Capability guide

Identity-bound policy

Policies that follow the identity, not the network. Ixiea evaluates who someone is — and what they are allowed to do — at the gateway choke point on every session.

From network-centric to identity-centric

Firewalls answer whether a packet may arrive. Identity-bound policy answers whether this person may open this session to this target right now. Network location, VPN membership, and shared jump box accounts are poor proxies for intent. The IdP is the source of truth for subject attributes.

Attributes that drive decisions

Group membership, role assignments, employment type (employee vs contractor), MFA status, and login ACL rules (source IP, time window) feed RBAC checks at connect time. Attributes sync from Okta, Azure AD, LDAP, or SCIM-backed directories — users live in the IdP, permissions in core.

Eliminating shared accounts

Operators authenticate as themselves; the gateway maps to target accounts via secrets brokering. Session recordings show named individuals — not admin or root. Shared break-glass accounts, if retained, are time-boxed, approval-gated, and recorded at higher fidelity.

Lifecycle and revocation

When someone leaves or changes teams, IdP deprovisioning removes their grants on the next sync — no hunt for orphaned SSH keys on bastions. Vendor identities expire automatically when contracts end. Permission changes in core apply to new sessions; historical audit records retain the identity that was active at connect time.

Operational docs

Ready to deploy? Continue in documentation

Ready to evaluate?

See the platform on your architecture

Walk through gateway brokering, recording, and audit exports in a working session — or browse the illustrated product flow first.