Skip to main content
AI activity can appear under a work email, personal account, device, provider identity, or agent. Oximy connects those identifiers to consistent people, agents, applications, and groups.

Workspace boundary

A workspace contains your company’s data, settings, integrations, policies, and product access.

People and organization

People can be associated with departments, managers, devices, accounts, and observed activity. Organization structure supports department reporting and, where configured, manager-scoped visibility.

Identity resolution

Oximy considers where each identifier came from and how reliable the match is. Administrator and provider information takes precedence over lower-confidence automated matches. Unresolved activity is retained as unattributed rather than discarded. An administrator can review identity proposals, map a device or account to the correct person, or explicitly leave an alias unattributed.

Account classification

Visibility can distinguish organization-managed accounts from personal or shared accounts when the available signals support that attribution. This helps separate official adoption from shadow usage and credential-sharing risk.

Agents and service identities

Agent activity is not attributed to a person solely because it used that person’s account or device. Oximy represents agents and service accounts separately when the source provides enough information.

Device enrollment

Device enrollment uses the same identity model. A device can be bound through self-enrollment, an imported roster, an identity provider, MDM-supplied information, or an administrator decision. MDM is one signal, not a requirement for attribution.

Access controls

Give people only the product and administrative access they need. The available controls depend on your identity provider, products, roles, and deployment. Before rollout, decide:
  • Who administers the workspace.
  • Which teams can view organization-wide or department-level data.
  • Who can manage integrations, provider keys, routing, and policies.
  • Which actions require approval.
  • How access is removed when a person changes role or leaves.
Configure SSO, directory sync, roles, and offboarding for the way your organization manages access.
Connecting activity to a person or agent does not grant access to that data. Roles and access policies separately determine who may view data or perform an action.