TrustRadius: an HG Insights company

What is Identity Rules?

Identity Rules is a unified Identity Threat Detection and Response (ITDR) and Identity Visibility and Intelligence Platform (IVIP) developed for security teams at regulated enterprises. The platform combines real-time detection of identity-based threats with continuous visibility and intelligence across human and non-human identities, spanning Active Directory, Okta, Microsoft Entra ID, AWS IAM, Google Workspace, Oracle Database, and Linux environments.

Key Capabilities
  • Real-time detection of compromised privileged accounts, unauthorized privilege escalation, dormant account reactivation, and abnormal access patterns.
  • MITRE ATT&CK identity-linked technique coverage including T1078 (Valid Accounts), T1098 (Account Manipulation), and T1556 (Modify Authentication Process).
  • Dedicated Non-Human Identity (NHI) security: service accounts, API tokens, workload identities (AWS IAM roles, Azure service principals, Kubernetes service accounts), automated agents, and OAuth applications.
  • Natural-language conversational assistant for SOC investigation, compliance evidence generation, and query execution on identity data.
  • Native integration with SIEM platforms (Splunk, Microsoft Sentinel), SOAR (ServiceNow), and identity providers.
  • Multi-tenant architecture for Managed Security Service Providers (MSSPs) delivering identity security across multiple customer tenants.

Differentiators
  • Unified ITDR + IVIP within a single platform: unlike vendors offering only threat detection (such as CrowdStrike Falcon Identity Protection) or only governance (SailPoint IdentityIQ, Saviynt Enterprise Identity Cloud), Identity Rules delivers both categories within a single deployment.
  • Docker-based deployment architecture: the platform is designed to deploy in days rather than the multi-month timeframes typical of legacy IGA implementations, without requiring a dedicated consulting engagement.
  • Native LATAM regulatory coverage: automated evidence generation for CNBV (Mexico), SFC (Colombia), CMF (Chile), SBP (Panama), and SUGEF (Costa Rica), alongside global frameworks including SOX, PCI-DSS, ISO 27001, and HIPAA.
  • Hispanic-native product: full Spanish and English interface with customer success operating in LATAM time zones, which is uncommon in ITDR and IGA categories typically dominated by US-headquartered vendors.

Common Categories of Findings
Identity risk assessments run on the platform commonly surface: non-human identities without a designated owner, service account credentials lacking rotation history, over-privileged accounts, dormant accounts still holding access, and privilege escalation paths crossing human and non-human identities.

Deployment and Pricing
Identity Rules deploys as SaaS (managed cloud hosting) or on-premise (Docker containers on customer infrastructure), using the same underlying engine. Pricing follows a subscription model — monthly or annual — that scales by number of identities and connected systems. A fixed-scope Identity Risk Assessment engagement is also available for organizations conducting an initial evaluation without long-term commitment.

Target Users
Identity Rules is used by CISOs, IAM leaders, SOC managers, and compliance teams at mid-market and enterprise organizations (500 to 10,000+ employees) in regulated industries: banking and financial services, insurance, telecommunications, government, healthcare, and technology. Primary geographic markets are Mexico, Colombia, Chile, Panama, and Costa Rica, expanding into the United States and Spain.

Videos

Screenshots

Screenshot of Executive dashboard showing the identity activity funnel — from monitored activities (18) to anomalies detected (4) to active incidents (0) — for a selected date range. Adjacent timeline visualizes incident detection and total AI-driven  analysis events per day, with headline KPIs for active incidents, human vs. non-human identities involved, activities analyzed, and anomalies analyzed.
Screenshot of Assets tab of the executive dashboard, delivering a unified inventory of 17 identities, 116 human accounts, 170 non-human identities (NHI), 599 entitlements, and 728 anomalies. Account risk distribution (Critical, High, Medium, Low) sits alongside behavioral anomaly indicators such as "NHI credential never expires" (169) and "NHI credential not rotated" (164), plus account state breakdown between active, locked, deleted, privileged, and shared accounts.
Screenshot of Security incident management workspace where SOC and IAM teams triage identity threats across all connected systems. Each incident is displayed with source application (Google Workspace shown here), severity (Critical / High / Medium / Low), lifecycle state (New, In Triage, Closed), 
AI-calculated confidence score, and final verdict — including labels like Token Theft, Lateral Movement, Password Spraying, Legitimate Activity, Business Exception, and Insufficient Evidence.
Screenshot of Detailed incident view for a high-severity case: "NHI account without owner and insecure credentials in Google Workspace". The AI Analysis tab maps the finding to MITRE ATT&CK tactic TA0006 (Credential Access) and technique T1556 (Modify Authentication Process) at 80% confidence, showing affected accounts, related activities, and correlated anomalies. An AI-generated Quality Assessment panel surfaces assumptions, evidence gaps, and cross-incident correlations so analysts can act with full context.
Screenshot of Analytics view organizing every identity anomaly by MITRE ATT&CK tactic and technique. isplayed here: TA0006 (Credential Access) with 7 detections across 2 techniques, and TA0003 (Persistence) with 2 detections across 2 techniques. The right-hand panel drills into T1556 (Modify uthentication 
Process) showing each individual detection with application, stage, verdict (Legitimate Activity, Business Exception), severity, and affected accounts — giving SOC teams a native ATT&CK-aligned view of their identity attack surface.
Screenshot of Interactive graph visualization of account relationships. Central node shows a Linux "root" account on Ubuntu, connected via directional edges to its two entitlements — "root" and "docker" privileged access on Ubuntu Linux. The legend explains node types (accounts, entitlements, child nodes, parent nodes), giving IAM and security teams a visual map of how privileges are structured across systems.
Screenshot of Account graph showing an Active Directory "Administrator" account on Windows Server 2012, with its six group memberships and entitlements: Administrators, Registry Users, Domain Admins, and additional privileged groups. Color-coded edges distinguish entitlement types and privilege levels, making it easy for security teams to spot excessive privileges, unexpected group membership, and identity attack paths crossing multiple Active Directory objects.

1 / 7

Screenshot of Executive dashboard showing the identity activity funnel — from monitored activities (18) to anomalies detected (4) to active incidents (0) — for a selected date range. Adjacent timeline visualizes incident detection and total AI-driven analysis events per day, with headline KPIs for active incidents, human vs. non-human identities involved, activities analyzed, and anomalies analyzed.

Technical Details

Technical Details
Deployment TypesOn-Premise, SaaS
Operating SystemsWindows, Linux, Mac
Mobile ApplicationNo
Supported CountriesLatam, USA, Canada
Supported LanguagesEnglish, Spanish

FAQs

What are Identity Rules's top competitors?
CrowdStrike Falcon Identity Protection are common alternatives for Identity Rules.