Skip to content
Master Identity Index

Know exactly who's who, in every system, at any time

Aquera Master Identity Index (MII) is the authoritative, persistent record of every identity tied to your organization, human and non-human. It correlates identities across every system of record, links them into one durable golden record per entity, and writes that record into every system the enterprise operates. They provision from an authoritative source; MII is the authoritative source.

Trusted by 1,500+ Organizations Worldwide

Wingstop_logo Warby_Parker_logo Lucid_Motors_logo JD_Sports_logo Silicon_Valley_Bank_logo_(2018) Allbirds_logo Allergan_logo backblaze_92n7 Forbes_logo Aptiv_logo Casper_Sleep_logo.svg Opendoorlogo.svg squarespace-logo-horizontal-black IonQ_corp_logo.svg Lindt-Logo images FIGS_Inc_Logo E.l.f.-Logo everlane-logo-vector images (1) 656661c5e4f9dbb18f4bd724_Matterport Myfitnesspal-Logo-Vector.svg- StoneX_Group_Inc_official_2023_logo.svg kisspng-keller-williams-realty-lake-charles-clarks-summit-5b08ba53863a91.8378231615272986435498 Bupa_logo.svg wwf_logo_large_rgb_72dpi_1_1_1_1_783732 b5586b9a-1c73-46ad-bccf-09ab444e2def-1
What It Delivers

One identity of record for the enterprise

One record
one golden record per person, no duplicates, no orphans, in any system
Upstream
identity resolved once, before every downstream tool touches it
Forever
temporal records survive departure and re-match on return, even after 18 months
The Gap

Every system re-derives who is who

Five or more systems each claim authority over people data, and nobody owns the person. Every downstream tool re-correlates independently, producing duplicates, joiner delays, lingering leaver access, and audit archaeology.

Without an identity of record
Day-one access waits. No system can confirm who the new hire is before HR provisioning fires, joiners are delayed.
Duplicates and orphans multiply. A returner looks like a brand-new person; service accounts outlive their owners.
Audit history is archaeology. Identity history must be reconstructed from logs across a dozen tools.
With Master Identity Index
Identity resolved once, upstream. One golden record per person, every IGA and IdP inherits the anchor ID.
Returners re-match automatically. New records match back to the same anchor ID, history intact.
Audits become retrieval. Every identity change is durable, timestamped, queryable history.
Go Deeper

Master Identity Index Solution Brief

Golden record architecture, anchor ID, temporal history, serve paths, and the full comparison table, learn more now.

Download the datasheet
How It Works

From raw source records to one identity of record

MII loads every source raw, resolves one golden record per entity with MDM-grade matching and survivorship, then writes the anchor-keyed result into every system the enterprise operates, so downstream tools inherit a solved identity, not another correlation project.

1 SOURCE

Load every source raw, full fidelity

Every identity source lands in staging exactly as provided, and profiling runs first to define match keys, field weights, and quality thresholds.

  • Raw-first pipeline. No edge transforms, source data preserved for audit and replay.
  • Profiling-defined config. Match keys and thresholds derived from measured data quality.
  • Multi-source ingestion. HCM, ATS, VMS, partner SoR, ITSM, databases, and files.
2 RESOLVE

Resolve one golden record per entity

Blocking plus hybrid scoring resolves records into one anchor-keyed golden record, with confidence gates automating high-confidence matches and steward review handling borderline cases.

  • Three-layer matching. Blocking + hybrid scoring, one golden record per person.
  • Confidence gates. Auto-resolve at 0.85+; steward review 0.65-0.84.
  • Temporal identity. Every change kept as durable history, nothing overwritten.
3 SERVE

Write the anchor ID into every target

The resolved golden record publishes to Active Directory, Entra ID, Okta, SailPoint, Saviynt, and databases over SCIM, XaaS push, Graph, and LDAP, anchor ID stamped in every target.

  • Four serve paths. SCIM, XaaS push, Microsoft Graph, and LDAP.
  • Universal anchor. One deterministic key the whole estate inherits.
  • Leavers as status changes. History preserved, re-matching works on return.
Core Product Capabilities

One master identity record. One anchor ID. Written into every system

Cross-Source Correlation

Resolves and links identities across HCM, ATS, contractor, partner, and directory systems into one record per entity.

Single Best Record

Profile, standardize, match, survivorship. MDM discipline producing one anchor-keyed golden record per person.

Temporal Identity

Records survive departure and re-match on return. Identity is a timeline, not a row.

Relationship Graph

People, service accounts, and agents modeled as connected entities with sponsorship, ownership, and delegation edges.

Reversible Link & Unlink

Bad matches unlink and re-resolve without losing history; new evidence triggers automatic re-linking.

Non-Human Identities

First-class service accounts and agent identities, each tied to an accountable human owner and governed over time.

What Makes It Different

MDM discipline, applied upstream to identity

The Write Path

MII doesn't just read fragmented identity, it resolves it once and writes the golden record into every target, so downstream tools inherit a fact, not a project.

Anchor ID Everywhere

One persistent identifier stamped into Active Directory, Entra ID, Okta, SailPoint, and Saviynt, per-tool correlation guesswork replaced by one shared key.

Identity Is a Timeline

Every attribute, link, and status change is durable history. Returners re-match automatically; auditors query history instead of reconstructing it from logs.

Let's Talk

See Master Identity Index in Action

A 30-minute working session mapped to your identity sources, scoped to what you actually run.

Request a Demo
Graphic placeholder: One person as each source sees her, linked to one anchor ID
Many Sources, One Person

Each source owns a slice. Nobody owns the person

MII loads every source raw and resolves one golden record per entity. Fragmentation is structural, not a hygiene failure that can be cleaned up once.

Where the Multi-Source Problem Lives

Any organization where no single system of record owns the person

Higher Education

Students, staff, applicants, alumni, and adjuncts across the SIS and the HCM.

Healthcare Systems

Employees, physicians, nurses, and volunteers across HR, credentialing, and VMS.

Government & Public Sector

Many agency HR systems, and one resident identity for citizen services.

Retail & Hospitality

Corporate versus franchise payroll, seasonal rehires, and high turnover.

Financial Services

Parallel HCMs from M&A, plus non-employee agents and brokers.

Manufacturing & Energy

Contingent workforces in a VMS alongside employees, resolved to one record.

Inside the Suite

Measure first, configure from the measurement

Master records written into: Active Directory  ·  Entra ID  ·  Okta  ·  SailPoint  ·  Saviynt  ·  Databases  ·  Other IdPs and IGAs

1

Raw-First Pipeline

Everything lands raw, full fidelity for audit, lineage, and replay.

2

Profiling-Defined Config

Profiling runs first. Match keys and thresholds are versioned configuration.

3

Three-Layer Matching

Blocking plus hybrid scoring. One golden record, with per-field lineage.

4

Confidence Gates

Auto-resolve at 0.85 and above; steward review 0.65 to 0.84; decline below the band.

5

Governed Access

Persona RBAC on every call. Federation rules hold on write and on read.

6

Four Serve Paths

SCIM Profile API, XaaS push, Graph /bulkUpload, and multi-application provisioning.

The Shift

From N sources, N truths, to one identity of record

Manual, fragmented identity estate
Aquera Master Identity Index
Enterprise MDM has the discipline, but skipped workforce and partner identity
Mastering discipline. MDM-grade matching, survivorship, and lineage applied to identity
Views at query time, they never create the record they anchor on
The write path. Resolves identity once, upstream, then writes the result into every system
IGA platforms and IdPs correlate identities to account access, per tool, forever
Identity correlation. One deterministic anchor key the whole estate shares
History reconstructed from logs across a dozen tools
Temporal history. Every identity, link, and status change is durable history
A returner looks like a brand-new person
Rehires and returners. Re-matched to the same anchor ID, history intact
Deprovisioning deletes or orphans the identity
Leaver handling. A status change, never a deletion, so history remains
Service accounts go orphaned when their owners leave
Non-human identities. First-class identities tied to an accountable human owner
They provision from an authoritative source they are given
IGA and IdP feed. MII is the source; SailPoint, Saviynt, Okta, and Entra consume it as trusted source

Frequently asked questions

What is the Aquera Master Identity Index (MII)? +

The authoritative, persistent record of every identity tied to an organization, human and non-human, across time. MII correlates identities across every system of record, links them into one durable golden record per entity, assigns each entity a persistent anchor ID, and writes the resolved identity into every system the enterprise operates.

What is the write path and why does it matter? +

The write path is the ability to push resolved identity into the systems the enterprise operates, rather than just reading and displaying identity data. Writing the resolved record, with its anchor ID, into every target converts identity from a recurring per-tool project into a solved upstream input.

What problem does the Master Identity Index solve? +

MII solves identity fragmentation. In most enterprises, five or more systems each claim authority over people data, but nobody owns the person, so every tool re-derives who is who on its own, producing joiner delays, lingering leaver access, duplicate identities, and audit archaeology.

What is a golden record in identity management? +

A golden record is the single best version of an identity, assembled from every source system that holds a piece of it. In MII, the golden record is anchor-keyed and temporal, and every field is traceable to the source and rule that selected it.

What is the anchor ID? +

A single persistent, universal identifier that MII assigns to each entity and stamps into a stable attribute in every connected system, converting identity correlation from per-tool guesswork into one deterministic key the whole estate shares.

How does identity matching work in MII? +

MII uses blocking plus hybrid scoring to resolve source records into one golden record per person. High-confidence matches resolve automatically at 0.85 and above; borderline scores from 0.65 to 0.84 route to a steward review queue.

How does MII handle rehires and returning workers? +

The new source record is matched back to their existing anchor ID, with full history intact, even after a gap of months or years. Returner re-matching is automatic.

How does MII handle leavers? +

A leaver is a status change, never a deletion. Access is revoked downstream and licenses reclaimed, but the identity and its complete history remain in the index.

Does MII manage non-human identities such as service accounts and AI agents? +

Yes. Service accounts and AI agent identities are first-class entities in MII, each tied to an accountable human owner and governed over time.

Where does MII publish the golden record? +

Active Directory, Microsoft Entra ID, Okta, SailPoint, Saviynt, databases, and other IdPs and IGAs, over four protocol paths: SCIM, XaaS push, Microsoft Graph, and LDAP.

How is MII different from IGA platforms like SailPoint, Saviynt, Okta, or Entra ID? +

MII is complementary: IGA platforms and IdPs correlate identities to account access within their own tool, from the feeds they are given, on every aggregation. MII does the correlation once, upstream, and hands every IGA and IdP a pre-resolved identity with a deterministic anchor key.

How does MII help with audits? +

MII turns audit archaeology into retrieval. Every identity, attribute, link, and status change is durable, timestamped history, and every operation lands in a full-text-searchable audit trail.

What compliance frameworks does MII support? +

MII is built for scrutiny under SOC 2, SOX, ISO 27001, GDPR, and HIPAA, with durable identity history, per-field lineage, reversible merges, and a searchable audit trail.

Which industries need a master identity index? +

Any organization where no single system of record owns the person: higher education, healthcare systems, government and public sector, financial services, retail and hospitality, and manufacturing with contingent workforces.