Data Security · AuditMap · Premium

Start at the asset.
See everyone who can reach it.

Premium

Every other view in the product runs identity → resource. AuditMap runs it backwards. Name the thing you actually care about protecting — the clinical storage account, the claims database, the model endpoint — and get the complete set of identities that can reach it.

The inversion

Two directions. Two different jobs.

Both questions run on the same canonical graph. They are not the same question, and answering one does not answer the other.

Identity Graph

Identity → Resource

“This service principal looks dangerous. What can it get to?”

The investigation direction. You have a suspect and you need its reach. Used during triage, offboarding, and incident response.

AuditMap · Premium

Resource → Identity

“This database holds cardholder data. Who can reach it?”

The assurance direction. You have an asset you are accountable for and you need the complete population that can touch it. Used during audit, certification, and design review.

Why this is the hard direction

You cannot answer it
by reading the resource.

Look at a storage account in the portal and you will see the assignments made at it. That is a small and misleading fraction of who can reach it.

The rest arrive from above — subscription Owners, resource-group Contributors, management-group inheritance — and from sideways: group nesting, PIM-eligible activation, federated credentials whose subject claim is broader than anyone intended, and non-human identities that hold the role on behalf of a pipeline.

Assembling that population by hand is a multi-day exercise that is stale the moment it finishes. AuditMap computes it continuously, and shows the path for every identity in the set.

Reach set · sa-clinical-prod
Direct assignment Storage Blob Data Owner · at resource
Inherited · subscription Owner · /subscriptions/prod-001
Inherited · resource group Contributor · rg-data-platform
Group nesting via sg-platform-eng → sg-all-eng
PIM eligible activatable, not currently active
Federated credential GitHub OIDC · subject claim scope

Illustrative path taxonomy. Only the first row is visible from the resource itself.

What you get

The answer, and the proof.

The complete reach set

Every identity — human, service principal, managed identity, workload, AI agent — that can reach the asset, with inheritance and nesting fully resolved.

The path for each one

Not just membership in the set, but how each identity got there. Direct, inherited, nested, eligible, or federated — attributed per identity.

Privilege, not just presence

Read differs from write differs from ownership. The map separates who can see the asset from who can exfiltrate, alter, or delete it.

Classification-aware

Reach into a PHI or PCI zone is a materially different finding from reach into a scratch environment. Data Trust Zones supply the anchor.

Audit-ready output

“Show me everyone who could reach cardholder data last quarter” is a question you can now answer with a document rather than a project.

Honest about blind spots

Where classification is undefined or a connector cannot see, the map says so. Unknown renders as unknown — never as safe.

Availability

AuditMap is enabled per account.

It is not bundled into a plan tier. AuditMap is granted per organization by the AuditGraph sales team, so scope, data-classification setup, and the reachability configuration it depends on are agreed before it is switched on.

That is deliberate: a resource-first exposure map is only as honest as the Data Trust Zone definitions underneath it. Turning it on without that groundwork produces a confident-looking map of the wrong thing.

Premium Enabled per account by the AuditGraph team — [email protected]
Beta Functional and in hardening, with known gaps documented
Get started

Pick one asset you are accountable for.

Name the storage account, database, or dataset that would hurt most. The assessment answers who can reach it — against your tenant, not a demo.

Free forever on a bounded estate · 30-day trial unlocks everything · No credit card

Read-only access · No agents · No log ingestion · Azure generally available