Every security team is sitting on a mountain of identity data. Almost none of them can answer basic questions with it. IRIS is the engine inside Zluri that converts fragmented identity signals into real-time answers about access, risk, and what to fix first.
There is a strange contradiction at the center of identity security. Teams have never had more identity data: directory exports, SaaS admin consoles, cloud IAM policies, HR records, access logs. And yet the fundamental questions remain painfully slow to answer.
Who has access to what, and is it still needed? How was that access granted, and when did it change? Where is the real risk, and what should we fix first?
The data to answer these questions exists. It is just scattered across a dozen systems in a dozen formats, and turning it into an answer means hours of manual correlation, per question, every time.
IRIS (Identity Risk Intelligence System) is Zluri's answer to that contradiction. It is the intelligence foundation of the platform: the engine that ingests fragmented identity signals and turns them into live, queryable context on access, risk, and identity relationships.
You Have the Data. You Don't Have the Answers.
The problem is not missing data. The problem is that identity data was never designed to be reasoned over together. Your directory speaks one schema, each SaaS app speaks its own, cloud IAM speaks another, and HR speaks a fourth. The same person exists as five different records with five different identifiers. The same entitlement means different things in different systems.

So when an auditor asks "show me everyone with access to financial data and how they got it," the answer is not a query. It is a project. Someone exports from six systems, reconciles identities in a spreadsheet, chases app owners for the entitlement mappings, and produces a snapshot that is stale before it ships.
The cost of this gap is measured in hours per question. Every access review, every incident investigation, every audit request pays the manual-correlation tax again, because the raw data never got turned into durable intelligence.
How IRIS Works: Four Stages From Signal to Decision
IRIS is built as a pipeline. Raw signals go in one end; prioritized, actionable risk intelligence comes out the other. Four stages make that happen.

1. Aggregation and Staging
IRIS ingests identity signals from across the environment: directories, SaaS applications, cloud platforms, and HR systems. Critically, it preserves source lineage as it does. Every piece of identity data retains a record of where it came from and when, which matters enormously later, when an auditor or investigator asks not just "what is true" but "how do we know."
2. Normalize and Canonicalize
This is the unglamorous stage that makes everything else possible. IRIS standardizes formats across sources, merges duplicate identity records, and produces one canonical record per identity. The five fragmented versions of the same employee become one authoritative identity, with every account, entitlement, and signal attached to it. Analysis built on canonical records is consistent and reliable; analysis built on raw fragments is guesswork.
3. Relationship Graph
With clean canonical records in place, IRIS maps how identities, entitlements, and applications connect. The graph reveals effective permissions: not just what an identity was directly granted, but what it can actually reach through group memberships, role inheritance, and app-to-app access paths. Direct entitlements are what your admin consoles show you. Effective permissions are what an attacker actually gets.
4. Intelligence and Decisioning
The final stage is where data becomes decisions. IRIS detects anomalies and risk patterns across the graph, prioritizes exposure so the riskiest items surface first, and recommends remediation actions. The output is not another dashboard of raw findings. It is a ranked answer to "what needs fixing, and in what order."
What IRIS Surfaces

Comprehensive identity visibility. Workforce and machine identities connected into a single source of truth, so there is one place to ask identity questions and one authoritative answer.
Proactive risk prioritization. Orphaned accounts, privilege creep, dormant access, and excessive entitlements, ranked by what needs attention first. The ranking is the point: every environment has hundreds of findings, and a flat list is just a different kind of noise.
Complete access context. For any identity, the full story: who has access, how it was granted, when it changed, and what risk it carries. The questions that used to take an afternoon of correlation become lookups.
Faster risk response. Because detection, investigation, and remediation live in the same platform, teams spot identity risks early and act on them without swivel-chairing between tools.
The practical shift: identity risk work moves from reactive archaeology (reconstructing what happened after something goes wrong) to continuous intelligence (knowing the current state, all the time, with the risky parts already flagged).
Intelligence Without Setup Overhead
An intelligence engine that takes a year of professional services to deploy is not intelligence, it is a project. IRIS ships ready to use: 10+ pre-built dashboards and 50+ widgets available from day one, 15+ app risk insights across risk categories, and a drag-and-drop interface for customizing analytics. No technical expertise or complex setup required to start getting answers.
This matters more than it sounds. Legacy identity analytics tools front-load months of data modeling before they produce a single insight. IRIS front-loads the modeling into the product itself, at the canonicalization stage, so the intelligence works out of the box.
Where IRIS Fits in the Zluri Platform
If IVIP is the platform's eyes, IRIS is its brain. Discovery feeds IRIS a complete stream of identity signals; IRIS turns that stream into the canonical records, relationship graph, and risk intelligence that everything else runs on.
That means access reviews are pre-loaded with risk context, so reviewers see which entitlements are dormant or excessive instead of rubber-stamping a flat list. Access requests can be evaluated against effective permissions, not just direct grants. Remediation recommendations arrive with the evidence chain attached, because source lineage was preserved from the first stage.
Every identity decision in the platform, human or automated, is a better decision because IRIS sits underneath it.
Frequently Asked Questions
What is IRIS in Zluri?
IRIS (Identity Risk Intelligence System) is the intelligence engine of the Zluri platform. It aggregates identity signals from directories, SaaS, cloud, and HR systems, normalizes them into canonical records, maps identity relationships, and produces prioritized risk intelligence with recommended remediation.
What is a canonical identity record?
A canonical record is the single, authoritative version of an identity after IRIS merges the duplicate and fragmented records that exist across different systems. All accounts, entitlements, and signals for that identity attach to the one canonical record, making analysis consistent.
What are effective permissions?
Effective permissions are what an identity can actually reach, including access inherited through groups, roles, and connected applications, as opposed to only the entitlements granted directly. IRIS computes these through its relationship graph.
How does IRIS prioritize identity risk?
IRIS detects patterns like orphaned accounts, privilege creep, dormant access, and excessive entitlements across the identity graph, then ranks findings by exposure so teams address the highest-risk items first rather than working through an unordered list.
Does IRIS require complex setup?
No. IRIS includes 10+ pre-built dashboards, 50+ widgets, and 15+ app risk insights available from day one, with a drag-and-drop interface for customization and no technical expertise required.
















