Identity governance has long focused on periodic reviews of who should have access to what. But those reviews happen on a schedule, and attackers do not wait for the next audit. As BleepingComputer reports, tenfold Software argues that this approach can leave a gap between reviews, allowing suspicious activity to go unnoticed until it is too late.
Real-time identity telemetry aims to close that gap. Instead of relying on snapshots of access rights, it continuously monitors how identities are actually being used. That lets security teams see anomalies as they occur, such as unusual login patterns or unexpected privilege changes, and investigate them before they turn into full-blown incidents.
The value is not in replacing identity governance but in complementing it. Periodic reviews still help define the right access posture, while real-time telemetry provides the ongoing visibility needed to catch threats in the moment. Together, they give security teams a clearer picture of both who should have access and what is happening with that access right now.