We started working with Linx Security as an ISPM. The first reasons were to have visibility into which employees have access to what applications. Within our industry, there were a lot of retail and real estate applications, and we were not able to get a very deep understanding of all our employees accessing them. That was our main initiative at the beginning. As we moved forward, we were also starting to implement the governance side, meaning not only doing the posture but also deciding based on what we have seen from the visibility side if you need access to the application, and we started to take actions, meaning provisioning you as an employee or taking your access away. So it started more in the ISPM front and then added also the governance or IGA front of the platform.
We were using CAD schemas, of course, as part of our work in the real estate market. We wanted to make sure that only a subset of the employees really has access there. We were not really able to do so with the APIs of the application or working through our IDP. The fact that Linx Security could have the connections to the HR system, the IDP, and the applications themselves gave us a very good understanding of that access. That was a big gap when we just started, and that was the leading use case for us to begin with.
The use case I shared was more of the way we started working with them. After we were able to validate the visibility to this scoped amount of applications and we saw the data was correct, we expanded to all the applications in the organization and then also enabled the part where we could really take action and run workflows. Once we did that, which was more or less a year after we started, we had also the workflows managing the joiners, the movers, the leavers in the company, and also contractors as well.
There is an area that we just started working with the team on. It is pretty new to us, and that is around controlling agents in our environment. Once you deploy them, first of all, we want to better understand which employees are deploying agents today. Second, after we understand that, to run the control center, which eventually controls what the agents are accessing.
