Identity management in practice is a graph: users hold roles, roles carry permissions, and every access decision is a lookup through that graph. This simulator renders the graph in 3D — a column of users, a column of roles, a column of permissions — and lets you edit the real edges: assign or revoke a role from a user, grant or remove a permission from a role. A live access-request check then traces the exact authorization path a real identity-and-access-management system (AWS IAM, Kubernetes RBAC, Active Directory) would evaluate, animating a particle from the requesting user through their assigned role to the requested permission, turning green on ALLOW or stopping red on DENY. Live readouts track effective permissions, role count and the outcome of every check, turning the graph into a working least-privilege audit tool.