Skip to main content
The Access Graph is a visual map of how accounts connect to applications, groups, roles, and resource instances. This page explains how to read what’s on screen - nodes, edges, node details, the activity overlay, and the Entitlement Graph - so you can navigate access relationships with confidence.

Nodes and edges

Each data entity in the graph is a node. Nodes are styled by entity type to make them visually distinct. Connections between nodes are edges that represent how access flows from one entity to another.

Nodes

Edges

Edges represent the access relationships between nodes. The direction of an edge shows how access is granted - for example, an edge from a role node to a resource instance node means that role grants access to that resource instance. Edge thickness reflects access frequency when the activity overlay is enabled: thick edges indicate high usage, thin edges indicate low usage, and dotted edges indicate zero usage.

Node details

Selecting a node opens a side panel with details about that entity - its context, permissions, and connections. Example: Select the node for Anthony Lee to open a side panel showing his email, user ID, role, user groups, and permissions. In this example, Anthony has a seed admin role, belongs to the engineering, board, sales, HR, and IT support groups, and has permission to access eight resource instances. Access Graph user details panel for Anthony Lee

Activity overlay

The activity overlay shows how frequently each account uses the access it has, rendered directly on the graph as edge thickness. This lets you immediately identify unused access and decide what to revoke. Example: Anthony Lee, Mary Johnson, and Oleria Connector all have access to the Comic Movies file. Anthony accesses it frequently (thick line), Mary accesses it occasionally (thin line), and Oleria Connector has never accessed it (dotted line). Because the Oleria Connector has zero activity, the admin can remove that access. Activity overlay showing thick, thin, and dotted access paths for three accounts on the Comic Movies file

Entitlement Graph

The Access Graph maps access from application accounts to resource instances, but it doesn’t show the identity-to-application layer on its own - which applications an identity can reach, how they got that access, and how often they use it. The Entitlement Graph fills that gap. The Entitlement Graph answers three questions:
  • Which applications does a user identity have access to?
  • How did they get that application access - directly, through a group, or through an IdP?
  • How frequently do they access each application?
1

Search for an identity

Search for an identity account. The graph displays the identity nodes in the Access Graph framework.
2

Select an identity node

Select an identity node to open its side panel.
3

Open the Entitlement Graph

In the side panel, select an application account to load the Entitlement Graph for that identity. The graph shows all applications the identity has access to, with edges representing how that access was granted.Entitlement Graph showing identity-to-application access relationships with access frequency indicators
By default, both Access and Entitlement Graphs are enabled and displayed together. To focus on one graph type at a time, use the Graph Types panel: select Entitlement to show only the identity-to-application layer, or select Access to show only the application account-to-resource layer. Access Graph displayed in isolation after selecting Access from Graph Types

Contact us

For questions, contact us at support@oleria.com.