213 orphaned identities. Zero owners. One live scan.
A regulated financial services enterprise ran ORYN against its live identity stack and found that 9 out of every 10 identities in the environment had no assigned owner and no risk score — invisible to the compliance program that was supposed to be watching them.
The client's compliance program looked healthy on paper. ISO 27001 and SOC 2 evidence was current, audits had passed, and the GRC function reported green status to the board every quarter. The identity layer told a different story. When ORYN was pointed at the live environment, it surfaced 238 distinct identities — human and non-human — across the client's access stack. 213 of them were orphaned: no assigned owner, no risk score, no active review cycle. They weren't malicious, and they weren't the result of negligence. They were the predictable output of a compliance model built to answer "does this have access" once a year, not "do we still know what this is" every day. This is the structural problem with point-in-time compliance: the audit passes because the audit only ever looks at the moment it's run. Everything that drifts in the eleven months between audits — including new service accounts, contractor access left active past offboarding, and increasingly, AI agents that don't fit cleanly into a human/machine binary — goes unscored and unowned until the next cycle catches it, or doesn't.
ORYN was deployed as a continuous compliance loop against the client's identity stack and control environment, rather than as a point-in-time scanning tool. Full identity discovery across human, service, and non-human accounts established a live baseline instead of a sampled one. Automatic ownership and risk scoring was applied to every identity found, closing the gap between "has access" and "someone is accountable for that access." Blast-radius and segregation-of-duties analysis ran against the discovered identity graph, not a static spreadsheet. Control-mapped evidence capture sealed findings against ISO 27001, SOC 2, and the client's applicable regulatory frameworks as they were generated — not reconstructed after the fact. A continuous scan cadence replaced the annual snapshot with an ongoing loop the compliance team could check any day of the year, not just the week before an audit.
Explore ORYN →What changed.
Have a similar problem?
Bring us the constraint. We'll scope the shortest path to a working system.