Skip to main content
The Access Graph lets you trace access relationships dynamically - from an account to the resource instances it can reach, or from a resource instance back to every account, role, and group that has access to it. The graph updates in real time as you interact, making it practical for investigating intricate access paths and detecting unexpected connections.

Search the graph

Search lets you find identities, application accounts, or resource instances by account email or resource instance name, then build a graph from the results.
Access Graph shows the top 5 search results. To see all results, select View all results to open the Access Inventory page.

Search by accounts

1

Select the Accounts search type

In the search bar, select Accounts from the dropdown menu.
2

Enter the account email

Type the account email address. A list of matching application account nodes displays.
If the email address contains reserved characters, wrap it in double quotes. Example: "demo-salesforce-group+anthonylee@oleria.com"
Access Graph search showing account results across multiple applications
3

Select an account node

Select an account from the results to build the graph. If the account exists in multiple application instances (for example, Salesforce Production and Salesforce Dev), the graph shows a separate node for each.

Search by resource instances

1

Select the Resource Instances search type

In the search bar, select Resource Instances from the dropdown menu.
2

Enter the resource instance name

Type the resource instance name. A list of matching resource instance nodes displays.Access Graph search showing resource instance results across multiple applications and environments
3

Select a resource instance node

Select a resource instance from the results to build the graph. If the instance exists in multiple applications or environments, the graph shows a separate node for each.
Use this path when you want to understand what a specific user or machine account can access.
1

Search for the account

Select Account from the search dropdown and enter the account email. The graph displays all applications the account has access to.
2

Select the application account node

Select an application account node to open its side panel. The panel shows details including email, user ID, assigned roles, group memberships, and resource access.
3

Add a resource to the graph

Select any resource from the side panel. The graph builds out to show that resource node.
4

Select the resource node

Select the resource node to open a side panel listing the resource instances the account can access.
5

Add resource instances to the graph

Select one or more resource instances to complete the graph. You now see the full access path from the account to its resource instances.Access Graph showing account Anthony Lee with Salesforce access, System Administrator role, group memberships, and resource instance access
Use this path during an incident investigation when you need to know every identity that can reach a specific resource.
1

Search for the resource instance

Select Resource instance from the search dropdown and enter the resource name. The graph displays the resource instance node.
2

Select the resource instance node

Select the resource instance node to open its side panel. The panel lists all accounts that have access to it.
3

Add accounts to the graph

Select one or more accounts from the side panel to expand the graph. Each selected account appears as a node connected to the resource instance.
4

Explore the access path

Select any account node to open its side panel and trace how it obtained access - through a direct role assignment, group membership, or inherited permission.

Contact us

For questions, contact us at support@oleria.com.