# Icite — The Identity Layer Your Stack Is Missing > Icite is an Identity Intelligence Platform for security operations: identity threat detection and investigation that correlates identity, access, configuration, and activity across every connected system in a single query. Your EDR covers the endpoint, your NDR the network, your CDR the cloud, your SIEM indexes the logs — none of them model identity. Icite is the fourth detection source into your SIEM, not a replacement for it: the identity layer that catches the attacks falling through the gaps between EDR, Cloud, and SIEM. ## Company - **Name:** Icite, Inc. - **Founded:** 2024 - **Headquarters:** Houston, TX - **Founders:** Wes Mullins (CEO) - **Category:** Identity Intelligence Platform — identity threat detection and investigation (ITDR + investigation), spanning identity visibility, posture (ISPM), threat detection, and response - **Tagline:** Identity is everything. - **Website:** https://icite.io - **Demo:** https://go.geticite.io/demo ## The Core Idea: Identity Attacks Aren't On a Surface Your security stack is organized by surface. EDR watches the endpoint. NDR watches the network. CDR watches cloud infrastructure. The SIEM ingests all of their logs. Each one sees a surface — and an identity attack isn't on a surface. It's a person, moving across systems, over time. - **EDR** watches the endpoint. An attacker operating through legitimate SaaS sessions barely touches one. The sensor is pointed at the wrong surface. - **NDR** watches network traffic. Identity attacks travel over encrypted, authorized channels that look like normal traffic. - **CDR** watches cloud infrastructure. Google Workspace, Salesforce, and GitHub sit outside its scope entirely. - **SIEM** ingests all their logs but sees log lines — not a person, not access state, not how that access changed. `EDR · NDR · CDR · Icite → SIEM` Icite is the fourth detection source into your SIEM, not a replacement for it. It models the one thing the other three can't: identity. ## The Problem Identity is the #1 attack vector, and the tools security teams stitch together for it were each built for a different problem. **By the numbers:** - **60%** of all 2025 reported incidents were identity attacks (Cisco Talos) - **42%** of 2025 breaches involve compromised credentials (Verizon DBIR) - **$3B** total impact in 2025 from Business Email Compromise (FBI) - **80%** of breaches involve compromised identities - **241 days** average time to identify an identity breach - **4-6 tools** stitched together by the average SOC to answer one identity question - **0 tools** today join identity + permission + configuration + events on one person - **30 minutes** to see real findings in an environment running your existing stack **Why today's tools miss it:** - **SIEMs** index billions of events but have no identity context layer. They can't answer "who has access to what?" A SIEM can tell you an IP logged in; it can't tell you the person behind that IP is an over-privileged admin with MFA disabled who was added to three new groups last week across two identity providers. - **ITDR** tools detect threats in authentication streams but lack configuration data. They see the attack, not the attack surface — they can't assess the blast radius of a compromised identity. - **UEBA** platforms baseline behavior without identity context. An anomalous login from a user added to an admin group 24 hours ago gets the same anomaly score as the same login from a tenured engineer on vacation. They surface anomaly scores without the story. - **ISPM** tools assess configuration snapshots without real-time events. They flag a stale account but can't show you the login history that proves it. **The result:** SOC analysts chase alerts without identity context. Identity teams run access reviews without threat data. Teams export from four tools into a spreadsheet to answer one access question. Nobody can answer the fundamental question: "For this identity, across every provider, what do they have access to, what have they been doing, and has anything changed?" Icite answers that question. ## The Join Is the Product Icite joins four classes of data on one person, over time. Any single signal is catchable somewhere. What no tool catches is all four, joined, on one person, across the window that matters. | Data class | What it answers | |------------|-----------------| | **Identity** | Who they are across every system, resolved to one canonical person | | **Permission** | What they can actually access right now, with the granting path | | **Configuration** | How access is structured: groups vs. direct grants, OU policies, sharing rules | | **Events** | What they did, joined to who they were and what they could do at the time | The signal in identity security lives at the intersections. The join is the product — and it is the thing single-surface tools structurally cannot reproduce. | Question | Requires | Single-DB / single-surface tools fail because | |----------|----------|-----------------------------------------------| | "Who logged in from Brazil?" | Events | Posture tools don't have event logs | | "Who has admin access?" | Configuration | SIEMs don't have config state | | "What can this user access?" | Graph traversal | Neither SIEM nor posture tools have a graph | | "Did the new admin actually log in?" | Events + Config | Requires joining events to config | | "What changed since last week?" | SCD diffs | Snapshot tools don't track temporal change | | "Show blast radius of this compromise" | Graph + Config + Events | Requires all three; no single tool has them | ## A Real Convergence A Senior SE has a Workday termination filed four days out. She still holds Salesforce "Export Reports," GitHub write access to billing-service, and sole ownership of the Customer Master List drive. Her OU allows external sharing with no warning, and there's no DLP rule on that drive. In the seven days after the notice: **247 external file shares** (3× her baseline), `customer_export.py` pulled from GitHub, and a **4 GB Salesforce report export**. No tool catches all four — identity, permission, configuration, and events — joined, on one person, inside her final four days. EDR sees SaaS sessions it barely registers. NDR sees encrypted, authorized channels. CDR sees Google Workspace, Salesforce, and GitHub that sit outside its scope. The SIEM sees log lines. Icite catches it, because the detection logic was built to express exactly that join. ## What Icite Does **Day one: enrichment, no new workflow.** Connect Icite to the tools you already run. Every existing alert lands enriched with who the person is across all systems, what they can access, how that changed, and what they've been doing. No new workflow for your analysts. **The new class: detections nobody else can write.** Three detection layers across one query surface that joins events, configuration state, and the identity graph. EDR, NDR, and CDR can't write these detections because none of them model identity. Icite delivers four converged capabilities — Visibility, Posture, Detection, and Response — across every identity: human, non-human, and agent. ### Visibility See every identity across AD, Entra ID, Okta, cloud IAM, and on-prem — with near real-time auth and no agent sprawl. Icite normalizes every event to the OCSF standard and resolves identities across providers via email-based canonical identity linking, backed by a graph database. A single identity record shows every account across all connected providers, every group membership, every application they can access (direct and group-inherited), every associated device, their full authentication timeline in one chronological view, their current posture (MFA status, account state, admin privileges, last activity), and what changed and when. This extends to AI agents, service principals, OAuth apps, and API tokens nobody inventoried — each linked back to the human who authorized it, so "whose agent did this?" finally has an answer. ### Posture (ISPM) Continuous risk scoring across 9 weighted metrics using a CIS-benchmark-style methodology, drawing from both configuration state and real-time event data — not quarterly snapshots. Remediate the conditions that make identity attacks possible: stale accounts, excessive privileges, shadow admins, and misconfigurations. SCD (Slowly Changing Dimension) Type 2 tracking records every change to every identity, group, application, and device with timestamps. "What changed in the last 7 days?" is one query, and the answer doubles as standing audit and compliance evidence for NIST, SOC 2, and ISO. Dozens of finding types are detected automatically — privilege escalation, new admin account, MFA disabled, off-boarding gap, device compliance drift, cross-provider drift, orphaned group membership, app access expansion — each classified by severity. ### Detection Fewer, higher-signal findings: deterministic, context-enriched, and inquiry-driven detections that grow from your own investigations instead of adding rules to maintain. Catch attack-path escalation, token attacks, privilege creep, and credential theft. See [The Detection Engine](#the-detection-engine) for the full model. Example detections shipping today: - **Cross-Cloud Privilege Escalation Chain** — a single enriched identity is granted an elevated role within a short window - **Shadow Identity Divergence Across IdPs** — a human's linked identities behave inconsistently across providers - **Post-Auth Exfiltration Setup, Cross-Surface** — an authentication anomaly is followed on the timeline by an exfil-enabling change on a different surface - **Hybrid Identity Desync Abuse** — an on-prem identity diverges from the cloud-side state of that same resolved person ### Response and Isolation When a threat is confirmed, isolate a compromised identity in seconds across every provider at once — not a ticket queue, one click: - **User isolation:** restrict a compromised identity to a predefined access tier (e.g., read-only, essential apps only) across Okta and Entra ID simultaneously - **Session revocation:** revoke all active sessions for isolated users across connected providers - **Multi-tier isolation:** configurable isolation tiers per tenant, each mapping to IdP groups and allowed application sets - **Audit trail:** every isolation action is tracked with who initiated it, when, and which tier was applied ## Identity Investigation for Your SOC Most alerts, regardless of where they originate, need some form of identity investigation. Connect Icite and every alert gets a comprehensive identity investigation — automatically. **Auto-investigations.** Icite investigates a finding end-to-end: reviewing tens of thousands of event logs, comparing configuration diffs, analyzing the graph database, building a timeline, and producing an impact assessment with key findings and recommended responses. In the Senior SE scenario above, Icite's recommendations are specific and actionable: revoke the 247 external Drive shares that persist after termination, transfer sole ownership of the Customer Master List drive to her manager, and remove the Salesforce "Export Reports" permission she used for the 4 GB export. **What makes the investigation possible:** - **Full event logs.** SIEMs are expensive and don't collect everything. Icite fills the gaps with full event payloads. - **Historical config data.** Icite collects configuration logs and snapshots every change — a configuration time machine. - **Canonical identities.** Tracking one person across systems is nearly impossible for a SIEM. Icite stitches a dozen usernames into a single canonical identity automatically. **AI Security Analyst.** Investigate identity questions in plain English. Unlike chatbots bolted onto dashboards, Icite's agent has direct query access to all three data stores through 13 purpose-built tools and follows a hypothesis-driven methodology — scope the question, form hypotheses, test against data, refine, and report findings with evidence strength labels (Confirmed, Observed, Inconclusive). Every claim traces to a specific tool result. Questions teams use Icite to answer — the ones their existing stack can't: - "Show me everything about jane@company.com across all providers" - "Which users have access to production cloud but no longer appear in our HRIS?" - "Which identities have significantly more access than peers in the same role?" - "Which non-human or agentic AI identities are active, and who owns each?" - "If john@company.com is compromised, what applications are at risk?" - "Did anyone with a termination in the last 30 days export customer data?" ## Proprietary Data Architecture Three databases, one query surface, purpose-built for identity. No other vendor ships all three in a single platform purpose-built for identity. The signal in identity security lives at the intersections, so the join is the product. ### Time-Series Event Analytics (ClickHouse) - OCSF-normalized audit events from all 19+ integrations - Sub-second queries across billions of events - Fields: timestamp, actor email, actor name, activity type, target resource, source IP, geo-location (country, city, coordinates), ISP/ASN, connection type, user agent, full raw event payload - Enables: timeline analysis, behavioral detection, authentication pattern analysis, geo-anomaly detection ### Relational Identity Configuration — SCD Type 2 (PostgreSQL) - Slowly Changing Dimension tables for user records, groups, applications, devices, and identity resolution results - Every state change tracked with valid_from/valid_to timestamps and status (current, changed, deleted) — the full trajectory of state, queryable at any point in time, not a snapshot of "now" - AccountState JSONB stores provider-specific fields: MFA status, admin roles, account type, job title, department, last password change - Enables: posture scoring, access reviews, change tracking, configuration drift detection, compliance reporting ### Identity Relationship Graph (Neo4j) - Nodes: SourceUser, Group, Application, Device, Email, Identity (canonical) - Relationships: HAS_EMAIL, GROUPED_IN, ASSIGNED_TO, RESOLVES_TO — all temporally versioned - Multi-hop traversals: User → Group → Application → Device → Permission, with cross-provider identity resolution via email-based canonical linking - Enables: blast radius analysis ("if this identity is compromised, what can they access?"), reverse lookups ("who has access to this application?"), cross-provider entitlement mapping, graph-based anomaly detection ## The Detection Engine Every other identity detection product — SIEM, UEBA, ITDR — treats detection as finding patterns in event logs. Icite treats it as joining four kinds of data: *what happened* (events), *what's true* (configuration state), *how things connect* (identity graph), and *what you've been investigating* (inquiry history). No single-plane system can match this, because the signal in identity security lives at the intersections. Detections are written in plain English and run in production the same day. ### Four data planes, one query surface 1. **Time-series events** (ClickHouse) — OCSF-normalized audit logs from 19+ integrations, sub-second queries over billions of events. 2. **Configuration state** (PostgreSQL SCD Type 2) — identities, groups, applications, devices, and entitlements with `valid_from`/`valid_to` timestamps. The full trajectory of state, queryable at any point in time. 3. **Identity relationship graph** (Neo4j) — multi-hop traversals across SourceUser → Group → Application → Device → Policy → Permission → Scope, with temporal edges. How Icite answers "how did this person get access to this thing" and "what's the blast radius if they're compromised." 4. **Investigation corpus** — every inquiry the AI Security Analyst has completed, with its tool calls, data retrieved, hypotheses tested, and findings. The fourth plane, and the one competitors don't have a path to: it makes the system get smarter with every investigation. A detection authored against Icite is a single expression that can span all four planes. "Find logins from a new country, by a user who was added to the Finance admin group in the last 7 days, whose device is outside MDM compliance" is one query against Icite — not three systems stitched together at the analyst's desk. ### Three detection layers **1. Deterministic — config + graph.** Assertions about the state of the identity graph that are provably true or false. Because they check structural facts rather than guess intent, they approach zero false positives by construction. Detects: shadow admin access via nested group inheritance, cross-provider offboarding gaps, privilege accumulation across role transitions, dormant privileged accounts, MFA coverage gaps on sensitive access paths, device compliance drift against sensitive applications, and toxic permission combinations that violate separation of duties. The question is never "is this real?" — it's "do we fix this?" **2. Contextual anomaly — time-series + baseline + graph.** Behavioral baselines that arrive already enriched with identity, permission, and device context, so an anomaly comes with the story attached. Icite maintains per-identity behavioral fingerprints (30-day rolling statistics: active hours, typical IP/geo clusters, application usage, authentication patterns, event volume) and peer-group baselines (identities clustered by shared entitlements via graph structure, not org chart). Scoring is ML-driven and multi-dimensional: a single deviation (new IP) is not a finding; a deviation crossing multiple axes (new IP + new hours + first-time access to an app inherited through a group added last week) crosses the threshold and is emitted with the correlated context already attached. UEBA emits the signals; Icite emits the already-correlated finding. **3. Inquiry-driven — agent to detection.** Detections that emerge from your own investigations. When the AI Security Analyst completes an investigation and identifies a finding, it proposes a detection that watches for the same pattern proactively. One decision promotes the inquiry to a running detection, scheduled on Temporal, with the full query set derived from the investigation. Your coverage compounds over time, learned from your own operators rather than a vendor roadmap. ### Conversational detection authoring Detections are not written in a proprietary rule language. Operators draft detections in conversation with a detection-authoring agent that has direct query access to the time-series store, the graph, and the SCD tables. The agent translates intent into time-series, relational, or graph queries, runs them against sample data, and iterates with the operator until the query set is tuned. Build complex detections specific to your environment in seconds — stop waiting weeks for custom detections. (Private beta.) ### Detection lifecycle and output `Draft → Published → Operationalized → Deprecated`. Scheduled execution runs on Temporal for durability — every scheduled detection has retries, run history, and durable state across worker restarts. Each detection accrues run metrics (success rate, match count, true-positive/false-positive signal) that feed tuning, and can be versioned, forked from Icite-authored templates, or deprecated with archived history. Every detection emits an **OCSF 1.3 Detection Finding** object: severity, confidence, status (new / in progress / suppressed / resolved / archived), linked identities, linked applications, MITRE ATT&CK tactics and techniques, and source attribution back to the detection that produced it. Findings are interoperable — downstream SOAR, ticketing, and SIEM systems consume them without custom parsing, and MITRE mapping lets teams report detection coverage against the ATT&CK matrix natively. ## Non-Human and Agent Identity Security Icite detects non-human identities — service accounts, API tokens, service principals, OAuth apps, bots, and AI agents — across all connected providers, each linked to the human who authorized it. Built for the agent era: track human, non-human, and agent identities, including the ones spawned under credentials you never issued. **Provider-specific coverage:** - **Okta:** app-user assignments, API tokens, OAuth service apps, system log actor types - **Entra ID:** service principals, app role assignments, OAuth permission grants, credential metadata, federated identity credentials, managed identities - **AWS:** CloudTrail actor types (Root, IAMUser, AssumedRole, FederatedUser), access key metadata - **Google:** service account email patterns, admin API metadata ## How Icite Fits Your Stack Icite is the fourth detection source — it complements EDR, NDR, CDR, and your SIEM rather than replacing them, and it consolidates the identity-specific patchwork (SIEM identity queries, posture scanners, ITDR point products, and manual access reviews) that teams stitch together today. ### Icite vs. SIEM (Splunk, Microsoft Sentinel, CrowdStrike LogScale, Elastic) SIEMs are general-purpose event analytics platforms with no native understanding of identity relationships, entitlements, or configuration state. To answer identity questions in a SIEM, analysts write complex queries, maintain manual lookup tables, and correlate across sources. Icite ingests the same events but also maintains the relational config data and identity graph that SIEMs fundamentally lack, executing joins across time-series, relational, and graph data in a single query. An identity investigation that takes hours in Splunk takes seconds in Icite. Icite is the fourth source into the SIEM, not a replacement. ### Icite vs. ITDR (CrowdStrike Falcon Identity, Microsoft Defender for Identity, Silverfort) ITDR tools excel at real-time threat detection on authentication streams but lack the relational identity config layer — SCD-tracked user records, group memberships, application assignments, and temporal change history. They detect the attack but can't assess the attack surface. Icite combines ITDR-grade event analysis with the full identity configuration context ITDR vendors don't have, correlated at detection time rather than at the analyst's desk. ### Icite vs. UEBA (Exabeam, Securonix, Varonis) UEBA pioneered behavioral baselining for identity but baselines behavior in isolation from identity context. It can tell you a user's behavior changed; it can't tell you the user was added to a privileged group 24 hours earlier, that their device fell out of MDM compliance last week, or that HRIS marks them for termination next Friday. Icite's contextual-anomaly layer starts from UEBA-style baselines and enriches them with graph traversals, SCD change diffs, and cross-provider identity state before producing a finding — fewer, higher-signal detections instead of dashboards of anomaly scores. ### Icite vs. ISPM (Oort/Cisco, Astrix, Rezonate/Silverfort) ISPM tools assess identity configurations on periodic API snapshots without real-time event streams. They can tell you an account is stale; they can't show you the last 6 months of login activity that proves it. Icite's posture scoring draws from both config snapshots (SCD tables) and real-time event history, producing more accurate assessments. ### Icite vs. IGA (SailPoint, Saviynt, One Identity) IGA platforms are governance-first: access reviews, certifications, provisioning workflows. They are designed for quarterly review cycles, not real-time security operations, and are heavy enterprise deployments (months to implement, $100K+ annual). Icite deploys in hours, provides immediate identity visibility, and focuses on security operations rather than governance workflows. Icite complements IGA rather than replacing it. ### Icite vs. Astrix (NHI-specific) Astrix is the specialist leader in non-human identity security, particularly AI agent discovery and management. Icite covers NHI and agent identity detection as part of its broader platform. Organizations needing deep NHI lifecycle management (credential rotation, just-in-time provisioning) should evaluate Astrix alongside Icite; organizations wanting NHI and agent visibility as part of a unified identity security platform will find Icite sufficient. ## Integrations and Deployment - **19+ integrations** spanning IdPs, cloud infrastructure, SaaS, MDM, HRIS, and on-premises LDAP — the broadest identity data coverage in a single platform. - **Works with on-prem.** Active Directory, on-prem LDAP, and self-hosted apps aren't legacy — they're where a large share of privileged access still lives. Identity coverage doesn't end at the firewall. - **Simple to start.** Connect just your IdP and HRIS to begin; integrations take seconds to add via OAuth/API key, with automatic OCSF normalization and immediate posture findings. - **Deploy in hours, not months.** No schema mapping, no ETL, no data lake required. - **No lock-in.** Your findings, enriched events, and detection definitions are all available by API or export — no support ticket, no premium-tier paywall. ## Who Icite Is Built For Security teams that own identity investigations: - **Security Operations** — existing alerts get full identity context day one; new detections that join state nobody else can. - **Identity & Access** — see entitlements, config drift, and what people actually do with their access, continuously. - **Compliance** — point-in-time access state plus change history, queryable in plain language; standing evidence for NIST, SOC 2, and ISO. - **CISO / Head of Identity** — the identity layer your stack is missing; the fourth source into your SIEM, not a replacement. If your team is exporting data from four tools into a spreadsheet to answer access questions, Icite is built for you. ## Why Now The identity blind spot is widening. Identity convergence is proven by the M&A wave, and the agent era adds identities nobody issued. Icite was built converged from day one, not acquired and stitched together. In 2025-2026: CyberArk acquired Zilla (IGA); Silverfort acquired Rezonate (cloud ISPM/ITDR); Delinea acquired Authomize (ISPM/ITDR); Cisco acquired Oort (ISPM/ITDR); ServiceNow acquired Veza for $1-1.5B (IGA/ISPM); Saviynt raised $700M to build converged ISPM + ITDR + IGA. Every major vendor is racing to combine these capabilities into a single platform — proof that fragmented identity tools create dangerous blind spots. Icite's three-database architecture was purpose-built to unify time-series events, relational config state, and graph relationships from day one — the same convergence incumbents are spending billions to acquire. ## Key Differentiators (Summary) 1. **The fourth detection source** — EDR · NDR · CDR · Icite → SIEM. Complements the stack, models the identity layer none of them do. 2. **The join is the product** — Identity + Permission + Configuration + Events, joined on one person over time. The signal lives at the intersections. 3. **Three-database architecture** — time-series + relational + graph purpose-built for identity; no other vendor ships all three in one platform. 4. **Three-layer detection model** — deterministic (approaching zero false positives by construction), contextual anomaly (ML baselines enriched with identity, graph, and peer-group context), and inquiry-driven (learned from investigations) — all in one query surface. 5. **SCD Type 2 temporal tracking** — every identity, group, app, and device change recorded with timestamps; "what changed?" queries snapshot tools can't answer. 6. **Identity investigation built in** — auto-investigations on every alert plus an AI Security Analyst with direct query access to all three data stores via 13 tools. 7. **Conversational detection authoring** (private beta) — draft detections in plain English against all three data stores, in production the same day. 8. **Cross-provider canonical identity resolution** — a dozen usernames stitched into one identity automatically, backed by a Neo4j graph. 9. **Human, non-human, and agent coverage** — ready for the agent era, with every machine identity linked to the human who authorized it. 10. **19+ integrations** spanning IdPs, cloud, SaaS, MDM, HRIS, and on-prem LDAP — deploy in hours, no lock-in, export by API. ## Industry Context - **ITDR market:** $12.8B (2024) growing to $35.6B by 2029 (22.6% CAGR) - **ISPM market:** $13.7B (2024) growing to $33.1B by 2029 (19.3% CAGR) - **IAM total market:** ~$21B (2024) growing to $65.7B by 2034 (12.4% CAGR) - **Analyst consensus:** ITDR and ISPM are "two sides of the same coin"; the market is converging into unified identity security platforms. - **Gartner:** identified ITDR as a top security trend since 2022; no standalone ITDR Magic Quadrant yet. - **Adoption rates (2025):** ITDR 26% deployed, ISPM 24% deployed, IGA 22% deployed — all with substantial near-term deployment intent. ## Get Started **30 minutes. Real findings.** Point Icite at an environment running your stack. We show you findings you didn't know about, or we haven't earned the conversation. - **Website:** https://icite.io - **Request a demo / trial:** https://go.geticite.io/demo - **General contact:** info@icite.io - **Security policy:** https://icite.io/security-policy - **Security contact:** security@icite.io *Identity is everything.*