Skip to content

Entitlements

The catalog you can actually keep current.

Connector-declared entitlements become first-class objects in Owlie’s graph. Assignments link identities to them. Sync keeps the catalog current. Ownership and hygiene signals surface stale and orphaned access before it becomes an audit finding.

First-class objects

Every connector declares what it grants.

Roles in Auth0. Admin roles in Google Workspace. Group memberships in Microsoft Entra ID. Every connector declares the kinds of entitlements it exposes, and Owlie sync pulls the current set into the shared graph. From there, each entitlement is a first-class object — with attributes the rest of the platform can reason about: last-observed state, linked assignments, and which resource can grant it — along with the owner set on that resource.

Signals, not surprises

Four signals that keep the catalog honest.

Ownership.

Each resource — and everything it grants — can carry an owner: a user or group responsible for deciding who gets access. Ownership surfaces during access reviews and drives approval routing when access is requested.

Stale observations.

When sync stops observing an entitlement Owlie previously provisioned, the assignment is marked stale instead of deleted. The signal surfaces without destroying context.

Orphaned assignments.

Identities linked to entitlements whose source object has disappeared get flagged. Useful for JML cleanup and for audits that ask “who still has access to systems we decommissioned?”

Access reviews hook.

Entitlements are a natural scope for review campaigns. Campaign owners pick the entitlements to review; reviewers see assignments per entitlement.

Licenses you pay for

Some access is finite. Owlie counts it.

Give a resource a seat count and Owlie keeps track of what’s left. The catalog shows the seats remaining and won’t let someone pick a resource with none; a request against one that’s already full fails at creation, naming the resource, instead of entering an approval chain that couldn’t admit it. Those are advisories. The binding check runs at provisioning, serialized per resource, so two grants racing for the last seat don’t both take it. Pending, scheduled, provisioned, and disabled assignments hold a seat — a suspended account still holds its license, which is the number finance asks about — and revoking releases one. When a grant pushes a resource past 90% used, its owner gets a heads-up. Leave the count empty and nothing is tracked: this is a property you set on the resources where it matters, not a licensing module you have to adopt.

Honest about what’s missing

No entitlement-risk scoring. Not today.

Owlie does not ship a full entitlement-risk scoring model at launch. We don’t synthesize “this role is risky because X + Y + Z.” We surface the primitives — ownership, lifecycle state, stale flags, assignment graph — and let your policy decide. Risk scoring is a deferred feature; we’d rather say so than pretend.

Entitlements are where access gets real.

Early access is open. Bring the system whose roles nobody can explain.