Compute Help
Identity sync mapped the wrong person
Identity sync created a duplicate, missed someone, or granted the wrong role? Check the external directory and the approved mapping, then isolate ambiguous people before changing a grant.
A member is missing, duplicated, or arrived with a role you did not intend.
Someone is missing, duplicated, or holds the wrong role
Identity sync read your external directory and produced members and role grants in Lithi. The result does not match the team you expect.
Fix this at the source. A grant edited by hand will be overwritten the next time the mapping runs.
Check the directory before the mapping
Your external directory is the authority for who exists. The approved mapping is the authority for what a directory attribute becomes here. Read them in that order.
- Is the person present, active and unique in the directory right now?
- Does the approved mapping cover the attribute their record actually carries?
- Has the sync run since their record last changed? The identity sync resource keeps its own events.
A person missing from the directory is a directory problem. No mapping change will conjure them.
Then do this
- Duplicate or ambiguous records. Isolate the affected people rather than guessing which record is real. Pause the mapping for that group, resolve the duplicate in the directory, then resume and read back.
- Missing or wrong mapping. Plan the mapping change, have it approved, apply it, then read back the resulting grants. Do not assume the apply is the outcome.
- Wrong privilege. Review the grant itself, not the title behind it. An external job title is evidence about a person. It is never a grant.
Every privilege change deserves two explicit reviews: what the privilege reaches, and who owns the resource it reaches. Do both before you apply.
What not to repeat
Never widen a role to make a sync error disappear. The error lives in the record or the mapping, and the widened role outlives both.
Never remove a member to clear a duplicate. Suspend or revoke instead, so the audit trail survives the fix and you can still explain it later.
Get help safely
Send the identity sync resource identifier, the request ID, and the operation name. Add your client version, the contract release, the mapping state you observed, and the time.
Describe the affected people by role and count. Never send directory exports, payloads, key values, signed URLs, or banking information.
Read more about directory and HR system sync and scopes and roles.
Still blocked?
Open the related help article or contact Lithi.