Identity & Access

Identity & Access

Troposphere imports the full principal directory from each connected cloud provider and joins it to the role assignments that grant those principals access to your resources. The Identity & Access section gives you a single place to audit who (and what) can do what across your estate.

The Overview page

Navigate to Identity & Access > Overview in the sidebar. The page opens with four summary cards:

  • Total Principals – every user, group, service account, and federated identity imported across your connections.
  • Active – the subset that is currently enabled in the directory.
  • Privileged – principals that hold a privileged role (Owner, Contributor, User Access Administrator). The card turns amber when more than two principals carry privileged access.
  • Connections – how many connections contributed to the numbers above.

Below the cards, the page breaks down the directory several ways:

  • By Type – Users, Groups, Service Accounts, and Federated Identities with counts.
  • By Status – Active, Disabled, and Deleted principals with counts.
  • Role Distribution – how often each role appears across all assignments. Useful for spotting common role patterns or unexpected sprawl.
  • Privileged Access – which privileged roles are in use and how many principals hold each. Clicking a privileged role opens the Role Assignments page filtered to that role.
  • Recent Principals – the most recently imported principals with quick links to their detail pages.
  • By Connection – a per-connection breakdown of how many principals each connection contributes.

What’s covered in this section

  • Principals – browse the full principal list, filter by type and status, and drill into individual principals.
  • Role Assignments – see every role assignment across your estate, filtered by role when needed.