TL;DR: Investigations break less from missing data than from missing field-to-field context, according to Crogl, and its knowledge graph is designed to persist the pivots analysts normally keep in their heads. The operational implication is broader than search: cross-system investigation becomes a governance problem about identity correlation, evidence, and trust, not just a tooling problem.
NHIMG editorial — based on content published by Crogl: The Right Pivot, at the Right Moment: Crogl's Knowledge Graph
By the numbers:
- Only 5.7% of organisations have full visibility into their service accounts.
- NHIs outnumber human identities by 25x to 50x in modern enterprises.
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools.
Questions worth separating out
Q: How should security teams reduce manual pivoting across identity and security tools?
A: They should standardise authoritative identity fields, document cross-system synonyms, and require investigation tooling to preserve the evidence behind each learned mapping.
Q: Why does cross-system identity correlation fail in practice?
A: It usually fails because the same person or asset is represented differently in each platform, and teams rely on human memory to bridge the gaps.
Q: How do teams know whether a knowledge graph is actually improving investigations?
A: Look for shorter time to the next relevant source, fewer dead-end queries, and more consistent investigation paths across analysts.
Practitioner guidance
- Map authoritative identity fields before automating pivots Document which systems own user, account, device, and asset identifiers, then define the canonical field names and acceptable synonyms used across connectors.
- Require evidence for every learned relationship Insist that any automated mapping between fields retains representative samples, validation logic, and an audit trail.
- Test the graph against live investigations, not clean demos Use real tickets, identity records, endpoint telemetry, and cloud events to see whether the system can move from one relevant source to the next without manual rediscovery.
What's in the full article
Crogl's full blog covers the operational detail this post intentionally leaves for the source:
- How the connector-based learning cycle validates field relationships before they become reusable investigation context.
- How Crogl handles representative samples, evidence retention, and auditable relationship history in customer environments.
- How the graph behaves in lake-first, source-first, on-premises, private-cloud, and air-gapped deployments.
- How investigators can run a live investigation to see which pivots the graph surfaces in practice.
👉 Read Crogl's analysis of knowledge graph pivots for security investigations →
Knowledge graph pivots in investigations: what changes for analysts?
Explore further
Identity correlation is now a governance control, not just an analytics convenience. When analysts cannot reliably connect the same identity across identity providers, ticketing, endpoint, cloud, and security tools, they lose investigative continuity. That turns schema ownership, field mapping, and auditability into first-class identity controls. Practitioners should treat cross-system identity resolution as part of the identity programme, not as an informal SOC workaround.
A few things that frame the scale:
- NHIs outnumber human identities by 25x to 50x in modern enterprises, according to the Ultimate Guide to NHIs.
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them.
A question worth separating out:
Q: What is the difference between a search layer and an investigation graph?
A: A search layer helps you find records, while an investigation graph helps you understand which identity or system to query next and why. The graph becomes valuable when it preserves relationship evidence and supports the analyst's reasoning, not when it simply returns more results.
👉 Read our full editorial: Crogl’s knowledge graph turns identity pivots into operational memory