Aggregation from any source
Pull accounts, groups and attributes on a schedule from directories, HR systems, cloud accounts and applications.
Aggregate and correlate users, groups and attributes from every connected source into a single resolved identity.
Identity data arrives from HR systems, directories, cloud providers and the applications themselves, and each holds a partial and slightly different view. The directory aggregates those sources and correlates the accounts belonging to the same person or service into one record, so every other capability in the platform works from the same answer.
The mechanics behind the capability — what the platform does, and where it does it.
Pull accounts, groups and attributes on a schedule from directories, HR systems, cloud accounts and applications.
Match accounts scattered across systems to the identity that owns them, so a person is one record rather than seven fragments.
Normalise differing field names and formats into a consistent schema, so downstream policy can rely on the shape of the data.
Service accounts and machine identities are first-class records, which is what makes it possible to spot the dormant and unowned ones.
Who feels the difference once Identity Directory is in place, and how.
Identity teams
Reconciliation between tools stops being a standing project, because there is only one record to begin with.
Security
Accounts with no valid owner become visible as soon as sources are correlated, rather than at the next audit.
Governance
Certifying access is only meaningful when the underlying identity data is accurate and complete.
IT operations
Provisioning from a correlated record avoids creating yet another duplicate account for the same person.
It works because the other capabilities share the same identity fabric. The quickest way to judge that is to watch it run against your own use cases.