> ## Documentation Index
>
> Fetch the complete documentation index at: https://lithi.ai/llms.txt
>
> Use this file to discover all available pages before exploring further.

## Someone is missing, duplicated, or holds the wrong role

Identity sync read your external directory and produced members and role grants in Lithi. The result does not match the team you expect.

Fix this at the source. A grant edited by hand will be overwritten the next time the mapping runs.

## Check the directory before the mapping

Your external directory is the authority for who exists. The approved mapping is the authority for what a directory attribute becomes here. Read them in that order.

- Is the person present, active and unique in the directory right now?
- Does the approved mapping cover the attribute their record actually carries?
- Has the sync run since their record last changed? The identity sync resource keeps its own events.

A person missing from the directory is a directory problem. No mapping change will conjure them.

## Then do this

- Duplicate or ambiguous records. Isolate the affected people rather than guessing which record is real. Pause the mapping for that group, resolve the duplicate in the directory, then resume and read back.
- Missing or wrong mapping. Plan the mapping change, have it approved, apply it, then read back the resulting grants. Do not assume the apply is the outcome.
- Wrong privilege. Review the grant itself, not the title behind it. An external job title is evidence about a person. It is never a grant.

Every privilege change deserves two explicit reviews: what the privilege reaches, and who owns the resource it reaches. Do both before you apply.

## What not to repeat

Never widen a role to make a sync error disappear. The error lives in the record or the mapping, and the widened role outlives both.

Never remove a member to clear a duplicate. Suspend or revoke instead, so the audit trail survives the fix and you can still explain it later.

## Get help safely

Send the identity sync resource identifier, the request ID, and the operation name. Add your client version, the contract release, the mapping state you observed, and the time.

Describe the affected people by role and count. Never send directory exports, payloads, key values, signed URLs, or banking information.

Read more about [directory and HR system sync](/docs/compute/access/scim-hris) and [scopes and roles](/docs/compute/access/scopes-and-roles).
