Skip to main content

Keeper Security: Node & Edge Schema

This connection integrates privileged access and password management data into the SlashID identity graph from Keeper Security. It models users, teams, credentials, and their sharing/access relationships.


Node Types

Node TypeDescription
KeeperUserA standard user account in Keeper
KeeperPAMUserA privileged access (PAM) user in Keeper
KeeperTeamA team or group of users
KeeperRoleA Keeper-defined role
CredentialA stored password, secret, or credential
ApplicationAn application node (used for context or linking)
ResourceA Keeper-managed resource or vault entry

Edge Relationships

Edge TypeFrom NodeTo NodeDescription
IS_MEMBER_OFKeeperUserKeeperTeamIndicates user membership in a team
HAS_MEMBERKeeperTeamKeeperUserReverse of IS_MEMBER_OF
HAS_ROLEKeeperUserKeeperRoleAssociates user with a role
ASSIGNED_TOCredentialKeeperUser or TeamIndicates who owns or manages a credential
OWNSKeeperUserResourceUser owns the resource
IS_OWNED_BYResourceKeeperUserReverse of OWNS
HAS_CREDENTIALKeeperUserCredentialUser possesses a credential
IS_CREDENTIAL_OFCredentialKeeperUserReverse of HAS_CREDENTIAL
CAN_ACCESSKeeperUser or KeeperTeamResourceEntity is allowed access
CAN_BE_ACCESSEDResourceKeeperUser or KeeperTeamReverse of CAN_ACCESS
CAN_SHAREKeeperUserResourceUser can share this resource
CAN_BE_SHARED_BYResourceKeeperUserReverse of CAN_SHARE
CAN_WRITEKeeperUserResourceUser can write to resource
CAN_BE_WRITTEN_BYResourceKeeperUserReverse of CAN_WRITE

Examples

(KeeperUser)-[:IS_MEMBER_OF]->(KeeperTeam)
(KeeperUser)-[:HAS_ROLE]->(KeeperRole)
(KeeperUser)-[:HAS_CREDENTIAL]->(Credential)
(KeeperUser)-[:CAN_SHARE]->(Resource)
(Resource)-[:CAN_BE_WRITTEN_BY]->(KeeperUser)
OSZAR »