NEWFreshservice is now a Ploy integrationSee what shipped

Identity security posture management

Identity security posture management (ISPM) is the continuous practice of finding and fixing identity-layer weaknesses (unused access, missing MFA, orphaned accounts, over-broad grants) before they are exploited.

Identity security posture management treats the identity layer the way vulnerability management treats software: as an attack surface with measurable weaknesses that should trend towards zero. Instead of CVEs, the findings are things like admin accounts without MFA, orphaned accounts that outlived their owner, grants nobody has used in months, and standing access that should be just-in-time.

Posture, not point-in-time

The word posture is doing real work. An access audit answers "were we compliant on the day we looked?". Posture management answers "what is exposed right now?", continuously, because the estate changes daily. A finding that is fixed and recurs is a process problem, and a posture tool should show that trend rather than a snapshot.

How it differs from IGA

Identity governance decides and proves who should have access; ISPM hunts for the states governance missed. The two feed each other: a posture finding ("47 identities hold an entitlement their segment does not") becomes a governance action (a policy, a revocation, a review). In Ploy the posture page names each gap as a segment with a count, and the job is to drive each count to zero.