How external insights work
When you configure an external insights source, ConductorOne syncs risk data from that tool through its connector. ConductorOne matches each risk score to an identity in your directory by email address and attaches it to that identity’s profile and any accounts they hold in other connected apps. Once synced, risk scores appear in the ConductorOne UI wherever that identity appears in an access decision.Enable or disable external insights
External insights are enabled automatically when a connector that is a supported external insight source is configured and syncing. No additional setup is required. If needed, you can manually turn risk score syncing on or off from the connector’s settings page in ConductorOne:Where external insights appear
Access review campaigns Reviewers see an identity’s risk score and risk factors on each review task, under the Insights tab. Risk factors are the specific reasons the source tool assigned that score — for example,STALE_ACCOUNT or WEAK_PASSWORD_POLICY. Reviewers can use this context to prioritize high-risk identities and make more informed certify or revoke decisions.
Task log
The task log includes an Insights column. Hovering over the insights indicator for a task shows a summary of the identity’s risk score and risk factors inline, with a link to view the full details.
Access request approvals
Approvers can see an identity’s current risk score and risk factors in a request task before submitting their decision.
Supported external insights sources
CrowdStrike Falcon Identity Protection
Ingest Falcon identity risk scores into ConductorOne.
Wiz Insights
Ingest Wiz identity risk scores into ConductorOne.