# Unify the identity sprawl

One person is rarely one account. They're an HR record, a directory user, a
handful of application logins, a VPN certificate, maybe a privileged account they
forgot about. Multiply that across your workforce, your contractors, and the
machine identities that outnumber them, and you have **identity sprawl** — access
scattered across systems that no single tool sees whole. You can't secure what
you can't see as one thing.

## Correlate accounts back to one identity

Axiad Mesh connects to your identity providers, HR systems, cloud platforms, and
infrastructure and correlates every account into a single
[identity](../concepts/identities.md). A person or a service spread across half a
dozen systems shows up as **one** entity, with all its accounts, credentials, and
access levels in view — including the sprawl you didn't know you had, surfaced by
pointing out gaps and matches in your data.

Identities then group into [entities](../concepts/entities.md) — teams,
departments, functions — so you can see risk by part of the organization, not
just per account.

## See the relationships that create risk

Sprawl matters because weakness in one place undermines strength in another. Mesh
doesn't score a single account on a single application in isolation — it looks at
one identity across many applications, and many identities across many
applications with different credential types, to see how a compromise in any one
place could cascade.

If a user is protected by a FIDO2 authenticator in one system but signs in to
another with only a password, how secure is the first system once an attacker has
that password? Mesh surfaces exactly these relationships. The
[identity graph](../concepts/investigations.md#the-identity-graph) draws the
neighborhood around any identity — the accounts correlated to it and the access
that chains through it — and highlights the paths that carry the most risk.

![The identity blast-radius graph in Axiad Mesh Generative UI, centered on an agentic identity whose offboarded human owner still chains through a group and resources to a production data store, with the critical path and ownership edge highlighted and a risk-layer score breakdown below](/img/generative-ui/identity-graph.png)

## You stay in control of correlation

Correlation is a judgment, and Mesh keeps it transparent. Strong matches are
grouped automatically; weaker ones are flagged for review rather than assumed.
When Mesh isn't sure, it shows you the two accounts **side by side** with the
details behind the match, so you can decide whether they're really the same
identity — and **confirm** or **reject** the correlation yourself. If a call
needs someone with more context, you can [delegate](../concepts/delegation.md)
it. The unified view of an identity stays accurate because the uncertain calls
are made by a person, not assumed by the system.

## Related

- [Identities](../concepts/identities.md) — how correlation works and how to
  review it.
- [Entities](../concepts/entities.md) — grouping identities to see organizational
  risk.
- [Investigations](../concepts/investigations.md) — the identity graph and
  drilling into relationships.
