The platform

One graph.
Eight ways to ask it a question.

AuditGraph is not a collection of tools that happen to share a login. Every surface renders the same canonical facts, produced once, by one owner. If two screens disagree, that is a defect — not a perspective.

  1. Human Employee, admin, contractor
  2. Service Principal App registration
  3. Managed Identity System or user-assigned
  4. AI Agent A subtype of NHI
  5. Model Cognitive Services
  6. Classified Data PHI · PCI · PII
Discovery builds this chain from your tenant's configuration. Every surface below is a question asked of it.
How it works

Connect, discover, decide.

  1. 01

    Grant read-only access

    Microsoft Graph and ARM, read scopes only. No agent is installed. No write permission is ever requested — the product is architecturally incapable of changing your tenant.

  2. 02

    Discovery builds the graph

    Every identity across every class — human, service principal, managed identity, workload, CI/CD, PAT, OAuth app, AI agent — with role assignments, scopes, federated credentials, and PIM state.

  3. 03

    Engines compute consequence

    Reachability, blast radius, attack paths, and data exposure — derived from configuration, not inferred from behavior. Each identity receives a lineage verdict.

  4. 04

    One ranked decision

    Ranked by business consequence — never by population or node count — with the evidence trail attached, ready to hand to an auditor.

Capabilities

Every capability, with honest maturity.

Maturity below is copied from our internal feature catalog, not written for this page. GA ships and reconciles. Beta is functional and hardening. Alpha is usable but not yet trustworthy for a buying decision. We would rather you know.

Decision Center

What is the biggest identity risk to the business today, and what is the one move?

  • Executive Summary Beta

    The one-minute decision story. One decision, above the fold.

  • Risk Center Beta

    The ranked risk landscape, with drill-through to evidence.

  • Risk Reduction Planner Beta

    Programs and their projected outcomes — tracked as reduction, not tasks.

  • Argus Beta

    Natural-language query over the graph. Answers reconcile to canonical facts or it declines to answer.

Identity Security

Who and what exists, what do they hold, and when was it last used?

  • Identity Estate — All / Human / NHI / AI GA

    The discovered estate by class. The substrate everything else is computed from.

  • Identity Investigation GA

    The canonical per-identity investigation: story, one recommendation, evidence.

  • Privileged Access Beta

    Standing privilege, PIM eligibility, and activation reality.

  • Identity Hygiene Beta

    Credential age, expiry, secret and certificate posture.

Investigations

How would an attacker get from here to something that matters?

  • Identity Graph GA

    Relationships and reachability. The moat and the evidence.

  • Attack Simulator GA

    Attack-path and blast-radius analysis, computed before exploitation.

Governance

Where is privilege excessive, and who signs off on reducing it?

  • Role Mining / Role Optimization Beta

    Find and reduce excess and standing privilege at scale.

  • Entitlements Beta

    What an identity truly holds once scopes resolve.

  • Toxic Access Beta

    Privilege combinations that enable escalation when held together.

  • Access Reviews Beta

    Reviewer-driven certification with a defensible trail.

Data Security

Who can reach our regulated data, and by what path?

  • AuditMap Premium

    The resource-first exposure map. Start at the asset, see everything that reaches it.

  • Data Trust Zones Beta

    PHI / PCI / PII classification — the value anchor every exposure number depends on.

  • Data Reachability Beta

    Which identities reach which classified data. The core business-risk link.

AI Security

What AI is running in our tenant, and what can it reach?

  • AI Findings Beta

    AI-identity risk surfaced as identity risk, on the same graph.

  • AI Runtime Alpha

    The AI-identity runtime surface — the fastest-growing identity class.

  • Model Registry Alpha

    Inventory of models and AI workloads discovered in the tenant.

  • Supply Chain Alpha

    Federation and provenance trust for AI and non-human identities.

Compliance

Can we prove this to an auditor?

  • Compliance Posture Beta

    Framework-by-framework rollup per control family.

  • Compliance Evidence Beta

    Evidence-first control posture tied to identity facts.

  • Auditor Pack Beta

    The artifact you hand to an auditor, reconciled to the same canonical numbers.

Operations

Is what I am looking at fresh, and what changed?

  • Findings Beta

    The operational backlog where investigation meets action.

  • Drift Analysis Beta

    Change between snapshots. Requires at least two — and says so when it has one.

  • Operations Center Beta

    Discovery and producer health. Freshness you can verify rather than assume.

What we cannot do yet

The honest list.

  • Prove reduction. Recomputing reachability with a remediation applied — the counterfactual engine — is on the roadmap. Until it ships, we show projected outcomes labeled as projected, never as measured.
  • AWS and GCP discovery. Both are documented extension points with stub connectors. Azure is the generally available provider.
  • Owner inference. We do not guess who owns an identity. Unowned identities display as unowned.
  • Per-object event history. Where we do not model an event timeline, the timeline is empty rather than filled with something plausible.
  • WCAG AA certification. The product is keyboard-operable and theme-aware; a formal audit and VPAT are pending.

This list lives at Trust → Known limitations and is maintained alongside the product, not the marketing.

Get started

Start with the question you cannot answer today.

A scoped assessment against your own Azure tenant. Read-only, agentless, and nothing is written to your environment — ever.

Free forever on a bounded estate · 30-day trial unlocks everything · No credit card

Read-only access · No agents · No log ingestion · Azure generally available