Five accounts across four systems resolve to one person.
The five accounts resolve to one person, each match naming the method that found it.
Govern, identity associations

One person holds five accounts across four systems, and nothing says they are the same person.
How it works
One person, many accounts. A canonical identity links every external account across connected directories
Matching runs automatically on email, UPN pattern, owner field, employee ID or display name, with manual linking as the fallback
Each association names the method that found it and the state it is in. Reviewing the match is the whole job
The jobs it is bought for.
Survive the auditHand the auditor the campaign instead of a week of screenshots
Nobody owns this accountEvery service account, key and token gets a name against it