Skip to content

Risk and identity

Prioritize exposure with asset and access context.

Connect security signals, identities, permissions, activity, and ownership for review.

Move from isolated findings to a bounded investigation while keeping Microsoft security and identity systems as the authoritative sources.

  • Finding context
  • Identity visibility
  • Activity review
  • Owned remediation
https://swavesglobal.com/lineage/risk-and-identity
Lineage Threat Intelligence risk review workspace

Lineage provides operational context for risk and identity review. It is not a substitute for Defender, Entra, a SIEM, a CNAPP, or a formal compliance assessment, and it does not certify an environment.

Threat Intelligence

Implemented capability

Review severity in the context of the affected estate.

Threat Intelligence organizes available risk signals around resources and review scope. Operators can assess what is affected, what related evidence exists, and who should validate the next step.

  • Finding and resource context
  • Review-oriented filtering and prioritization
  • Paths into ownership and reporting
https://swavesglobal.com/lineage/app/risk-prioritization
Threat Intelligence screen with Azure risk findings

Access review

Implemented capability

See identities and permissions alongside operational evidence.

Identity views bring available users, groups, service principals, role assignments, and related signals into the review workspace. Effective access can be complex, so operators should validate conclusions against Entra and Azure RBAC.

https://swavesglobal.com/lineage/app/identity-context
Lineage identity overview of Azure principals and access

Principals

Review synchronized user, group, and workload identity context.

Assignments

Inspect available role and scope information.

Activity

Compare identity context with recorded operations where available.

Who or what acted

Implemented capability

Use activity records to test an access or change question.

Activity Feed helps reviewers inspect operations, outcomes, and available actor context. It can support an investigation, but missing or expired source telemetry cannot be reconstructed by the product.

  • Actor and operation context where supplied
  • Success and failure signals
  • Time-bounded review alongside estate history
https://swavesglobal.com/lineage/app/activity-evidence
Azure activity evidence in Lineage Activity Feed

Advisor evidence

Implemented capability

Relate recommendations to the resource and its operating history.

Advisor and related findings can be reviewed with resource, cost, and ownership context. This helps teams decide what warrants validation first rather than treating every recommendation as an automatic action.

https://swavesglobal.com/lineage/app/recommendation-context
Lineage Advisor recommendations with resource context

Signal

Review the recommendation and its source category.

Context

Check affected resources, history, cost, and ownership.

Disposition

Assign, defer, accept, or document follow-up through the operating workflow.

Controlled follow-up

Implemented capability

Keep the security decision visible after triage.

Action Center supports ownership, priority, status, and notes for validated findings. Where a write-class path is configured, separate identity, permission, policy, approval, execution, and audit controls apply.

  1. 01

    Assign

    Route validated follow-up to a named owner.

  2. 02

    Review

    Record priority, status, and the decision rationale.

  3. 03

    Control

    Keep approved execution separate from analysis.

Service and advisory

Service and advisory

Use the workspace within a defined security review.

Swaves can help scope evidence, facilitate review, and document remediation ownership. Penetration testing, formal compliance assessment, incident response authority, and managed detection are separate services and are not implied by this product page.

  • Define scope and authoritative evidence sources
  • Validate identity and risk conclusions with accountable specialists
  • Document gaps, decisions, and remediation owners

Evaluate Lineage

Frame one risk or access review.

Bring the affected scope and authoritative source signals; use Lineage to test whether context and ownership improve the outcome.

Start the review