Standing privilege where money moves
Financial services has the most mature access governance of any sector and still cannot answer reach questions, because governance operates on roles while risk operates on scope. An entitlement review that certifies role names certifies nothing about what those roles reach.
“Can we prove least privilege over the systems in scope for our audit?”
How the risk takes shape.
Cardholder scope is a reachability boundary
PCI scope is defined by what can reach cardholder data. Non-human identities with inherited access quietly widen that boundary, and scope creep is discovered during assessment rather than before it.
SOX ITGC wants evidence, not assertions
Access controls testing asks who could have changed a financially relevant system. That is a reach question about a point in time, answerable from configuration snapshots rather than reconstructed from tickets.
Automation identities carry production authority
Trade reconciliation, settlement, reporting and risk pipelines run under identities with write access to systems of record — and are governed far less rigorously than the humans who built them.
What we look for first.
These are structural patterns this operating model tends to produce — not findings from any particular organization. They are where an assessment starts, because the architecture makes them likely.
Whether they are present in your estate is an empirical question. That is the point of looking.
- CI/CD identities with production data-plane roles held permanently rather than activated
- PIM-eligible privileged roles treated as zero risk despite being one activation from active
- Reporting and analytics service principals reaching cardholder environments through inherited subscription scope
- Federated credentials whose subject claim is broader than the single pipeline it was created for
- Legacy application identities that no current owner recognizes
Evidence, in your framework's language.
The reach set
Every identity that can reach your cardholder data, with the path each one takes — direct, inherited, nested, eligible or federated.
Control-mapped findings
Findings tied to the control families you evidence against — PCI DSS and SOX ITGC — with the underlying facts attached.
One ranked decision
Not a backlog. The single highest-consequence move, with its projected outcome labeled as projected and its evidence trail intact.
Test these patterns against your own estate.
A scoped, read-only assessment on a subscription you choose. We answer the question above with your numbers, and tell you plainly where we could not determine something.
Free forever on a bounded estate · 30-day trial unlocks everything · No credit card
Read-only access · No agents · No log ingestion · Azure generally available