Get
Returns a non-human identity by its global id. Requires the https://devx.{environment}.oleria.io/read scope.
Authorizations
OAuth 2.0 client-credentials flow. Request an access token from the token endpoint and send it as Authorization: Bearer <token>.
Path Parameters
Global id of the non-human identity.
Response
The non-human identity.
An Oleria Account object represents a user, machine, or token account in an enterprise SaaS application, identity provider, MFA provider, or directory service e.g. Okta, PingOne, ActiveDirectory, GitHub, Salesforce, or ServiceNow
The source application-specific role associated with the account e.g. member, admin, etc. This preserves the underlying information used to determine type and userType of the account, and is referenced when doing identity provider assignment
"MEMBER"
The username associated with the account in the application instance
1"kirtd-oleria"
Authentication functions associated with this account (see AccountAuthenticationFunction)
The primary email address of the Account
"kirt@oleria.com"
Is the Account enabled?
true
Is the Account authorized to access the application's API endpoints?
false
An identifier (unique to integrated application) for an Account object represented in the Oleria system. Oleria converts these identifiers to global ids so they can be unique in the context of the global system graph. It is important for this identifier to be based on an underlying persistent and reusable application or identity provider id so connections to the object are robust to metadata changes and other relevant operations
"user:U_kgDOB7P6Rg (GitHub based on node identifier), 838439349399 (Google Workspace based on user id), user:wiz-inc-4db1c46901 (GitHub based on app slug)"
Is the Account an administrator?
true
The ObjectMetadata structure defines metadata that applies to every object and relationship, and is usually managed by the system that receives the data
The following sub-types of account are supported:
- Application is used to represent accounts used to represent an "installed" application or custom created service principal for application or federated use. When the sub-type is Application, the source application should also emit ApprovedApplicationUsage for the account
- AnonymousUser is used to represent anonymous accounts typically in the context of sharing resources
- ExternalUser is used to represent accounts that are outside of the application-defined customer organizational unit, and is typically used in the context of sharing resources]
- StandardUser accounts are any user accounts not classified as AnonymousUser or ExternalUser and is typically the majority of accounts managed by an enterprise application
- System is used to represent system bots and pre-defined or configurable system service principals e.g. the merge queue bot in GitHub
- Unavailable should be indicated when the sub-type of the account cannot be definitively determined as AnonymousUser, ExternalUser, StandardUser, Application, or System based on the absence of endpoint functionality or lack of access
Application, AnonymousUser, ExternalUser, StandardUser, System, Unavailable "Standard"
- Machine accounts are used to represent system-defined accounts and service principals registered with the enterprise application that can take some sort of audited action
- Token accounts are used to represent tokens used to impersonate accounts with some restricted scope e.g. personal access tokens
- User accounts are used to represent human users of the application
Machine, Token, User "User"
Normalized version of the email found in Account.Email
Categories of risk implied by sharing to an entity (account) evaluated as having the given risk category
AnonymousEndpoint, RegisteredEnterpriseEndpoint, RegisteredInternetEndpoint, TrustedApplicationEndpoint, Unavailable MFAStatus describes the MFA usage currently being enforced for an account including those derived from authentication policy, adaptive security requirements, authorized location constraints, and more. It also includes information about how MFA authentication is operationalized for the account via a list of participating entities such that a graph topology can be built to represent the source of the MFA policies being enforced
object metadata supersets object metadata with platform enrichment provenance — the enrichment version and the time the record was generated
"Org Members"
Alternate email aliases for the account's primary email
Approved application usages associated with this account (see ApprovedApplicationUsage)
These are the locations assigned as delivery points for this Account. It is typically populated by identity providers in lieu of the definitive data coming from HRIS integrations
This policy expresses the selection criteria used by an IDP or MFA provider to select authentication methods for use at authentication time (usually as a subset of the enforced authentication methods)
AuthorizedLocationPolicy is used to specify locations authorized for use by accounts, groups, roles, employees, departments, etc.
The name of the company or enterprise associated with the Account
"Oleria Corporation"
The cost center associated with the owner of the Account
"232345"
ISO-3166-1 A-2 country code assigned to the account
"US"
An identifier (unique to integrated application) for an Account object represented in the Oleria system. Oleria converts these identifiers to global ids so they can be unique in the context of the global system graph. It is important for this identifier to be based on an underlying persistent and reusable application or identity provider id so connections to the object are robust to metadata changes and other relevant operations
"user:U_kgDOB7P6Rg (GitHub based on node identifier), 838439349399 (Google Workspace based on user id), user:wiz-inc-4db1c46901 (GitHub based on app slug)"
Federation information used when specifying an EntityIdentifier
The date the Account was created
"2024-05-02T03:17:34.948Z"
The name of the company or enterprise department associated with the Account
"Platform Engineering"
Federation information used when specifying an EntityIdentifier
The directoryEntryId is emitted when this Account object is synced with an Account emitted by a directory. The id here should match the synced Account.id
Federation information used when specifying an EntityIdentifier
The directoryProviderId indicates the DirectoryProvider defining the sync relationship for this account
The user experience displayable name of the Account holder e.g. a nickname. If this field is not set, then Oleria will set its value to name during processing
"Kirtliness"
The employee number associated with the Account holder
"29375"
The date the Account expires if applicable
"2024-05-02T03:17:34.948Z"
A FederationId is an account username override used in the context of an authenticated session or in some contexts an Oleria LocallyUniqueAccountId
"kirt@oleria.dev"
The hash identifiers are typically emitted in connection with Machine and Token accounts to expose the fact that they can be "unlocked" by access to key material matching the hash. The relevant hash algorithm prefix plus the hash are added to the array of strings so they can be connected to owner or steward accounts by Oleria
Identifier of the job or job profile of the Account's owner, also known as the Job ID (Workday Job Code — the Job Profile's reference ID; SuccessFactors Job Classification code)
"343949"
The job family of the Account owner's job — a grouping of related jobs that share core knowledge and background requirements (Workday and SuccessFactors Job Family). Narrower than jobFamilyGroup and broader than specialization
"Software Engineering"
The broadest grouping of job families for the Account owner's job (Workday Job Family Group)
"Technology"
The functional role or occupation of the Account's owner. A role-level descriptor, not a broad grouping — occupational groupings belong in jobFamily / jobFamilyGroup
"Product Manager"
The date of the last activity performed by the Account
"2024-05-02T03:17:34.948Z"
An identifier (unique to integrated application) for an Account object represented in the Oleria system. Oleria converts these identifiers to global ids so they can be unique in the context of the global system graph. It is important for this identifier to be based on an underlying persistent and reusable application or identity provider id so connections to the object are robust to metadata changes and other relevant operations
"user:U_kgDOB7P6Rg (GitHub based on node identifier), 838439349399 (Google Workspace based on user id), user:wiz-inc-4db1c46901 (GitHub based on app slug)"
Federation information used when specifying an EntityIdentifier
The date the Account was last modified
"2024-05-02T03:17:34.948Z"
The date the Account password was last changed
"2024-05-02T03:17:34.948Z"
The license regime under which the account is currently active or was last activated
Free, NotApplicable, Paid, Unassigned, Unavailable "Paid"
Is the account license active or inactive?
Active, Inactive, NotApplicable "Active"
The application-specific license type (or plan) used by the Account
"Enterprise Plan"
Array of manager emails for the employee that has the Account
The name (ideally full name) of the Account holder
1"Kirt Debique"
Federation information used when specifying an EntityIdentifier
An identifier (unique to the integrated application) for a ObjectDirectory object represented in the Oleria system. Oleria converts these identifiers to global ids so they can be unique in the context of the global system graph. It is important for this identifier to be based on an underlying persistent and reusable application or identity provider id so connections to the object are robust to metadata changes and other relevant operations
"repo:R_kgDOLL0doQ (GitHub based on repository node identifier), 1BUxdX4M-H7X8GKRgTjprJS8fjY_Ij1giE82lQlny2kc (Google Drive based on file id)"
An array of profile key-value pairs extending the schema of the Account object
Additional underlying account roles associated with the Account object
An application-specific tag representing the Account information data source
"OrgOwners"
A finer sub-discipline within the Account owner's jobFamily. There is no standard Workday or SuccessFactors foundation field for this — it is sourced from an org-defined specialty or sub-classification. Not the Workday Job Category field, which is a regulatory/EEO classification. Distinct from the business title
"Site Reliability"
The job title of the Account holder
"Chief Architect"
AuthorizedLocationPolicy is used to specify locations authorized for use by accounts, groups, roles, employees, departments, etc.
Aggregate access-risk posture for a non-human identity (Machine/Token account), derived from its impersonation and application-assignment relationships. Omitted for human accounts.
Normalized version of each alternate email found in Account.AlternateEmails
Cached count of resource instances this account can access. Values above 1000 may be approximate.
Names of owners assigned through Oleria's ownership-governance workflow - for example, non-human-identity ownership assignment.
Number of user accounts this non-human identity (Machine/Token account) can impersonate - a blast-radius indicator for NHI access risk. 0 when the identity has no impersonation reach. Null for human accounts or when not computed.
Most recent activity observed on this account.
Names of owners derived from the source system's management relationships.

