributes to the program.
Four artifacts you own, whatever you decide about tooling.
What CINQUE does not do.
Stated plainly, so nobody is surprised in month two.
- CINQUE does not provision, deprovision, or certify access. It is the evidence layer your governance tooling and your reviewers work from.
- CINQUE replaces no tool in your stack, including your IGA platform. It is the correlation layer above it.
Same platform, different question.
All use cases · What is Unified Security Posture Observability?