TerraVault Insurance Group • Real-time identity risk operationalization connecting auth anomalies, privilege sprawl, and access certification gaps
Privileged account distribution across Tier-1 systems • Size = account count • Color intensity = avg access age
Waterfall showing contribution of each risk factor to total index
Daily rate • Day 11 spike: credential stuffing attack on contractors
Contractors lag at 87.6% enrolled
Leaver process gap creates orphaned accounts
Days overdue by system tier
Top 12 identity risks requiring immediate action • Sorted by composite risk score
| User / Account | Type | Risk Issue | System | Days Open | Risk Score | Status |
|---|---|---|---|---|---|---|
| svc_payroll_batch | Service Acct | Credential age 847d, no rotation policy | SAP Financials | 847 | 94 | Critical |
| james.morrison@ext | Contractor | Terminated 34d ago, 3 systems still active | Okta, Salesforce, Jira | 34 | 91 | Critical |
| admin_db_legacy | Admin | Dormant 127d, Domain Admin privileges | Active Directory | 127 | 89 | Critical |
| maria.santos@ext | Contractor | No MFA, 14 failed auth attempts day 11 | Okta | 79 | 87 | High |
| svc_bi_extract | Service Acct | Access cert overdue 67d, READ on PII tables | Snowflake DWH | 67 | 84 | High |
| raj.patel | Employee | Privileged access, MFA bypass 8x last 30d | CyberArk PAM | 30 | 82 | High |
| temp_dataload_03 | Temp Admin | Created for migration, project ended 45d ago | Oracle ERP | 45 | 78 | Medium |
| linda.chen | Employee | Role change 21d ago, old Finance access retained | Workday, NetSuite | 21 | 76 | Medium |
| svc_claims_api | Service Acct | Password stored in GitLab repo, detected day 6 | Claims Platform API | 84 | 74 | Medium |
| alex.kim@ext | Contractor | AWS Console access, no MFA, 2 regions | AWS IAM | 56 | 72 | Medium |
| backup_admin_02 | Admin | Shared credential, last rotation 312d ago | Veeam Backup | 312 | 69 | Medium |
| emily.rodriguez | Employee | 14 privilege escalations last quarter (helpdesk) | ServiceNow, AD | 90 | 64 | Low |
Distribution across 218 service accounts • Target: <180d rotation
% of identities under continuous verification policy
30-day daily tracking • Bypass events vs. total authentications • SMS fallback highlighted
Accounts belonging to terminated users still active • Tier-1 systems flagged