Ask Your Identity Data Better Questions

Steve Goldberg
Steve Goldberg
Senior Solutions Engineer
August 10, 2026
3 min read
hydden-discovery-hero.png

For the past decade, identity visibility and intelligence tools (Gartner now has a category called IVIP) have performed privileged access assessments in roughly the same way. Scan the Windows and Unix estate, count the privileged accounts, flag the policy exceptions, hand over the findings. The report is accurate on the day it's produced, and it drifts from that day forward.

That made sense when the assessment served a project with an end date. Its job was to size a deployment, and one good snapshot was enough to get started. But privileged access management stopped being a project a long time ago.

Your assessment should be a query

Identity management, privileged or otherwise, is a continuous process. Accounts get created, people change roles, servers get decommissioned, and somebody stands up an integration on a Tuesday that nobody in security hears about. Your identity security posture changes every day.

That's why the modern version of the assessment cannot be a document. Instead, enterprises are demanding identity data that stays current and complete, so the next assessment is a query instead of another costly and time-consuming services engagement.

That changes the kind of questions you're able to ask. A report answers the question somebody thought to ask last quarter. A record you can query answers the question you have right now. Like, "show me every privileged account added to an admin group in the last thirty days" or "show me privileged accounts with no successful authentication in a year" or "show me service accounts with no attributed owner."

None of those are particularly odd questions. They're just impossible to answer from a PDF and a spreadsheet. So now, your work can really start. The same question that produced the finding can start the fix. Accounts with no owner go into attribution. Accounts with no authentication in a year get queued for deprovisioning. Accounts that need managing get tagged for the vault.

Hydden's Agent Studio is where you build both the query and response. You write the query, then define what happens to whatever comes back. Nothing sits in a report waiting for someone to pick it up. Instead, you can operationalize your PAM and IGA programs right away.

What it takes underneath

Look at those three questions again. Every one of them is about change rather than current state. Added in the last thirty days. Not used in a year. Never attributed to anyone.

Your directory can tell you who is in the admin group right now. It usually can't tell you who was added last month, or what that group looked like before. That gap is what sends people back into an engagement, because reconstructing history by hand is slow work and can require expensive engagements to get answers.

Hydden records those change events continuously, across the systems you already run. The history of every account's configuration change and activity is what makes your next identity security assessment a query.

See how Hydden integrates with your identity stack.

Frequently asked questions

Why does a privileged access assessment go out of date so quickly?

A traditional assessment reports the state of the estate on the day it runs. Accounts get created, people change roles, servers get decommissioned, and integrations appear without security hearing about it, so the findings drift from the moment they are produced. That was acceptable when the assessment existed to size a one-time deployment, but privileged access management stopped being a project a long time ago.

What does it mean for an assessment to be a query instead of a report?

It means the underlying identity data stays current and complete, so the next assessment is a question you run rather than another services engagement. A report answers the question somebody thought to ask last quarter. A record you can query answers the question you have right now.

What kinds of questions can you ask a continuous identity record?

Questions like which privileged accounts were added to an admin group in the last thirty days, which have no successful authentication in the past year, and which service accounts have no attributed owner. None of those are unusual questions. They are just effectively impossible to answer from a PDF and a spreadsheet.

Why can't a directory answer those questions?

Every one of them is about change rather than current state. A directory can tell you who is in an admin group right now, but usually not who was added last month or what that group looked like before. Reconstructing that history by hand is slow work, which is what sends teams back into an expensive engagement.

How does a query turn into remediation?

The same question that produced the finding can start the fix. Accounts with no owner go into attribution, accounts with no authentication in a year get queued for deprovisioning, and accounts that need managing get tagged for the vault. Agent Studio is where you write the query and define what happens to whatever comes back, so nothing waits in a report for someone to pick it up.

What has to be recorded for this to work?

Change events, captured continuously across the systems you already run. The history of every account's configuration change and activity is what makes the next identity security assessment a query rather than an engagement.

Share
Steve Goldberg

Steve Goldberg

Senior Solutions Engineer

Senior Solutions Engineer at Hydden. Focused on connecting enterprise security teams with the identity visibility they need.

Stay Ahead of Identity Security Threats

Get the latest insights on identity governance, zero trust, and cybersecurity delivered to your inbox.

© 2026 Hydden Inc. All rights reserved.Privacy PolicyTerms of Service