A group audit answers whether the directory's structure still matches the organization's intent. This checklist covers the structural checks that surface real findings, with the evidence worth capturing for each.

Structural integrity#

The checks that find broken shape:

  • Circular references: any membership loops, however long the chain.
  • Nesting depth: chains beyond your policy maximum, ranked by depth.
  • Orphaned groups: no owner, no members, or no discernible purpose.
  • Overlapping groups: memberships that duplicate another group's.

Licensing hygiene#

The checks that find money and risk:

  • License assignments per group, and whether each is still intentional.
  • Duplicate and conflicting assignments per user, including disabled service plans.
  • Seats held by disabled or dormant accounts that remain direct members of licensed groups.

Evidence to capture#

For every finding, capture the state, not a screenshot: the structure as of the audit date, exportable in a format whose origin can be verified. An audit that cannot prove what it saw is an opinion with formatting.

VisualizerEngine

Running the checklist in VisualizerEngine

Every structural check on this list is a built-in analysis: circular references, depth against your thresholds, orphans, overlap, and per-user license conflicts are continuously computed. Snapshots capture the audit-date state, and compliance exports carry provenance metadata and an integrity trailer for the evidence file.