Skip to content

People directory

Part of the Environment & People dashboard.

Your people are part of your attack surface. This section builds a directory of everyone in your organisation, then surfaces the risks tied to them — who lacks multi‑factor authentication (MFA), who has turned up in a known data breach, and how identity risk is trending.

There are three ways to populate the People Directory, and you can mix them:

Section titled “1. Sync from Microsoft 365 or Google Workspace (recommended)”

If you use Microsoft 365 or Google Workspace, connect one once and your directory fills itself:

  1. Go to Environment & People → People directory (or Settings → Integrations, depending on your build).
  2. Choose Connect Microsoft 365 or Connect Google Workspace and approve the read‑only access when prompted.
  3. Your staff sync across automatically, bringing MFA status, department, and device data with them.

The sync is genuine directory data, so it stays closer to reality than a spreadsheet and refreshes as your organisation changes. Both connectors work the same way and cover the same ground — pick whichever is your organisation’s identity provider.

A populated People Directory with Connect M365, Connect Workspace and Import CSV buttons, summary cards for MFA enabled, high risk and no MFA, and a table showing each person’s role, MFA state, type, devices and risk.

No Microsoft 365 or Google Workspace, or want to bring in contractors and others alongside a sync? Use the built‑in Import Wizard — a consistent 4‑step flow used across the platform:

  1. Upload your CSV.
  2. Map your columns to 786 Cyber fields (name, email, department, manager, and more).
  3. Validate — the wizard checks every row and flags problems before anything is saved.
  4. Import — commit the rows.

This isn’t just a bulk-upload box. The wizard is built for exactly the messy exports real organisations have: departments named inconsistently across systems are auto‑created and fuzzy‑matched, so “IT” and “I.T.” land in the same department instead of quietly forking your org structure into two. Validation catches problems — missing required fields, malformed emails, unmapped columns — before a single row is saved, not after. And because every import can be rolled back for 24 hours with one click, importing a large or unfamiliar file is never a one-way door.

Safety net: every import can be rolled back for 24 hours, so you can undo a bad file with one click. Departments referenced in your file are auto‑created and fuzzy‑matched so near-duplicate names don’t create near-duplicate departments.

Step 1 of the people Import Wizard — choosing a CSV file to upload, before the field-mapping and validation steps.

Step 2 of the people Import Wizard — matching each platform field to a column from your file, with required fields marked and a preview of the first three rows.

For one‑offs, use Add person and fill in the form directly.

Using a different identity provider or HR system? Microsoft 365 and Google Workspace are the two built‑in sync connectors today, with more planned — CSV import in the meantime means you’re never blocked on a native connector to get your directory in. If there’s a specific tool you’d like 786 Cyber to connect to natively, let us know — integrations are prioritised based on what customers actually ask for.

Click any person to open their detail view, which brings together:

  • Devices linked to them
  • Alternate email addresses
  • Their manager (used to build your org chart)
  • Credential & breach exposure — whether their details appear in known breaches

A person detail view showing the Identity, Devices, and Credential & Breach Exposure panels. This person reads "Not yet checked" — a clean state, not a breach.

MFA is tracked as three states, not a simple yes/no:

  • Enabled
  • Disabled
  • Unknown (we don’t yet have the data)

“Unknown” is never quietly treated as “disabled” — you always know the difference. MFA coverage is one of the snapshot indicators on your dashboard.

786 Cyber checks your people against known breach data (via Have I Been Pwned). Anyone whose credentials appear in a breach is flagged on their detail view and rolled up as a credential‑exposure indicator on the dashboard, so you can prompt password resets and MFA where it matters most.

In development. An aggregate Identity Posture Score — a single number combining MFA coverage, breach exposure, and other identity signals — is on the roadmap. Until it ships, use the individual signals above.

For everyday security: a live directory shows you, at a glance, who is missing MFA and who has been caught in a breach — two of the most common ways organisations get compromised.

For compliance: an accurate, current people directory underpins access control, user management, and starter/mover/leaver requirements across Cyber Essentials Plus, NCA ECC and SAMA CSF. MFA coverage evidence maps directly to authentication controls.


Next: Departments & the org chart →