Definition
An identity graph is a database of relationships between identifiers, such as customer IDs, email addresses, browser IDs and devices. It records which identifiers a system associates with a person, household or company. Identity resolution is the process that creates or uses those relationships.
At Leadpipe, we use identity infrastructure for website visitor identification. That is one application of a graph. A customer data platform connecting your existing users and a provider supporting advertising audiences may need different data, permissions and outputs.
The first buying question is therefore specific: what identity must the graph resolve, from which starting signal, for which action? A large graph is useful only if its links support that job.
Identity graph example
Here’s a concrete example of an identity graph. It shows one fictional B2B buyer, “Jordan Rivera”, as the graph stores them. Every value below is an invented placeholder. Nodes are the identifiers. Edges are the links between each identifier and Jordan’s person record, and each edge carries its match type, source and timestamp.
| Node (identifier) | Example value (fictional) | Edge to person record | Match type | Evidence | Last seen |
|---|---|---|---|---|---|
| Person ID | P-000123 |
Root node | n/a | n/a | n/a |
| Hashed personal email (SHA-256) | 9f2c…e41a |
Owns | Deterministic | Consented newsletter sign-up | 2026-09-02 |
| Work email | jordan.rivera@example.com |
Works as | Deterministic | Authenticated webinar registration | 2026-08-19 |
| Company | Example Corp (example.com) |
Employed by | Deterministic | Work email domain + profile record | 2026-08-19 |
| LinkedIn URL | linkedin.com/in/example-jordan |
Profile of | Deterministic | Profile record matched on name + employer | 2026-07-30 |
| Mobile ad ID (MAID) | AAAA-1111-BBBB |
Uses device | Deterministic | App login with the personal email | 2026-09-10 |
| Laptop cookie ID | ck_7d3e… |
Uses browser | Deterministic | Same browser submitted the work email | 2026-09-21 |
| Second browser cookie ID | ck_a91b… |
Probably uses | Probabilistic (0.72) | Same device fingerprint family + home IP + time pattern | 2026-09-22 |
| Household IP | 203.0.113.24 |
Seen at | Probabilistic, household-level | Repeated evening sessions, shared by other people | 2026-09-22 |
| Office IP | 198.51.100.7 |
Company network | Company-level only | IP-to-company lookup; many employees share it | 2026-09-18 |
This example shows three things:
- Edges carry different weight. The work email and laptop cookie are hard evidence. The second browser is a scored guess. A well-run graph uses the scored guess only where a wrong match is cheap, such as ad frequency capping, and never to put a name on a sales lead.
- Some nodes are shared. The household IP and office IP connect Jordan to other people too. On its own, an IP can support a household or company match, not a person match.
- Timestamps drive freshness. If Jordan changes jobs, the work email and company edges should expire rather than linger.
To evaluate one identity in a graph, pick a person you can verify, like a colleague or your own test profile. Look up every node linked to them. Mark each edge right or wrong, and check whether the deterministic and probabilistic labels hold up. It’s the fastest sanity check you can run on any provider.
TL;DR
- A node represents an identifier or entity; an edge represents a relationship the system has accepted or inferred.
- A shared IP address does not establish that two sessions belong to the same person.
- A first-party graph connects the identifiers your organization collects. External identity services may add reach or links beyond that dataset.
- Evaluate coverage, correctness, freshness and permitted use separately.
- Compare identity graph providers by workflow. Customer unification, media activation and visitor identification are different purchases.
How identity graphs work
A system receives an identifier with its context: where it came from, when it was observed, and what relationship the source supports. A logged-in customer event may connect an account ID to a browser ID. A later authenticated session may connect another browser to the same account.
That is different from joining records solely because their names look similar. Keep the strength and scope of the evidence attached to the link. A household relationship should not silently become a person-level relationship.
A worked example
This is a conceptual example, not a description of every vendor’s implementation.
| Observation | Possible relationship | What it does not establish |
|---|---|---|
| Customer signs in using account ID A from browser B | A and B were linked during that authenticated event | Every future browser user is the same person |
| The same account signs in from browser C | C can be associated with A under the system’s rules | B and C should always be merged across every use case |
| Several browsers share an office IP | A network or location relationship | One individual owns all of those browsers |
| An employee changes company | A new employment relationship may be recorded | The old employer remains current |
A useful graph needs rules for creating, revising and removing relationships. Keeping every historical link indefinitely can preserve incorrect or outdated associations.
The matching layer
Deterministic matching uses an exact identifier or an established relationship. Probabilistic matching infers a relationship from signals under a model. Neither label alone establishes the error rate of a finished product.
An exact match can still inherit a bad source record or a shared account. An inferred relationship needs a clear confidence policy and a use case that tolerates its uncertainty. Ask what evidence supports the output you will actually receive. See deterministic versus probabilistic matching for the concepts.
Types of identity graphs
Identity graphs are usually classified on three axes. A single product can sit on more than one.
Deterministic vs probabilistic identity graphs
| Deterministic identity graph | Probabilistic identity graph | |
|---|---|---|
| How links form | Exact shared identifiers: a login, a hashed email, a phone number | Statistical inference from IP, device attributes, location and timing |
| Strength | Fewer false positives, and each link can be audited | More reach where no shared identifier exists |
| Weakness | Fewer links when people don’t authenticate | Some links are wrong, so they need confidence thresholds |
| Typical users | CRM onboarding, CDPs, person-level visitor identification | Cross-device ad reach, household targeting |
Probabilistic identity resolution gives each candidate link a likelihood score and accepts links above a threshold. Many commercial graphs are hybrids. LiveRamp’s documentation, for example, describes a fully deterministic graph that has “less scale than probabilistic vendors” in exchange for fewer false positives. Twilio Segment says its profile matching is entirely deterministic and does not support probabilistic matching.
First-party, third-party and private identity graphs
- First-party identity graph: built from identifiers you collect yourself (logins, form fills, app IDs, loyalty IDs), usually inside a CDP.
- Third-party identity graph: operated by a provider across many sources. You rent access to its links.
- Private identity graph: a graph built and governed inside your own environment, often seeded with a provider’s reference data. Acxiom’s Real ID, for example, lets brands “build and control” their own interoperable identity graph.
Consumer vs B2B identity graphs
Consumer graphs center on the person and household: name, postal address, personal email, MAIDs, CTV devices. B2B graphs add the professional layer: work email, employer, title and LinkedIn profile, plus company-level IP resolution. That layer is what lets a website visit become a named buyer at a named account. For a list of vendors in each group, see identity graph companies and providers.
First-party identity graphs versus external identity data
A first-party identity graph organizes identifiers your organization collects through its own relationships and systems. It can connect a known customer’s app, website and CRM records when the necessary links exist.
An external provider may supply additional identity relationships or resolved outputs. Access to external data is not the same as owning the underlying graph. Likewise, owning a graph does not establish that every field is current or usable for every purpose.
| Question | First-party graph | External identity service |
|---|---|---|
| Starting data | Your collected identifiers and events | Inputs supported by the provider plus its available relationships |
| Main evaluation | Can it unify your records correctly? | Can it resolve the required population and return usable output? |
| Main limitation | Missing links cannot be created merely by centralizing data | Coverage, permissions and available fields depend on the service |
| Operational owner | Your data or customer-platform team | Your team plus the provider and downstream integration owners |
These approaches can work together. Document which system owns the profile, which supplies additional fields, and how a correction or deletion reaches the destination.
Identity graph providers: compare the job first
The following examples illustrate different product categories. They are not an accuracy ranking or a list of interchangeable subscriptions. Product positioning was checked against the linked official pages on September 23, 2026.
| Provider or platform | Published focus | Evaluate when you need |
|---|---|---|
| LiveRamp | Identity, data collaboration, media activation and measurement | Connectivity across an advertising and marketing ecosystem |
| Adobe Real-Time CDP | Unifying customer and account profiles across data sources | A governed customer profile within an enterprise customer-data workflow |
| Claritas | Consumer identity resolution | Consumer audience and identity use cases |
| Leadpipe | Website visitor identification and person-level intent | Eligible visitor records or an intent audience for a B2B workflow |
For a fuller list organized by type (LiveRamp, Experian, TransUnion, Epsilon, Acxiom, Verisk, Stirista, UID2, CDPs and B2B graphs), see our identity graph providers list.
For each candidate, ask for a demonstration using your input type. A successful customer-record merge is not proof that the same product can identify an anonymous visitor. A media identifier is not necessarily a contact record that a sales rep can use.
If your job is specifically visitor identification, use our ten-tool comparison and B2B buying guide. Keep the shortlist narrow enough to inspect actual output.
Quality dimensions: coverage, accuracy, freshness
Coverage
Coverage describes the population and identifiers a service can resolve. A count of nodes is not a count of unique people: one person may have several identifiers. Nor is a total profile count your expected match rate on a particular site.
Report your eligible population, the provider’s returned output and the measurement window. Separate company and person results. Compare the same regions and page scope before deciding one provider has better coverage.
Accuracy
Correctness is field-specific. A company match can be correct while a suggested contact is unrelated to the visit. An email can be deliverable while the job title is stale.
Accuracy also varies widely between providers. A Truthset and CIMM study of 3.9 billion hashed email records found email-to-postal linkage accuracy ranging from 32% to 69% depending on the data provider.
Create review criteria for the identity, company, role and contact channel you need. Record missing and unresolved results separately from accepted and rejected records. If you inspect a sample, show how it was selected and how many records you reviewed.
Freshness
Ask what each timestamp means. The last time a profile was delivered, the last time a source checked a job title, and the last observed visit are different events.
A daily processing schedule does not prove every field was independently reverified that day. Require freshness evidence for the fields that affect routing or outreach.
Permissions and removal
Ask which uses the provider permits, how exclusion and opt-out requests are handled, and how linked records are removed or corrected. Have your privacy owner assess the proposed workflow and regions. A matching capability does not by itself authorize outreach or every downstream use.
Identity graph in marketing
These are the most common marketing uses for an identity graph:
- Retargeting. Link a site visitor’s cookie or device to a hashed email or MAID, then reach that person on other channels. Retargeting by identity rather than cookie alone survives a switch between browsers and devices. Two tactics that work: retarget identified visitors by account tier, and suppress known customers from prospecting ads.
- Suppression. Resolve every identifier of an existing customer or opted-out person, so exclusions reach all of them, not just the one email in your CRM.
- Measurement and attribution. Connect ad exposure on one device to a conversion on another. This is the core use of household graphs in CTV.
- First-party cookie stitching. A first-party cookie keeps its ID on your domain. When the visitor later logs in or submits a form, the graph attaches the whole anonymous history to the known profile. Segment’s identity resolution does this with anonymous IDs, cookie IDs and user IDs.
Signals keep shifting under these workflows. Google decided in April 2025 to keep third-party cookie choice in Chrome. That still leaves Safari, app and CTV traffic, where hashed email and first-party IDs carry the graph.
How a B2B identity graph connects anonymous visits to buyers
A B2B identity graph turns anonymous behavior into a known buyer profile in five steps:
- Capture. A first-party script records the session: cookie ID, device signals, IP, pages viewed and timestamps.
- Resolve the network. The IP is resolved to a company where possible. This works worldwide at the company level (see IP-to-company).
- Match the person. The cookie, device and hashed-email signals are looked up in the graph. A deterministic match returns one person record. No verified link means no name.
- Enrich the profile. The matched person node brings its edges: work email, title, LinkedIn URL, employer and firmographics.
- Attach behavior and act. The session’s pages and repeat visits attach to that profile, then flow to CRM, Slack or a sequence, or into an audience for retargeting.
Leadpipe runs this flow on its own deterministic, person-level identity graph, resolving about 30–40% of US traffic to individuals and identifying non-US visitors at the company level.
Try Leadpipe free with 500 leads →
Identity graphs versus CRMs
| Layer | Stores or manages | Question it helps answer |
|---|---|---|
| Identity graph | Relationships between identifiers and entities | Which records might refer to the same entity? |
| CRM | Accounts, contacts, ownership and commercial activity | What is our relationship with this account or person? |
| Identity resolution | Matching and linking operations | How should this incoming record relate to existing records? |
Keep the CRM’s ownership and suppression rules when adding graph-derived records. A new match should not automatically create a duplicate lead or overwrite a field your team has verified.
Applications and their limits
Visitor identification
A supported website signal may be resolved to a person or company record. The output depends on available evidence, geography, configuration and product scope. Not every visit can be identified, and not every returned field is guaranteed to be present.
Cross-device resolution
Two devices can be linked when the system has adequate evidence, such as a supported authenticated relationship. Similar browsing behavior alone is not proof of shared identity. For multiple properties, read the multi-domain tracking guide.
Data enrichment
A known identifier can help retrieve additional fields. Check whether the returned information describes the right person and current company before allowing it to change an important CRM field.
Suppression
Linked identifiers can help apply exclusion rules, but the implementation needs validation. Test how the chosen product handles an alternate email, repeat visit and correction request. Do not assume suppression automatically reaches every linked identifier or downstream tool.
A practical provider evaluation
- Write the input and required output: customer ID to profile, browser signal to visitor, or another specific relationship.
- Choose a representative sample and define what counts as a correct result.
- Inspect output at the field level; separate missing, incorrect and unknown data.
- Check freshness, correction and removal behavior.
- Deliver accepted output to the real destination and review duplicates and ownership.
- Compare complete operating cost against accepted output.
Use the evaluation kit for a reusable scorecard and vendor questionnaire. It keeps a provider’s documented capability separate from what your trial actually demonstrated.
FAQ
What is an identity graph?
An identity graph is a database that links identifiers such as emails, phone numbers, device IDs, cookie IDs and IPs to the person, household or company they belong to. Identity graphing is the process of building and maintaining those links.
What is an example of an identity graph?
One person’s record might link a hashed personal email, a work email, a mobile ad ID, two browser cookie IDs, a household IP and a LinkedIn URL, with each link labeled deterministic or probabilistic and time-stamped. See the worked example above.
What is a first-party identity graph?
A first-party identity graph links only the identifiers your organization collects, such as logins, form fills and app IDs, usually in a CDP. It unifies your known customers but doesn’t identify people you’ve never collected data on.
What is probabilistic identity resolution?
Probabilistic identity resolution links identifiers by statistical likelihood (shared IP, device traits, timing) rather than an exact shared identifier. It adds reach but introduces false positives, so it suits ad targeting better than naming a sales lead.
How does a B2B identity graph connect anonymous behavior to known buyers?
It captures the session’s cookie, device and IP signals, resolves the company from the IP, matches the person through verified links in the graph, then attaches the pages viewed to that buyer’s profile in your CRM.
What is an ID graph?
ID graph is another name for an identity graph: a set of relationships between identifiers and the people, households or companies they represent. The intended entity level matters when interpreting a match.
Is a first-party identity graph a contact database?
Not necessarily. It may connect identifiers your organization already holds without supplying new prospect contact information. Specify whether you need record unification, enrichment or visitor identification.
How should I compare identity graph companies?
Start with the workflow, input signal, required output and region. Then assess a representative sample for correctness, freshness, delivery and permitted use. A total node count cannot replace that evaluation.
Does an identity graph identify every website visitor?
No. Identification depends on available links, technical signals and the product’s scope. Keep unresolved visitors visible in the measurement rather than counting them as identified.
Does owning an identity graph guarantee better results?
No. Ownership describes the infrastructure relationship. Evaluate the output and operating controls that matter for your use case instead of treating built versus licensed as an accuracy score.
Related Articles
- Identity Graph Companies: 2026 Provider List
- How Identity Graphs Work
- How We Built the Leadpipe Identity Graph
- What Is Identity Resolution?
- Identity Graph APIs: How They Work
- Deterministic vs Probabilistic Identity Matching
Evaluate visitor identity on your own traffic
If you need eligible website visitor records, explore Leadpipe Identification and bring the scorecard to inspect what your team can actually use. Get 500 identified leads free, no credit card →




