Forge brings cloud and repository machine identities into one inventory while
preserving their provider-native identity. Open Identities → NHIs to review
service accounts, IAM roles and users, applications, managed identities,
repository credentials, and other supported non-human principals.
What Forge shows
Each record can include its provider and account scope, native type, status,
credential posture, activity, AI relationships, ownership evidence, access,
and the source connection that produced the record. Missing evidence is shown
as unavailable rather than inferred.
Provider actors and contacts are attribution leads. Forge reports an
accountable human owner only when the provider record joins to accepted
directory, SCIM, email, or person evidence. Bots, applications, deleted users,
and login-only records remain machine or unresolved identities.
Inventory and evidence coverage
Inventory is collected from each connected AWS account, Azure tenant and
subscription, Google Cloud project, and GitHub organization. A sync can be
complete, partial, stale, permission-blocked, or failed for an individual
evidence family. Other successfully collected identities remain available when
one provider surface is incomplete.
Use the evidence section in an identity drawer to distinguish current provider
state from historical activity, accountable ownership from a provider contact,
direct grants from inherited access, and an empty result from a permission or
retention gap.
Native actions
Supported identities can expose provider-native actions such as revoke or
disable. An inventory connection never authorizes those actions by itself.
Forge enables an action only when a separate operator connection is healthy and
the server has an exact target, current before-state, expected provider effect,
and independent readback plan.
Previewing an action does not change provider state. Execution creates a
durable operation and preserves provider acceptance, execution, readback,
residual access, and completion as separate facts. If readback cannot prove the
expected state, Forge reports the operation as pending or unproven rather than
successful.
Disabling a principal or credential may prevent new authentication without
ending previously issued sessions or tokens. Review the residual-access result
before treating containment as complete.
Troubleshooting incomplete inventory
Open the source integration and inspect its latest Test and Sync results. Add
only the permission named by the failed evidence family, then run Sync again.
A healthy read from one cloud service does not prove that every NHI, activity,
credential, or ownership source is readable.