Skip to main content

Link accounts to personnel in Drata (New Experience)

Learn how to link accounts to personnel in Drata, handle service and system accounts and mark accounts out of scope.

Updated over a month ago

New Experience
This article applies to the New Experience.

Overview

When accounts are first synced into Drata, they may not be automatically linked to personnel. Linking accounts to personnel helps Drata:

  • Understand who has access to systems

  • Accurately evaluate access-related compliance requirements

  • Maintain a clear audit trail

  • Reduce audit follow-up questions

Prerequisite

  • Personnel are synced into Drata from your identity provider. If no identity provider is connected:

    • The Personnel dropdown may not have options to select from.

How to link an account to personnel

For accounts that represent access held by an individual employee:

  1. From the Connections page, open the relevant Manage accounts page.

    Showcases Infrastructure page under Manage accounts after you select Connections page.

    This example shows the Infrastructure page, but the same actions are available across all account management pages.

  2. Locate the account you want to link.

  3. In the Personnel column, select the appropriate employee.

Once linked, the account is associated with that person. If ownership changes later, you can select the ellipse to unlink the account and relink it to a different employee.

Handling service and non-human accounts

Not all accounts belong to a specific individual. Common examples include:

  • Service accounts

  • Automation users

  • System-generated identities

These accounts should not be linked to personnel. Instead, they can be marked out of scope with a documented business rationale.

How to mark an account out of scope

  1. Open the relevant Manage accounts page.

  2. For the desired account, select the ellipse > Mark out of scope.

    Displays where the ellipse is located in order to select Mark out of scope
  3. Provide a brief rationale explaining why the account does not represent individual access.

Once an account is marked out of scope:

  • It cannot be linked to personnel

  • The rationale remains visible for audit purposes

  • You can view the rationale or mark the account back in scope from the same ellipsis (⋯) menu

Did this answer your question?