Group Membership Graph Analyzer

Group Membership Graph Analyzer

Review supplied groups, principals and memberships with cycle, nesting and evidence-path analysis.

Local export analysis only. Reachability is not live token membership, effective access or authorization. Unknown types, omitted objects, primary groups, dynamic rules, trust, filtering and provider policy can change actual membership. Scope checks cover only the selected declared AD native-mode subset. Heuristic thresholds are configurable review signals, not platform limits.

Supported import schemas and limits

JSON: an edge array of group/member records, or an object with nodes and edges arrays. Each node declares id and kind (group/principal/unknown), optional label, scope (global/universal/domain-local/unknown), domain, forest and boolean security. IDs, domains and forests compare exact text. Unrelated attributes are excluded from the normalized review.

CSV edge headers: group,member. Inventory headers: record,id,kind,group,member; record is node or edge. Optional metadata headers match JSON. Empty metadata cells mean unknown; security is true/false. LDIF imports content snapshots with DN IDs, objectClass types, groupType and forward member DN attributes. memberOf/memberUid/uniqueMember are excluded with warnings. DN pairing uses structural syntax, not directory matching rules.

Maximum 2,000,000 characters, 5,000 nodes including unresolved references, 25,000 membership occurrences, 30,000 CSV rows, 1,024 characters per identifier and 5,000,000 export characters. Invalid input blocks all analysis/export. Edge duplicates retain source occurrences on one edge.

Local membership dataPaste the declared JSON, CSV or LDIF schema
Waiting for explicit local analysis
Nodes0
Unique edges0
Cyclic components0
Finding groups0
Membership reviewRun a valid analysis to inspect and export findings
Waiting for input…