Elisity delivers cloud-native, identity-based microsegmentation that runs on the access-layer switching you already own. It gives you complete visibility into every asset on your network and a low-friction path from that visibility to enforced, identity-based policy.
This article is a guided introduction to the Elisity platform. Each section links to the in-depth Knowledge Base articles for the topics it introduces, so you can start here and follow the links to the technical detail you need.
Introduction
Thank you for your interest in Elisity Microsegmentation. Elisity reduces the complexity that is commonly associated with deploying true microsegmentation in brownfield environments. Forrester noted in The Forrester Wave™: Microsegmentation Solutions, Q3 2024 that we are in the Golden Era of Microsegmentation, where Elisity was recognized as a top performer. With minimal prerequisites and the ability to leverage existing access-layer switching hardware, Elisity transforms the way dynamic edge segmentation is achieved. The platform builds policy from identity and context — who or what an asset is and how it behaves — rather than from location or IP address, and it applies equally to users, applications, and devices no matter where they appear on the network.
From Visibility to Enforced Policy
Most security and network tools stop at visibility. They tell you what is on the network, but leave the work of turning that knowledge into enforced segmentation to you. Elisity takes the same identity and behavioral data you would expect from any asset-visibility platform and removes the friction of acting on it.
Elisity discovers every asset natively from the network and enriches it with identity and context from every connected system — your identity providers, endpoint and IoT/IoMT security tools, CMDBs, and cloud platforms. That aggregated understanding lives in Elisity IdentityGraph, and it is what shortens the next step: administrators build precise, identity-based policy directly from real asset attributes and observed traffic, without re-architecting the network, deploying new hardware, or hand-maintaining IP and VLAN mappings. The result is a fast, repeatable path from "I can see it" to "it is segmented and enforced."
Components of Elisity
The Elisity solution is a software-defined network security platform in which the control plane and data plane are separate and independent. Elisity has developed a control and policy plane that scales to the enterprise, paired with an identity-based policy language that keeps deployment and day-to-day management simple. Together, these components establish a continuously verified secure network across users, applications, and devices.
The Elisity architecture has several primary components:
Elisity Cloud Control Center — The centralized management, visibility, policy, and integration console, delivered as a service.
Elisity IdentityGraph — The aggregated identity and behavior of every asset on your network, discovered natively by Elisity and enriched with identity and context from every connected system. See What is IdentityGraph™?
Elisity Dynamic Policy Engine — Atomizes policy into its identity elements and distributes them to the enforcement infrastructure closest to each asset.
Elisity Intelligence — The analytics engine that studies asset identity, behavior, and traffic to surface evidence-backed insights and policy suggestions. See Policy and Device Insights.
Elisity Virtual Edge — Controllers for the policy enforcement points that translate identity, telemetry, and policy between the switches and Cloud Control Center.
Elisity Virtual Edge Nodes — Cisco, Arista, Juniper, and HPE Aruba access and aggregation switches transformed into policy enforcement points. See the Switch Compatibility Matrix.
Elisity Cloud Control Center
Elisity Cloud Control Center (CCC) is the management, control, and policy plane for Elisity. Administrators log in to CCC to provision, manage, and monitor the Elisity fabric and every identity and cloud integration, including Active Directory, cloud platforms such as AWS, and security sources such as Claroty, CrowdStrike, and ServiceNow. CCC performs multi-domain asset discovery and identity mapping, presents identity and behavior analytics, and is where administrators build the contextual, identity-based policies that harden the edge of the network. CCC then orchestrates the distribution of those policies across every component of the Elisity architecture over a secure TLS control channel. A dedicated Cloud Control Center is provisioned per customer and hosted as a service by Elisity on a cloud-native, horizontally scaling microservices architecture. CCC is organized into a left-hand navigation menu, grouped by product area, that provides access to every capability in the platform.
Navigating Cloud Control Center
Cloud Control Center presents a left-hand navigation menu, located below the page header, that groups related capabilities under primary product sections. Selecting a section expands it to reveal its pages.
The navigation menu is organized into the following primary sections:
- Dashboards — role-based views of network activity and deployment progress, including Overview, Executive Summary, Zero Trust, and Snapshots.
- IdentityGraph — the discovered inventory of Devices, Workloads, and Users, along with the Connectors that enrich them.
- Policy — the policy construction and deployment tools: the Matrix, Policy Groups, Security Profiles, Policy Sets, Policy Evaluator, and Policy Settings.
- Edge Management — the enforcement infrastructure: Virtual Edges, Virtual Edge Nodes, Site Labels, Distribution Zones, and Edge Settings.
- Traffic Analytics — observed traffic flows across the network.
- Insights — policy suggestions and their configuration, under Suggestions and Insight Settings.
- Monitoring — operational records across Audit Logs, Events, Activity Logs, and Alerts.
- Settings — tenant and platform configuration under Administration and System.
The header spans the top of every page and displays the customer logo, the current page title, action icons, and a profile menu. The Help Center link and the light and dark mode toggle are available from the profile menu.
The rest of this article walks through each primary section in turn, describing what it is within the platform and linking to the Knowledge Base articles that cover it in depth.
Dashboards
The Dashboards section presents role-based views of the platform. The Overview Dashboard is the primary operational workspace, providing real-time visibility into network activity, device distribution, policy deployment, and infrastructure health. The Executive Summary Dashboard gives leadership a high-level view of deployment progress and site-by-site key performance indicators, and the Zero Trust Posture Dashboard scores how completely your environment is segmented and where the highest-impact gaps remain. For complete documentation, see Cloud Control Center Dashboards, the Zero Trust Posture Dashboard, and Understanding the Zero Trust Posture Dashboard.
IdentityGraph™
At the heart of Elisity's approach to network security is IdentityGraph™: the aggregated identity and behavior of every asset on your network, discovered natively by Elisity and enriched with identity and context from every connected system.
What it is. IdentityGraph is a continuously updated map of every entity in your network ecosystem. It does not just record that a device or user exists; it captures relationships, roles, and behavior. It aggregates data from identity providers, endpoint and IoT/IoMT security tools, CMDBs, and cloud platforms into a single, comprehensive profile for each asset — attributes such as user identity, device type, operating system, security posture, compliance status, and location.
How it works. As assets connect and interact, IdentityGraph learns and refines its understanding in real time. When an attribute changes at the source — for example, an endpoint moving from trusted to untrusted in a connected security tool — the enriched profile updates automatically, and any dynamic policy that depends on that attribute follows without manual intervention.
Why it is pivotal. IdentityGraph is what makes Elisity's path to policy so short. Because policy is built from real, verified attributes rather than guesswork, the policies you create in the Matrix are precise, effective, and adaptive — visibility and enforcement drawn from one source of truth.
The IdentityGraph section surfaces IdentityGraph across Devices, Workloads, and Users, giving you a sortable, filterable inventory of every discovered asset and a per-asset detail view of everything IdentityGraph knows about it, including associated policies and observed traffic.
People imported from your identity provider — such as Active Directory — appear under Users, each with login history, current status, associated policies, and traffic context.
This section is also where you configure all Connectors — the integrations with third-party identity and security sources that feed device and user attributes into IdentityGraph. Elisity supports pre-built connectors for common sources as well as custom, REST API-based connectors for any system that exposes the data you need, and the source of every attribute stays transparent on each asset's profile.
For a deeper treatment of IdentityGraph, see What is IdentityGraph™? For connector configuration and attribute details, see the Identity category, which contains the documentation for all connectors.
Policy
The Policy section is where identity becomes enforced segmentation. It groups the tools you use to build and deploy identity-based policy: the Matrix, Policy Groups, Security Profiles, Policy Sets, Policy Evaluator, and Policy Settings. Policy Groups are dynamic, identity-based groupings of assets and are the foundation of an effective policy framework, while the Matrix provides a graphical view for deploying policies between groups — with a Traffic Flow view that lets you base those decisions on observed traffic rather than guesswork.
The Matrix presents your Policy Groups in a visual grid, where each cell represents the policy between two groups and colored cells in the Traffic Flow view reveal the communication Elisity has observed.
For step-by-step guidance, see Policy Matrix, Managing Policies Using the Policy Matrix, and Policy Groups. To organize how policy is scoped and distributed across locations, see Policy Sets and Site Labels and Policy Set Scores.
Edge Management
The Edge Management section is the enforcement layer of the platform. It brings together Virtual Edges, Virtual Edge Nodes, Site Labels, Distribution Zones, and Edge Settings — the infrastructure that turns your existing switching into identity-aware policy enforcement points and controls how policy is distributed to each location.
Elisity Virtual Edge is a secure virtual appliance running Elisity software to provide both east-west and north-south identity-based zero trust control and microsegmentation at the network edge. It gleans identity metadata from traffic flows, collects flow analytics, and detects IT, OT, IoT, and IoMT devices, sharing this information with Cloud Control Center for additional identity and policy classification. Through the secure Elisity control channel, policy is distributed to the appropriate Virtual Edges, which enforce it using switch-native functionality on the access switch closest to the endpoint. Virtual Edge is the primary deployment methodology for campus and large-branch customers, and it can be inserted into your network either by hosting the software directly on switches with application-hosting capabilities or by running it as a VM on your hypervisor of choice.
Elisity Virtual Edge Nodes are your supported switches transformed into policy enforcement points with minimal friction. All you need to begin onboarding Virtual Edge Nodes is a Virtual Edge deployed anywhere in your network with connectivity to the switches you want to onboard; from there, onboarding is a matter of loading a few required configurations on the switch and entering its network address and credentials. Many Virtual Edge Nodes can be controlled by the same Virtual Edge, and you can onboard many at once using bulk onboarding.
For design options and deployment detail, see the Virtual Edge design guidance, the Virtual Edge Hypervisor Deployment Guide, Overview of Virtual Edge Groups, and Virtual Edge Shell and Commands. For platform-specific onboarding, see the Switch Compatibility Matrix and the guides for Cisco, Arista, HPE Aruba, and Juniper (Mist and Direct Switch Integration), along with Bulk Onboarding Virtual Edges and Virtual Edge Nodes and Visibility-Only Virtual Edge Nodes (Cisco). To scope how policy is distributed across locations, see Distribution Zones and Elisity Intelligent Tag Distribution (ITD), or browse all of these articles.
Traffic Analytics
The Traffic Analytics section presents the traffic flows Elisity observes across the network, letting you understand how assets actually communicate before you write a single policy. Reviewing real flows makes policy creation evidence-based: you can allow known-good communication and segment the rest with confidence. See Cloud Control Center Traffic Analytics.
Insights
The Insights section is where Elisity Intelligence surfaces evidence-backed recommendations. It continuously analyzes asset identity, behavior, and observed traffic to produce Policy Group suggestions and to identify overly permissive policy, grounding every recommendation in IdentityGraph attributes and flow telemetry so the data behind it is always visible.
Elisity Intelligence and the Elisity Assistant run on private large language models hosted in Elisity's single-tenant AWS Bedrock environment. Customer data stays within each tenant, is never shared across customers, and is never used to train models. Every suggestion is presented for administrator review and approval, keeping a human in the loop for all policy decisions. To work with these capabilities, see Policy and Device Insights and Elisity Assistant - Identify Overly Permissive Policy.
Monitoring
The Monitoring section records operational activity across Audit Logs, Events, Activity Logs, and Alerts, giving administrators a durable record of what changed, when, and by whom. For field references, see Monitoring (Logs and Events) Reference.