Skip to content
open.securityopen.securityBeta

One identity. Many systems.

Identity Security Posture Management

A person can appear as an HR record, a directory account, a cloud principal, a SaaS user, and a code collaborator. ISPM tests whether an agent can connect those fragments into a defensible view of access, posture, and risk — across systems that were never designed to answer one question together.

One published contract.

Contract

ISPM-Enterprise-SQL@v1

A text-to-SQL evaluation over a frozen synthetic enterprise. The agent must query the world, explain the result, and leave a reviewable trace.

Contract published

No second modality published

Native-tool investigation and bounded remediation are research directions. Neither has a frozen tool surface or a scoring contract, so neither has a public identity to publish.

Six kinds of identity work.

Every task declares one theme: the identity-security job it performs. The taxonomy is the benchmark’s own, and the catalog filters on it.

Inventory & visibility
Establish who and what exists before making a security claim.inventory-visibility
Auth posture
Test password, session, recovery, and MFA controls.auth-posture
Privilege & exposure
Find direct, inherited, and cross-system administrative access.privilege-exposure
Lifecycle & offboarding
Trace access that survives a departure or deprovisioning event.lifecycle-offboarding
Dormant & stale
Identify unused credentials, accounts, and assignments.dormant-stale
Cross-vendor exploration
Infer identity links where platforms declare no foreign keys.cross-vendor-exploration

Where the difficulty is.

Identity security is a cross-vendor problem: privilege paths run through identity providers, clouds, HR records and code platforms that were never built to be queried together. What has been missing is a shared environment spanning them with known-correct answers. Under the one published contract, ISPM-Enterprise-SQL@v1, 52 of 127 tasks cross a boundary, asking an agent to resolve one person across systems whose only shared identifiers are an email, a username and an employee id. The other 75 stay inside one system, because an agent that misreads a password policy has no business correlating four of them.

One of the cross-vendor ones: “Which terminated employees still have AWS SSO access?” Nothing in the schema says the HR record and the directory account are the same person, so the join has to be inferred.

Composition

every bar is a share of 127 tasks

Theme

Auth posture33
Privilege & exposure28
Lifecycle & offboarding17
Credential hygiene16
Cross-vendor exploration16
Dormant & stale11
Inventory & visibility6

Scope

Single-platform75
Cross-platform52

Complexity

a scale, not a ranking

Easy64
Medium37
Hard26

Platforms

a task can span several

AWS61
Okta47
Google Workspace35
BambooHR21
GitHub16
Azure6
GCP4
MongoDB Atlas3

One frozen world.

Dataset
ispm-crossvendor-v1ISPM Cross-Vendor Snapshot — Osbench Labs, entirely synthetic.
Interface
SQLite snapshotThe agent queries the world it is asked about; nothing is live.
Systems
8 vendor-shaped systemsBambooHROktaAzure ADAWSGoogle WorkspaceGitHubGCPMongoDB Atlas