Live State
The provider's current config vs your latest backup.
Live State
Each tenant's Overview is a live dashboard of the IdP itself. The Live State panel shows the provider's CURRENT configuration in a two-pane layout: a category rail on the left (Directory, Applications, Security & access, System) with live object counts and drift chips vs your latest backup, and the selected category's objects on the right. Click an object for a side-by-side view of the live version and the version in your latest backup, with the changed fields called out.
Backup status per object
- backed up - identical to the latest backup.
- changed since backup - differs from the latest backup; the detail view lists exactly which fields.
- not backed up yet - exists live but is not in any backup yet.
- deleted since backup - in your latest backup but gone from the live tenant. This is the one to look for after an accidental deletion - Restore it right from the row.
Users in Live State
With a Business or MSP license, the Directory section includes Users: the live user directory compared against your latest Users & Access snapshot. User directories are the API-heavy surface of every provider, so users load on demand - the first click on Users (or Refresh Users from provider) fetches the directory, which then stays cached for the time set in Administration > System settings (Live State users cache, default 60 minutes, minimum 5). Restore on a deleted user opens the Users & Access restore with just that user preselected.
Search everything
The search box in the Live State header searches every category at once by name or id - apps, policies, flows, bindings, and users once the directory is loaded. Results come back grouped by category; clicking one jumps straight to that object's detail.
Refresh, freshness, and paging
Config state refreshes automatically on the interval set in System settings and whenever you click Refresh Config from provider (debounced, so it cannot hammer the API). Large categories page in place - 50/100/250 objects per page - and the counts always reflect the full set, not just the visible page.
Restore and roles
Every restore goes through a dry-run preview - one click to preview, one to apply, never a silent write. Org viewers can browse everything but see no Restore buttons, and the server enforces the same rule regardless.
Trends
Show Trends reveals three charts once a tenant has two or more backups: changes per backup, object count over time, and backup size (including Full-DR dumps when enabled). On the Overview these cover BOTH backup types - config and Users & Access appear on one timeline, with separate lines per type in the object and size charts. The Backups page shows the config-only versions, and the Users & Access page has its own four: changes per backup, directory over time (users, memberships, assignments), backup size, and backup duration with API calls per run.