Reconciliation reports (for management)
Twan Duvigneau
The current Reconciliation report is not really a report, but more of an issues/incidents list. The important stakeholders in the governance process don't use this information, the want reports showing mismatch percentages, percentages of unmanaged permissions, trends, counts. They want to see that month over month improvements are being made to reduce the amount of unmanaged permissions, they want to see their governed entitlements increasing.
These reports are especially essential when you think about NIS2 and GDPR, they state that the responsibility of cybersecurity is placed at the organizations governing body, which means that we should be able to report to them with our Identity and Access Management governance status etc. The solution is currently build solely for IT, which is exactly what NIS2 is trying not to do.