Glossary
This is the authoritative list of customer-facing terms. If you see a word in the documentation, it should be here. If you write a new page and need a term that isn't here, add it first.
This is a reference page. There's no screen to show.
Attack path
A detected chain of identity relationships that lets an account reach a crown jewel. Identity X-Ray shows only paths supported by collected evidence.
Cloud Security Posture Management (CSPM)
The module that ingests findings from your connected cloud accounts (AWS, Azure, GCP, Cloudflare, OCI) and surfaces misconfigurations against best-practice baselines.
Compliance Hub
The module that maps findings to industry frameworks (CIS, NIST CSF, MITRE ATT&CK) so you can see your posture from a compliance perspective.
Crown jewel
A sensitive group, role, account, or other identity target whose control would have a high operational or security impact. Identity X-Ray includes built-in Tier 0 targets and your Privileged Zones.
Blast Radius
The collected FortiGate policy and group references that could be affected by changing or removing an address or service object. It does not include dependencies outside the saved firewall snapshot.
Collection confidence
The trust state attached to a modeled result. Collected means supporting configuration was captured, Modeled means Retrievy calculated a result from that snapshot, and Incomplete means required evidence was missing, stale, unsupported, or not evaluated.
Cross-policy anomaly
A provable relationship between ordered FortiGate rules, such as shadowing, partial overlap, redundancy, generalization, or a merge opportunity.
Data source
Any system Retrievy ingests from: a cloud account, an Active Directory tenant, a FortiGate firewall, or a Windows server agent.
Drift alert
A notification triggered when a configuration in a monitored system (Active Directory, FortiGate) changes between snapshots.
Retrievy Index
Retrievy's unified risk score across your entire environment. Calculated from severity-weighted findings across every module.
Finding
A specific security issue detected in your environment, for example an unencrypted S3 bucket, a privileged user without MFA, or a permissive firewall rule.
GPO X-Ray
The Active Directory investigation workspace for effective policy, GPO inventory, policy changes, and cleanup observations from collected Group Policy snapshots.
GPO Library
The policy-first inventory in GPO X-Ray. It shows each GPO's status, links, collected registry settings, modeled contribution, estimated scope, confidence, and observed versions.
Identity Security Posture Management (ISPM)
The module that surfaces identity risks across your connected directory and cloud identity sources: stale users, privilege sprawl, weak MFA, and dormant accounts.
Identity X-Ray
The ISPM investigation workspace for identity exposure, detected attack paths, authentication gaps, privileged access, and customer-defined crown jewels.
Kanban Triage
The board where findings move through states: open → pending verification → resolved / risk accepted.
Remediation project
A grouped collection of findings with an owner, a deadline, and a generated PDF report.
Privileged Zone
A customer-defined set of sensitive Active Directory groups or accounts that Identity X-Ray treats as crown jewels alongside built-in Tier 0.
Policy Simulator
The read-only FortiGate workspace that estimates which saved IPv4 policy would handle a proposed flow and explains uncertainty when configuration alone cannot prove the decision.
Risk acceptance
Formally marking a finding as accepted risk rather than fixing it. Requires an approver per your workspace's approval chain.
Scan
The act of ingesting data from a data source. Cloud scans are typically scheduled; agent scans run on a timer.
Security Configuration Management (SCM)
The module that analyzes Active Directory Group Policy Objects (GPO X-Ray) and FortiGate policy rules (Policy X-Ray with Domino Effect visualization).
Security exception
A formal record of a risk you have accepted, tracked in the register with an approver and an expiry date.
Shadow Admin
An identity that is not nominally privileged but still has a detected relationship path to a crown jewel.
Tier 0
The built-in identity targets whose control can confer broad authority over the directory or identity environment.
Tenant / Workspace
Your organization's isolated Retrievy environment. Accessed at <your-workspace>.retrievy.com.
Windows Agent
The MSI-installed service that snapshots your on-prem Active Directory and GPO state and ships it to Retrievy.