Multi-cloud honesty
Service coverage
Every individual service across Azure, AWS, GCP, Kubernetes, identity systems, and hybrid connectivity — with a fully / partially / planned / not-supported grade per capability. We do not pretend coverage we haven't built. See the guide.
- ○Microsoft Entra IDidentity.entra· identityPlannedSupported: observabilityDiscovery: MS Graph + ARM. Auth: OAuth client credentials + User-Assigned Managed Identity. Reads: Users, groups, app regs, service principals, role assignments, group memberships, sign-in logs.
- ○Microsoft Entra B2Cidentity.entra_b2c· identityPlannedSupported: observabilityDiscovery: Graph. Auth: OAuth. Reads: Custom policies, user flows, tenant config.
- ○Entra Domain Servicesidentity.entra_ds· identityPlannedSupported: observabilityDiscovery: ARM. Auth: OAuth (UAMI). Reads: Domain config, replication state.
- ○Oktaidentity.okta· identityPlannedSupported: observabilityDiscovery: Okta Management API. Auth: API token (read scopes: users:read, groups:read, apps:read, logs:read). Reads: Users, groups, apps, role assignments, MFA enrollments, system log, policies.
- ○Ping Identityidentity.ping· identityPlannedSupported: observabilityDiscovery: PingOne API. Auth: OAuth client credentials. Reads: Users, populations, applications, role assignments, MFA.
- ○OneLoginidentity.onelogin· identityPlannedSupported: observabilityDiscovery: OneLogin API. Auth: API credentials. Reads: Users, apps, roles, sign-in events.
- ○ForgeRock Identity Cloudidentity.forgerock· identityPlannedSupported: observabilityDiscovery: AM/IDM REST. Auth: Service account / OAuth client credentials. Reads: Users, identities, journeys, federation config.
- ○Auth0 (Okta)identity.auth0· identityPlannedSupported: observabilityDiscovery: Management API. Auth: M2M token (audience: management API). Reads: Users, applications, connections, rules/actions, logs.
- ○JumpCloudidentity.jumpcloud· identityPlannedSupported: observabilityDiscovery: JumpCloud API. Auth: API key (read scopes). Reads: Users, systems, system bindings, SSO apps, MFA enrollment.
- ○Google Cloud Identityidentity.gcp_identity· identityPlannedSupported: observabilityDiscovery: Google Admin SDK Directory API. Auth: OAuth (workforce identity federation preferred). Reads: Users, groups, OUs, role assignments, sign-in events.
- ○Amazon Cognitoidentity.cognito· identityPlannedSupported: observabilityDiscovery: AWS SDK (Cognito IDP). Auth: Cross-account IAM role (read-only). Reads: User pools, app clients, identity providers, federation config.
- ○SailPoint IdentityNowidentity.sailpoint· identityPlannedSupported: observabilityDiscovery: IdentityNow API. Auth: OAuth client credentials (read scopes). Reads: Identities, entitlements, access reviews, certifications, sources.
- ○Saviynt Identity Cloudidentity.saviynt· identityPlannedSupported: observabilityDiscovery: Saviynt REST. Auth: Service account. Reads: Users, accounts, entitlements, requests, certifications.
- ○CyberArkidentity.cyberark· identityPlannedSupported: observabilityDiscovery: Conjur API + EPM API + Privilege Cloud API. Auth: API authentication. Reads: Safes, accounts, applications, privileged session audit.
- ○Delinea (Thycotic + Centrify)identity.delinea· identityPlannedSupported: observabilityDiscovery: Secret Server REST + Privilege Manager API. Auth: API key + service account. Reads: Secret templates, folders, permissions, audit logs.
- ○Duo Security (Cisco)identity.duo· identityPlannedSupported: observabilityDiscovery: Duo Admin API. Auth: hostkey + skey + IKey (read). Reads: Users, integrations, authentication logs, enrollment status, policies.
- ○RSA SecurIDidentity.rsa_securid· identityPlannedSupported: observabilityDiscovery: SecurID Cloud Authentication API. Auth: service account. Reads: Users, tokens, authentication policies, sign-in events.
- ○Keycloakidentity.keycloak· identityPlannedSupported: observabilityDiscovery: Keycloak Admin REST API. Auth: OIDC client_credentials. Reads: Realms, users, groups, clients, role mappings, identity providers.
Read-only and advisory by design — we never modify cloud resources. The grades describe what we can observe, not what we can change.