LogoLogo
SupportDeveloper Docs
  • Welcome
  • Getting Started
    • Introduction to BalkanID
      • BalkanID Onboarding
      • BalkanID Summary Dashboard
    • Setting Up BalkanID
      • User Role Management
      • Users Entitlements Discovery
      • Employee Data Extraction
      • Application Integration & Entitlement Data Extraction
      • Business Owners for Application Integrations
    • Entitlement Discovery
      • Entitlements Discovery
      • Applications Entitlements Discovery
      • Connection Entitlement Discovery
      • Resource Entitlement Discovery
      • Identities Entitlements Discovery
      • Working with Filters
      • Impact Analysis
    • Access Review Management
      • Access Review Campaigns
      • Performing Access Reviews
      • Campaign dashboard and management
      • Campaign Audit Reporting
      • Access Review Campaign Notifications and Reminders
      • Configuring Integration Specific Multi-Level Review Settings
      • Configuring Multi-Level Review Settings in Campaigns
      • Reviewer Insight Escalation for Campaigns
      • Recurring Campaigns
      • Campaign Escalation
      • Nominate Delegate In Account Preferences
      • Access Review Graphs
      • Access Review Recommendations
    • Access Request Management
      • Creating and Managing Access Requests
        • New User Access Request
        • New Service Account Access Request
        • New Identity Access Request
        • New Connection Access Request
        • New Resource Access Request
        • New SCIM Access Request
    • System Notifications & Automatic Ticket Creation
      • Notification Preferences
      • In-app Notifications
      • Supported Ticketing Systems
    • BalkanID CLI
      • BalkanID Extractor CLI
      • BalkanID API CLI
  • Configurations and Integrations
    • Integrations Overview
    • HRIS Integrations
      • Integrate via Merge
    • Direct Application Integrations
      • Asana Integration Setup
      • Atlassian Confluence Integration Setup
      • Atlassian Jira Application Integration Setup
      • AWS Application Integration Setup
      • AWS Identity Center Integration Setup
      • Bitbucket Integration Setup
      • Box Integration Setup
      • Code Climate Integration SetupPage
      • Datadog Integration Setup
      • Dropbox Integration Setup
      • GitHub Application Integration Setup
      • Gitlab Integration Setup
      • Google Cloud Platform Integration Setup
      • Google Drive Integration Setup Guide
      • Google Workspace Integration Setup
      • Jenkins Integration Setup
      • JumpCloud Integration Setup
      • MariaDB Integration Setup
      • Microsoft Azure and Active Directory (AD) Integration Setup
      • On-Prem Active Directory (AD) Integration Setup
      • Microsoft Office365 Integration Setup
      • MongoDB Integration Setup
      • MySQL Integration Setup
      • Netsuite Application Integration Setup
      • New Relic Integration Setup
      • Okta Application Integration Setup
      • Onelogin Integration Setup
      • OpenVPN Integration Setup
      • Pagerduty Integration Setup
      • Ping Identity Integration SetupPage
      • PostgreSQL Integration Setup
      • Ramp Integration Setup
      • Salesforce Application Integration Setup
      • SAP Integration Setup
      • Sendgrid Integration Setup
      • Sentry Integration Setup
      • Slack Application Integration Setup
      • Smartsheet Integration Setup
      • Snowflake Integration setup
      • Splunk Integration Setup
      • Sumologic Integration Setup
      • Twingate Integration Setup
      • Zoom Integration Setup
    • Manual Uploads
      • Application Entitlement Data
      • Employee Data
      • Mapping Identities to Employees
    • SSO Integrations
      • Ping Identity
      • Okta
      • OneLogin
      • Microsoft
    • Fulfillment Options
    • BalkanID API
  • Playbooks and Webhooks
    • Playbooks Overview
    • Configuring Global Playbooks
    • Configuring Integration Specifc Playbooks
    • Configuring Global Webhooks
    • Configuring Integration Specific Webhooks
    • Automated Employee Data Upload Playbook with AWS Lambda & S3
    • Automated Entitlement Data Upload Playbook with AWS Lambda & S3
  • IAM RISK ANALYZER
    • Findings
    • Current State RBAC
    • IAM Risk & RBAC Analysis Report
  • Insights and Rules
    • Entitlement Rules & Labels
      • Setup Rules and Labels
      • Terminated Employee Label
      • Privileged identity Label
      • Setup privileged identities
    • Entity Insights and Finding Rules
      • Creating entity filters
      • Setup insights using entity filters
      • Setup finding rules using entity filters
  • BalkanID Slackbot
    • Setting up BalkanID Slackbot
    • Access Requests and Access Review Notifications with BalkanID Slackbot
    • Findings (Daily Alert) with BalkanID Slackbot
  • JITPBAC
    • Overview of JITPBAC
    • Purposes
      • Create Purpose
      • Edit Purpose
      • Delete Purpose
      • Filtering Purposes
      • Create User-Purpose Access Request
        • Creating a Request Through the Web App
        • Creating a Request Through the Slackbot
      • Starting & Stopping Assigned Purposes
  • BalkanID Copilot
    • BalkanID Copilot
  • Updates
    • Release Notes
      • Introducing Findings: Prioritize, Act, and Automate Identity Risk Management
      • Action Center as a command hub for identity risk findings
      • Introducing Impact Analysis: Visualize, Understand, and Manage Access
      • In-app Notifications & Notification Preferences
      • Upgrades to RBAC Analyzer
      • Slackbot for Access Requests and Review Notifications
      • Playbooks and Webhooks for enhanced workflow automation
      • Introducing support assistant for BalkanID application for in-app support
      • Scheduling campaigns & multi-level approvals, nomination & delegation of reviews and graph views for
      • Campaign dashboard actions, access reviews by identity, enhanced access requests and entities connec
      • Access Provisioning & Deprovisioning, Email Notifications, Access Reviews & Campaigns Updates and Ne
      • Quickly find what you’re looking for with the new People, Applications, and Identities pages
      • Integrate your HRIS or Identity Provider without exposing sensitive personnel data or powerful admin
      • Quickly find unusual entitlements with Outliers (Early Access)
      • Announcing “Days Since Termination” filter
      • Announcing JumpCloud direct integration
      • Published Access Review Campaigns can now be deleted
      • Easily switch between tenants using the new tenant picker
      • Skip Access Review Campaigns by downloading a PDF report of your Entitlements
      • User account information now available on the Account page
      • Announcing Bulk API (Early Access)
      • Announcing HRIS integration capability with 23 new HRIS integrations
      • Privileged Identity insights help to quickly identify privileged identities
      • Terminated insights help to quickly identify and remediate entitlements held by terminated employees
      • Announcing Azure and Azure Active Directory direct integration
      • Access Review Campaign drafts can now be permanently deleted
  • Terms & Conditions
    • Privacy Policy
    • Terms of Service
    • AI Policy FAQ
    • Trust Center
Powered by GitBook

© 2025 · BalkanID, Inc. | Nothing on the BalkanID website, platform, or services, nor any portion thereof constitutes actual legal or regulatory advice, opinion, or recommendation by BalkanID, Inc.

On this page
  • Query identity data using natural language
  • Generate playbooks and build automation into your workflows
  • Create custom reports using natural language prompts
  • What are the typical questions that one can ask?
  • Who can view my interactions with BalkanID Copilot?
  • Does BalkanID Copilot share any information with OpenAI or other LLMs?
  • What is BalkanID's AI policy in general?
  • Can BalkanID Copilot run alongside my existing IGA tools such as Sailpoint or IAM tools like Okta or Azure AD?
  • What use cases does BalkanID Copilot support with existing tools?

Was this helpful?

Export as PDF
  1. BalkanID Copilot

BalkanID Copilot

This document provides answers to common questions regarding the BalkanID Copilot, including common use-cases.

PreviousStarting & Stopping Assigned PurposesNextRelease Notes

Last updated 4 months ago

Was this helpful?

BalkanID Copilot enhances the user experience of BalkanID identity security and governance, allowing users to obtain answers by typing their questions in natural language. The technology behind BalkanID Copilot features a sophisticated data linkage system that facilitates fast querying and deep analytical capabilities. It also utilizes large language models (Currently, GPT4-o) to interact with the user. All our data is sourced from the BalkanID App.

Query identity data using natural language

Gain insights from your enterprise identity data quickly by asking questions in simple, non-technical language. Let BalkanID Copilot build your query from the questions you ask, or take advantage of common pre-built questions.

Generate playbooks and build automation into your workflows

Insights are useful, but the true advantage of BalkanID Copilot lies in its automation. By generating playbooks, you can automate complex identity management tasks through Python code or text and visual query flowcharts.

Create custom reports using natural language prompts

Create custom reports by just asking questions in simple, non-technical language or choose from a set of pre-defined report templates. Let BalkanID Copilot stitch a report to your needs without complex reporting user interface, filters and no code.

What are the typical questions that one can ask?

The BalkanID Copilot is a discovery tool that can answer questions regarding a company’s employees, their identities, connections, resources, permissions and the integrated applications. It can also answer questions regarding access reviews, requests and campaigns, IAM risks and findings, BalkanID generated Roles and BalkanID Just-In-Time Purpose-Based Access Control (JITPBAC). While answering these questions, we also flag useful insights like SoD violations, privileged entities and terminated employees. This data is sourced from the entitlements and reviews data on the BalkanID app.

Here are some questions that you could try on the BalkanID App:

Questions around Discovery

  • What identities are members of privileged groups in AWS?

  • Show me all employees, their departments, and job titles.

  • What applications have been integrated?

  • List all applications and the number of unmapped identities they contain.

  • Which user has the highest number of connections?

  • How many resources does each application contain?

  • List all terminated employees and their connections.

  • Show me terminated employees who have access to resources in various applications.

  • List all the campaigns and their progress.

  • What are the campaigns that target terminated employees?

  • Show me all the privileged permissions

  • List all identities that were reviewed, along with the campaign name and application details

  • List identities that have been reviewed in the last 90 days, along with the application and review details

  • List connections that have been reviewed in the last 90 days, along with the application and review details

  • List resources that have been reviewed in the last 90 days, along with the application and review details

  • List identities that have not been reviewed in the last 90 days, along with the application and review details

  • List connections that have not been reviewed in the last 90 days, along with the application and review details

  • List resources that have not been reviewed in the last 90 days, along with the application and review details

  • What campaigns are overdue?

  • Who has created the most number of requests?

  • List all grant requests over the past 3 months that were approved. Who are the reviewers?

  • What purposes are defined and who is eligible for them?

  • Who gained access via Purposes this week?

  • What purposes are set to expire before the end of the month?

  • List the accesses via purposes that are not least privileged. Also list the applications, and identities who have the accesses.

Questions around Playbooks

  • Create a joiner playbook for new employees

  • Create a playbook to revoke access for terminated employees who have active identities in AWS

Note:

  • Questions about connections, resources, and permissions should be enclosed in double quotes. e.g. Who all have access to “aws-prod-admin” connection?

Who can view my interactions with BalkanID Copilot?

Your interactions with BalkanID Copilot are private and secure. Only authorized personnel within BalkanID may access this information to ensure correctness and better user experience.

Does BalkanID Copilot share any information with OpenAI or other LLMs?

The BalkanID Copilot does not send PII to OpenAI or any other LLMs for its primary functionality. However, aggregated statistical data from query results is sent to OpenAI or other LLMs to generate summaries that make it easy for the user to interpret the result. This is not the case when the BalkanID Copilot is self-hosted (or hosted in a contained environment dedicated to the customer), which is an option provided to run BalkanID Copilot.

What is BalkanID's AI policy in general?

Can BalkanID Copilot run alongside my existing IGA tools such as Sailpoint or IAM tools like Okta or Azure AD?

BalkanID Copilot can be deployed on top of existing existing Identity Security, IGA, PAM, IAM, Service Desk type tools like Okta, Microsoft Entra, Jira, SailPoint, etc.

What use cases does BalkanID Copilot support with existing tools?

Copilot enhances and complements your current IGA and IAM solutions in several ways, including:

  • Serving as an analytics and custom reporting tool

  • Feeding intelligence into IGA and IDP systems to boost workflows, such as:

    • Generating and feeding RBAC roles, policies, and recommendations during access request lifecycle and access review certification

    • Providing actionable insights and playbooks

Here you can find our overall .

To enable BalkanID Copilot on your tenant, contact your customer success representative or email at any time to discuss options.

AI Policy FAQ
support@balkan.id