One identity. Many systems.
Identity Security Posture Management
One published contract.
ISPM-Enterprise-SQL@v1
A text-to-SQL evaluation over a frozen synthetic enterprise. The agent must query the world, explain the result, and leave a reviewable trace.
Contract published
No second modality published
Native-tool investigation and bounded remediation are research directions. Neither has a frozen tool surface or a scoring contract, so neither has a public identity to publish.
Six kinds of identity work.
Every task declares one theme: the identity-security job it performs. The taxonomy is the benchmark’s own, and the catalog filters on it.
inventory-visibilityauth-postureprivilege-exposurelifecycle-offboardingdormant-stalecross-vendor-explorationWhere the difficulty is.
Identity security is a cross-vendor problem: privilege paths run through identity providers, clouds, HR records and code platforms that were never built to be queried together. What has been missing is a shared environment spanning them with known-correct answers. Under the one published contract, ISPM-Enterprise-SQL@v1, 52 of 127 tasks cross a boundary, asking an agent to resolve one person across systems whose only shared identifiers are an email, a username and an employee id. The other 75 stay inside one system, because an agent that misreads a password policy has no business correlating four of them.
One of the cross-vendor ones: “Which terminated employees still have AWS SSO access?” Nothing in the schema says the HR record and the directory account are the same person, so the join has to be inferred.
Composition
every bar is a share of 127 tasks
Theme
Scope
Complexity
a scale, not a ranking
Platforms
a task can span several