HumanIdentities Object
Relationships
graph LR
HumanIdentities -->|"account"| Accounts
Properties
Truto's stable unified identifier for this object. Opaque; use provider_id to address the object in the provider's own console or API.
The administrative roles or policies behind is_admin, as provider references.
When Truto read this object from the provider, in UTC ISO 8601 with offset. Not the request time, and not a provider-supplied timestamp.
When the identity was created.
The person's display name. Null for AWS IAM users (they have no display name, only a user name and path), flagged not_supported_by_provider.
Email address or user principal name. AWS IAM users have no email attribute in the API, so this is null there unless the customer set it as a tag.
Whether the identity can currently sign in. Read directly for Identity Center users; for AWS IAM users it is derived from having no login profile and no active access keys, and flagged as derived.
Group references for this identity.
Whether the identity has interactive sign-in, distinct from programmatic-only access. On AWS derived from a 404 on GetLoginProfile; null on the Identity Center path (IAM-only concept).
Whether the identity holds long-lived credentials. An IAM-only concept on AWS; null on the Identity Center path.
The provider's own identifier for the identity.
Which identity store this row came from. On AWS, IAM users and Identity Center users share no identifiers and populate different subsets of fields.
Whether this is a person, a service account, or an external guest.
humanserviceguestexternalunknown
Whether this identity holds administrative privilege. Derived from attached permissions, since no provider exposes an admin flag directly.
Last interactive console sign-in. On AWS, console-only, at five-minute granularity, with no tracking before 2014-10-20 and a gap in 2018; not available for Identity Center. Null forever for programmatic-only users -- do not read as 'never signed in'.
Number of MFA devices registered to this identity.
The registered MFA method types. On AWS these are inferred from the device serial number shape (not returned by the API) and marked derived; FIDO and TOTP cannot always be distinguished.
Whether this specific user has MFA registered (per user, not per account). Null with not_supported_by_provider for AWS Identity Center, which exposes no such field.
The provider's own type string, unmodified -- for example 'AWS::S3::Bucket', 'aws_iam_role', 'Microsoft.Sql/servers'. Used for display and drill-down.
Which cloud this object was read from.
awsazuregcp
The provider's own identifier, verbatim -- a full ARN, resource id, or self-link. Never truncated or normalised. Use it to find the object in the provider's console.
Where the object is located. 'global' marks resources with no region (e.g. IAM, a GCP VPC network). If the provider gives none, the collector's queried region is used instead and flagged in unreadable_fields.
Raw data returned from the remote API call.
Key-value pairs exactly as the customer set them -- no case folding, key/value normalisation, or merging across providers. An empty object means no tags; unreadable tags appear in unreadable_fields instead.
Fields on this object that could not be read, and why. An empty array means everything was read. Use this to tell a real value from a missing one.
Additional detail on the reason, when there is any.
The property on this resource that could not be read.
Why the field could not be read. available_on_get: Not read on list to keep the list fast; call GET for this resource's id to get it.
not_supported_by_providernot_configuredpermission_deniednot_collectedcollection_errorpartially_collectedavailable_on_get
When the object was last modified at the provider, in UTC ISO 8601. Null when the provider does not record one - see unreadable_fields.