Identity

Identity and access hygiene: the environment that decides most of the Security Score

Permissions and entitlements are usually where the largest gap between a third party's stated posture and its real posture lives — and it is only visible once an account is actually connected.

Blog

August 8, 2026 · 9 min read

01

Why identity is its own environment in the score

Identity findings — stale privileged access, weak authentication settings, over-broad service permissions — carry real weight in the overall Security Score precisely because they are evaluated with the same evidence standard as cloud and SaaS findings: read directly from the connected account.

Identity & Access: access and entitlement hygiene findings across the third party's connected accounts.
Identity & Access: access and entitlement hygiene findings across the third party's connected accounts.
02

What gets evaluated

Access reviews focus on the entitlement hygiene that most commonly leads to compromise: standing privileged access, authentication configuration and account lifecycle controls, evaluated the same way for every connected provider.

  • Privileged and standing access across connected accounts
  • Authentication configuration hygiene
  • Account lifecycle and dormant-access findings
1stone Research

Talk to the team about a third-party program

A working session against your actual third-party portfolio: how workspaces are created, which accounts get connected first, and what the Security Score looks like in week one.

Request a walkthrough