Skip to content

Grants

The catalog you can actually keep current.

Grant targets become first-class objects in Owlie’s graph. Grants link accounts to those targets. Sync keeps the catalog current. Ownership and hygiene signals surface stale and orphaned access before it becomes an audit finding.

First-class objects

Every connector declares what it grants.

A Grant is the access an account holds: a role in Auth0, an admin role in Google Workspace, or a group membership in Microsoft Entra ID. A Grant target is what can be granted — the role or group itself. Every connector declares the Grant kinds it exposes, and Owlie sync pulls the current targets and held Grants into the shared graph. Each Grant target is a first-class object with attributes the rest of the platform can reason about: last-observed state, held Grants, and which resource can grant access to it — along with the owner set on that resource.

Catalog maintenance

Ownership and access hygiene.

Ownership.

Each resource — and everything it grants — can carry an owner: a user or group responsible for deciding who gets access. Ownership surfaces during access reviews and drives approval routing when access is requested.

Stale observations.

When sync stops observing a Grant Owlie previously provisioned, the assignment is marked stale instead of deleted. The signal surfaces without destroying context.

Orphaned assignments.

Identities holding Grants whose target has disappeared get flagged. Useful for JML cleanup and for audits that ask “who still has access to systems we decommissioned?”

Access reviews hook.

Grants are a natural scope for review campaigns. Campaign owners pick the Grant targets to review; reviewers see held Grants per target.

Licenses you pay for

Some access is finite. Owlie counts it.

Give a resource a seat count and Owlie keeps track of what’s left. The catalog shows the seats remaining and won’t let someone pick a resource with none; a request against one that’s already full fails at creation, naming the resource, instead of entering an approval chain that couldn’t admit it. Those are advisories. The binding check runs at provisioning, serialized per resource, so two assignments racing for the last seat don’t both take it. Pending, scheduled, provisioned, and disabled assignments hold a seat — a suspended account still holds its license — and revoking releases one. When an assignment pushes a resource past 90% used, its owner gets a heads-up. Leave the count empty and nothing is tracked. Set a count only on resources where you need to track seats.

Planned capability

Grant-risk scoring is planned.

Owlie does not ship a full Grant-risk scoring model at launch. Your policies can use ownership, lifecycle state, stale flags, and the assignment graph. Automated risk scoring is deferred.

Grants are where access gets real.

Sign up free. Bring the system whose roles nobody can explain.