Resources center
Glossary
E
What is externalized authorization?
Externalized authorization is access control decisions centralized and separated from application logic. In other words, it centralizes access control decisions for applications and systems across the organization, rather than within individual programs. This means the access logic and policies are consistent, regardless of the application. It’s like having a central security office that decides who can enter which rooms in all buildings of a company, instead of each building managing its own security. Such centralized management allows security and IAM professionals to efficiently add, update and deploy policies across a portfolio of applications, alongside fine-grained access control which ensures users access the right data and actions. When combined with a dynamic data model, it allows businesses to leverage other data, make faster decisions based on dynamic data points and orchestrate a consistent experience across services (with all systems using the same externalized authorization).
Learn more here.
Or check out this webinar.
F
What is fine-grained access control?
Fine-grained access control allows for more precise management of access permissions, and grants or denies access based on multiple factors. This method provides precise control over who can access what data or functionalities, and becomes particularly important when dealing with access to specific data or in complex circumstances - where you might have more than one account. Imagine a library where access to each section and book is individually controlled. Some books may only be available to specific membership types, and users may need different permissions to borrow books or access special collections.
Learn more here.
F
What is first-party data?
First party data refers to information directly collected by a company from its customers or users. It is typically obtained through interactions, transactions, or engagement with the company's own platforms, products, or services. First-party data includes information from sources like your customer relationship management (CRM) system.
F
What is fragmented data?
Fragmented data refers to data that is scattered across multiple sources or systems in a disorganized manner, making it difficult to access, analyze and use. A company may use different systems for sales, inventory, CRM, marketing, etc. Without this data unified, it can be difficult to get a complete picture, leading to poor decision making and unsatisfied customers.
G
What is graph-based access control?
Graph-based access control is a security model that uses graph technology - where nodes represent entities (like users, roles, or resources) while edges represent relationships - to manage and enforce access decisions. By analyzing these relationships, the system can determine whether a user should be granted access based on context, connections, and permissions.
Why it matters: Graph-based access enables more accurate, context-rich decisions, improving both security and flexibility in complex environments.
G
What is graph data?
Graph data is information organized as nodes and edges, where nodes represent entities (people, accounts, devices) and edges represent relationships (ownership, interaction, dependency). Both nodes and edges can carry attributes, allowing the data to include context alongside values. This structure makes relationships explicit and queryable, enabling enterprises to see dependencies, patterns, and connections that traditional tabular data cannot capture.
G
What is graph data modeling?
Graph data modeling is the process of structuring data as a graph, where entities are represented as nodes and their relationships as edges with attributes. This approach carries context with the data, supports flexibility as business requirements evolve, and enables visibility across connected domains, forming a foundation for analysis, governance, and operational use.
G
What is graph integration?
Graph integration is the use of a graph model as a shared layer to connect data from multiple systems while preserving the relationships between entities. Rather than moving isolated records, applications operate on a connected structure that reflects how systems, customers, and processes interact. This approach improves consistency, adaptability, and context-rich insights across enterprise applications, while embedding governance and reducing duplication or conflicts.
Why it matters: Integrating data through a graph model preserves context, reduces duplication, and supports faster, more accurate insights across systems.
G
What is a graph model?
A graph model is a way of structuring data (using a graph database) that represents entities as nodes and the relationships between them as edges. It captures not just values but the connections and dependencies among entities, allowing enterprises to see complex systems, follow chains of interaction, and understand how elements such as customers, accounts, transactions, and products relate to one another.
Why it matters: Understanding and using graph models enables organizations to uncover hidden relationships, maintain context across systems, and make better-informed decisions.
I
What is an identity knowledge graph?
An identity knowledge graph, is a real-world network of both person and non-person entities and the relationship between them. The graph captures all identifiers related to an entity, including dynamic attributes such as location, and stores this for each data node, along with capturing what the relationship is between entities which provides ‘context’. An identity knowledge graph can be used to unify data across an organization, applications and channels. The end result is a holistic, connected view of your customers, partners, entities that you can leverage for analytics, AI, access and insights.
Why it matters: A unified, contextual view of identities improves decision-making, personalization, and secure access control.
Discover IndyKite Identity Knowledge graph
I
What are identity silos?
Identity silos refer to isolated and fragmented systems of user identity information which is stored separately in different applications or departments, making it difficult to unify and manage user identities across an organization. Picture having different lockers for all your belongings at the gym, office, and home, making it difficult to get access to everything at once.
I
What is Intent Based Access Control?
Intent-based access control is an approach to governing how data is used by applications and AI systems, based on the purpose and context of each request.
As AI agents interpret data, make decisions, and trigger actions across systems, access control must extend beyond identity and permissions to evaluate intent. This includes understanding why data is being requested, how it will be used, and whether that use aligns with policies, consent, and operational constraints.
Each request is evaluated in real time against a combination of signals such as relationships, provenance, sensitivity, trust, and execution context. This ensures that AI-driven actions are grounded in data that is appropriate for the task, under the conditions in which it is being used.
In practice, intent-based access control operates at the point of data retrieval and action, continuously assessing whether an AI system or application should be allowed to proceed. It provides traceability into what was requested, how intent was interpreted, and why a decision was made, enabling accountable and policy-aligned execution.
With IndyKite, intent-based access control is delivered through a context-driven control layer that governs how data is retrieved, interpreted, and acted on at runtime. It ensures that AI systems operate with precision, using data in ways that are consistent with enterprise policies, contextual constraints, and trust requirements.



