LogoLogo
SupportDeveloper Docs
  • Welcome
  • Getting Started
    • Introduction to BalkanID
      • BalkanID Onboarding
      • BalkanID Summary Dashboard
    • Setting Up BalkanID
      • User Role Management
      • Users Entitlements Discovery
      • Employee Data Extraction
      • Application Integration & Entitlement Data Extraction
      • Business Owners for Application Integrations
    • Entitlement Discovery
      • Entitlements Discovery
      • Applications Entitlements Discovery
      • Connection Entitlement Discovery
      • Resource Entitlement Discovery
      • Identities Entitlements Discovery
      • Working with Filters
      • Impact Analysis
    • Access Review Management
      • Access Review Campaigns
      • Performing Access Reviews
      • Campaign dashboard and management
      • Campaign Audit Reporting
      • Access Review Campaign Notifications and Reminders
      • Configuring Integration Specific Multi-Level Review Settings
      • Configuring Multi-Level Review Settings in Campaigns
      • Reviewer Insight Escalation for Campaigns
      • Recurring Campaigns
      • Campaign Escalation
      • Nominate Delegate In Account Preferences
      • Access Review Graphs
      • Access Review Recommendations
    • Access Request Management
      • Creating and Managing Access Requests
        • New User Access Request
        • New Service Account Access Request
        • New Identity Access Request
        • New Connection Access Request
        • New Resource Access Request
        • New SCIM Access Request
    • System Notifications & Automatic Ticket Creation
      • Notification Preferences
      • In-app Notifications
      • Supported Ticketing Systems
    • BalkanID CLI
      • BalkanID Extractor CLI
      • BalkanID API CLI
  • Configurations and Integrations
    • Integrations Overview
    • HRIS Integrations
      • Integrate via Merge
    • Direct Application Integrations
      • Asana Integration Setup
      • Atlassian Confluence Integration Setup
      • Atlassian Jira Application Integration Setup
      • AWS Application Integration Setup
      • AWS Identity Center Integration Setup
      • Bitbucket Integration Setup
      • Box Integration Setup
      • Code Climate Integration SetupPage
      • Datadog Integration Setup
      • Dropbox Integration Setup
      • GitHub Application Integration Setup
      • Gitlab Integration Setup
      • Google Cloud Platform Integration Setup
      • Google Drive Integration Setup Guide
      • Google Workspace Integration Setup
      • Jenkins Integration Setup
      • JumpCloud Integration Setup
      • MariaDB Integration Setup
      • Microsoft Azure and Active Directory (AD) Integration Setup
      • On-Prem Active Directory (AD) Integration Setup
      • Microsoft Office365 Integration Setup
      • MongoDB Integration Setup
      • MySQL Integration Setup
      • Netsuite Application Integration Setup
      • New Relic Integration Setup
      • Okta Application Integration Setup
      • Onelogin Integration Setup
      • OpenVPN Integration Setup
      • Pagerduty Integration Setup
      • Ping Identity Integration SetupPage
      • PostgreSQL Integration Setup
      • Ramp Integration Setup
      • Salesforce Application Integration Setup
      • SAP Integration Setup
      • Sendgrid Integration Setup
      • Sentry Integration Setup
      • Slack Application Integration Setup
      • Smartsheet Integration Setup
      • Snowflake Integration setup
      • Splunk Integration Setup
      • Sumologic Integration Setup
      • Twingate Integration Setup
      • Zoom Integration Setup
    • Manual Uploads
      • Application Entitlement Data
      • Employee Data
      • Mapping Identities to Employees
    • SSO Integrations
      • Ping Identity
      • Okta
      • OneLogin
      • Microsoft
    • Fulfillment Options
    • BalkanID API
  • Playbooks and Webhooks
    • Playbooks Overview
    • Configuring Global Playbooks
    • Configuring Integration Specifc Playbooks
    • Configuring Global Webhooks
    • Configuring Integration Specific Webhooks
    • Automated Employee Data Upload Playbook with AWS Lambda & S3
    • Automated Entitlement Data Upload Playbook with AWS Lambda & S3
  • IAM RISK ANALYZER
    • Findings
    • Current State RBAC
    • IAM Risk & RBAC Analysis Report
  • Insights and Rules
    • Entitlement Rules & Labels
      • Setup Rules and Labels
      • Terminated Employee Label
      • Privileged identity Label
      • Setup privileged identities
    • Entity Insights and Finding Rules
      • Creating entity filters
      • Setup insights using entity filters
      • Setup finding rules using entity filters
  • BalkanID Slackbot
    • Setting up BalkanID Slackbot
    • Access Requests and Access Review Notifications with BalkanID Slackbot
    • Findings (Daily Alert) with BalkanID Slackbot
  • JITPBAC
    • Overview of JITPBAC
    • Purposes
      • Create Purpose
      • Edit Purpose
      • Delete Purpose
      • Filtering Purposes
      • Create User-Purpose Access Request
        • Creating a Request Through the Web App
        • Creating a Request Through the Slackbot
      • Starting & Stopping Assigned Purposes
  • BalkanID Copilot
    • BalkanID Copilot
  • Updates
    • Release Notes
      • Introducing Findings: Prioritize, Act, and Automate Identity Risk Management
      • Action Center as a command hub for identity risk findings
      • Introducing Impact Analysis: Visualize, Understand, and Manage Access
      • In-app Notifications & Notification Preferences
      • Upgrades to RBAC Analyzer
      • Slackbot for Access Requests and Review Notifications
      • Playbooks and Webhooks for enhanced workflow automation
      • Introducing support assistant for BalkanID application for in-app support
      • Scheduling campaigns & multi-level approvals, nomination & delegation of reviews and graph views for
      • Campaign dashboard actions, access reviews by identity, enhanced access requests and entities connec
      • Access Provisioning & Deprovisioning, Email Notifications, Access Reviews & Campaigns Updates and Ne
      • Quickly find what you’re looking for with the new People, Applications, and Identities pages
      • Integrate your HRIS or Identity Provider without exposing sensitive personnel data or powerful admin
      • Quickly find unusual entitlements with Outliers (Early Access)
      • Announcing “Days Since Termination” filter
      • Announcing JumpCloud direct integration
      • Published Access Review Campaigns can now be deleted
      • Easily switch between tenants using the new tenant picker
      • Skip Access Review Campaigns by downloading a PDF report of your Entitlements
      • User account information now available on the Account page
      • Announcing Bulk API (Early Access)
      • Announcing HRIS integration capability with 23 new HRIS integrations
      • Privileged Identity insights help to quickly identify privileged identities
      • Terminated insights help to quickly identify and remediate entitlements held by terminated employees
      • Announcing Azure and Azure Active Directory direct integration
      • Access Review Campaign drafts can now be permanently deleted
  • Terms & Conditions
    • Privacy Policy
    • Terms of Service
    • AI Policy FAQ
    • Trust Center
Powered by GitBook

© 2025 · BalkanID, Inc. | Nothing on the BalkanID website, platform, or services, nor any portion thereof constitutes actual legal or regulatory advice, opinion, or recommendation by BalkanID, Inc.

On this page
  • What Are Insights?
  • Steps to Set Up Entity Filters and Create Insights
  • How Insights Add Value to Managing Entitlements

Was this helpful?

Export as PDF
  1. Insights and Rules
  2. Entity Insights and Finding Rules

Setup insights using entity filters

PreviousCreating entity filtersNextSetup finding rules using entity filters

Last updated 5 months ago

Was this helpful?

What Are Insights?

Insights provide valuable, actionable information about how users interact with resources and help identify potential security risks or misconfigurations in your identity and access management system. They are based on the data from entities like users, resources, and connections, and they provide valuable context for understanding access patterns and identifying potential security risks.

Examples of insights include:

  • MFA Missing: This insight identifies users who do not have Multi-Factor Authentication (MFA) enabled, indicating a security gap that needs to be addressed.

  • Over-entitled: This insight highlights users who have excessive access to resources beyond what is necessary for their role, posing a potential security risk.

  • SoD (Segregation of Duties): This insight flags potential conflicts of interest by identifying users who have access to multiple resources or actions that should be separated to prevent fraud or errors (e.g., a user who can both approve payments and manage accounts).

  • Unused Access: This insight detects access permissions that have not been used in a while, which could indicate unnecessary or outdated access rights that should be reviewed and potentially revoked.

By setting up entity filters and creating insights, you can track important security findings like MFA missing, over-entitled users, segregation of duties (SoD) violations, or unused access.

Steps to Set Up Entity Filters and Create Insights

  1. Navigate to the Insights Section

    • In the navigation sidebar, go to the Rules & Playbooks section and select the Insights tab.

  2. Create a New Insight

    • Click the Create Insight button located at the top left corner of the page. This will open a modal where you can configure your new insight.

  3. Select Entity Filters

    • In the modal, choose the entity filters you would like to apply to this insight. These filters will help you select specific data (such as users, resources, or connections) that you want to evaluate for potential issues.

  4. Enter Insight Details

    • Name: Give your insight a clear and descriptive name.

    • Description: Provide a brief explanation of what this insight will track and why it’s important.

    • Label Name: This field determines how the insight will appear on entity pages across the tenant. Choose a concise and meaningful label name, as it will be displayed alongside entities in your system.

  5. Save the Insight

    • After filling in the fields, click Save to create the insight.

  6. View the Insight

    • After saving, the new insight will appear in the Insights table within the Rules & Playbooks section. Within a short period of time (1-5 minutes), you will start seeing the label associated with the insight applied to relevant entity tables across your tenant.

How Insights Add Value to Managing Entitlements

Insights are a powerful tool for improving the visibility and security of your IAM system. They allow you to:

  1. Identify Security Gaps: Insights like MFA Missing help you spot areas where users may not be following best security practices. This allows you to take action to mitigate risks and ensure a stronger security posture.

  2. Monitor Excessive Access: Insights like over-entitled users can help you identify individuals who have been granted too many permissions. This is a key component of least privilege access management, helping you ensure users only have access to the resources they need.

  3. Ensure Compliance: Insights related to Segregation of Duties (SoD) help you maintain compliance with internal controls and regulatory requirements. They flag situations where access should be restricted to prevent conflicts of interest.

  4. Reduce Waste and Risk: Insights such as unused access highlight permissions that no longer serve a purpose, reducing the potential attack surface and simplifying your access control management.

Example Use Case

Let’s say you want to track over-entitled users (users with excessive access). You would:

  1. Set up filters to find users with access to resources beyond what’s required for their job.

  2. Create an insight with the name "Over-entitled Users" and a concise label name like "Excessive Access."

  3. Once the insight is created, it will automatically appear on relevant entity pages, and you’ll be able to identify and review over-entitled users quickly.