Curated demo content by default.
The /demo route group is a public demonstration surface. Its stories, report packs, and portal views are intentionally curated unless a live tenant is explicitly selected.
Current route truth
Synthetic operations outputThe public route exists now and shows IAM reporting structure; the data and remediation framing are synthetic public demo content.
Strongest first view
Open TechnicalStart here when the room is technical and needs proof depth, attack-path substance, and remediation detail quickly.
This IAM operations report is a synthetic public demo surface. It shows representative operational framing and remediation planning, not a promise that every surfaced metric is already measured, verified, or available on every authenticated path.
Demo truth model
Persona switching, posture, blast radius, and remediation delta are anchored to real platform/runtime contracts.
Identity lifecycle, risk concentration, root-cause quantification, and targeted remediation for IAM teams.
Report credibility
Every field is shown explicitly. Items not yet provided are labelled (Roadmap, Unavailable, Not applicable, Missing) rather than hidden.
Demo seed — period derived from synthetic profile, not live tenant telemetry
Reference IF-IAM-RUN-MRI-
No prior version to diff — the public demo regenerates deterministically per request.
Named report owner is captured in webapp tenant scope settings — surfaced once a tenant is provisioned.
Approver sign-off block lands with the Audit / PBC workspace milestone.
Substantia signed-evidence chain is exercised in the authenticated webapp, not in the public demo route.
IAM risk is concentrated in lifecycle exceptions rather than a single broken workflow. 12% of the current operational drag is tied to leaver handling, which is why targeted deprovisioning changes will move risk faster than a broad policy rewrite alone.
114
Joiners
81
Movers
31
Leavers
23
Orphaned
Leaver and orphaned access debt
21%
The largest share of IAM risk sits in access that should already have been removed.
Provisioning quality variance
46%
Birthright and onboarding access still introduce avoidable downstream review noise.
Mover governance lag
33%
Role changes are not being reconciled quickly enough to keep privilege aligned with current job scope.
New users receive more access than needed
Accounts created without manager approval
Campaign Completion
High-Risk Entitlements Pending
19
Require immediate review
Automate joiner role assignment via HR integration
Owner: IAM
Enforce immediate deprovisioning workflows
Owner: IAM
Trigger alerts for orphaned accounts >7 days
Owner: Security
Cuts the highest-concentration IAM risk cluster first.
Reduces avoidable access review volume in the next campaign cycle.
Improves remediation routing and shortens time to closure.
IAM Operations Report · Prepared by IdentityFirst Ltd · Prepared for Acme Corp · Ref IF-IAM-RUN-MRI- · v1.0 · Confidential - Demonstration Use Only · SAMPLE - SYNTHETIC DATA - NOT FOR DISTRIBUTION