Three identity systems
The IdP, cloud IAM and Kubernetes service accounts each have their own view and none of them link.
Who can assume which role, which role can reach which data store, and which exposed workload authenticates as that identity — as edges you can walk, not as a quarterly access review.
The IdP, cloud IAM and Kubernetes service accounts each have their own view and none of them link.
Roles granted for an incident in 2024 are still assumable.
A credential committed and rotated is still a credential in git history.
Access reviews show the grant, not what the grant can reach.
The exposed service that authenticates as an over-privileged role is the path, and no identity tool sees the service.
PAM context lives in a vault product that never meets the finding.
member_of, assumes, can_access, authenticates_as and stores edges connect identities to roles, roles to data stores, workloads to identities.Nine types, versioned vocabulary.
Principals, roles and policies across three clouds.
Fingerprints, entropy, history walker.
Which grant to remove first.
Okta, Entra, Google, CyberArk, SCIM.
Every governance action recorded.
We show the role that reaches the most data and the exposed workload that can assume it.