AuditGraph Map · Monitor · Secure Book an assessment
PlatformIdentity GraphAI IdentitiesTechnologyIndustriesPricingCompanyPilot observationsTrust Center
Identity Security Graph · Human · Non-Human · AI

Access is what you granted. Reach is what they get.

Every human, non-human, and AI identity in your cloud reaches further than the role you assigned it. AuditGraph computes the difference — from your architecture, before an attacker does.

Free forever — 1 subscription, 500 identities · 30-day trial unlocks every feature · No credit card · See what's included

AgentlessRead-only — never writes to your tenantNo log ingestionArchitecture-derived
app.auditgraph.ai/executive Interface mockup
Today's decision
Regulated data is reachable by identities with no accountable owner
Act now
Privilege tier
Owner
Reach
Subscription-wide
Classification
PHI · PCI
The one move
Scope three non-human identities from subscription Owner to resource-level roles.
projected
Outcome is labeled projected, never measured — the counterfactual engine is roadmap.
Provenance
measured computed as_of · last snapshot

The decision surface. One finding, its band, the one move — and the basis every number was derived from.

The chain that matters

One compromised credential. Six tiers of reach.

When a credential is compromised, the incident question is always the same: what is the chain from that credential to the data we lost? That chain crosses humans, non-humans, AI agents, models, and datasets. Most tools see one tier of it.

01
Human
Employee, admin, contractor
02
Service Principal
App registration
03
Managed Identity
System or user-assigned
04
AI Agent
A subtype of NHI
05
Model
Cognitive Services
06
Classified Data
PHI · PCI · PII

Every edge is a verified RBAC, OIDC trust, or data-classification relationship — read from your tenant's configuration. Patent provisional filed June 2026.

Most identity products see
User → Role → Resource

Accurate. Also the part you could already query yourself.

AuditGraph sees
Human → SPN → MI → AI Agent → Model → Dataset

The full authority path — including the tiers that have no owner today.

The problem

You have an inventory. An attacker has a path.

The market stops at truth: a list of principals, roles, permissions, misconfigurations, graph edges. All accurate — and all irrelevant to the person who has sixty seconds and a board meeting.

Truth and relevance are different properties. Detection is commoditized. The decision is the moat.

The tiers nobody owns

SailPoint stops at humans. CIEM stops at roles. NHI vendors stop at service accounts. AI security tools stop at runtime. Each covers one tier; none connects the chain.

Log-based tools miss static risk

An identity that has never signed in produces no telemetry — and can still hold Owner on a production subscription. Absence of activity is not absence of authority.

Non-human identities outnumber humans, and nobody is counting

Service principals, managed identities, workload and CI/CD identities, PATs, OAuth apps, AI agents. They accumulate permissions and rarely lose them.

Counts are not consequences

"You have 4,000 identities" is not a decision. "This one reaches regulated data and three people can assume it" is.

The approach

Reach is in your architecture. It was never in your logs.

Roughly 70% of organizations do not run the logging a behavior-based product depends on. AuditGraph derives risk from what is already there — role assignments, PIM, federated credentials, RBAC scopes, ARM, GitHub OIDC, network configuration.

Business-first

The headline is the business condition, never the role name. The role is how we prove it; the consequence is what we say.

Every number has provenance

Each value carries its basis — measured, computed, projected, estimated, attested, or unknown. A value without a basis does not render.

Unknown is a real answer

Absence is never painted as safety, never coerced to zero, never shown green. "We cannot see this" is a finding, not a gap to fill.

Deterministic, not generative

No language model sits in any reasoning, ranking, or narration path. Argus formats conclusions the engines reached. It cannot improvise.

On scoring

A score you cannot decompose is a score you cannot defend.

A single 0–10 number tells a CISO nothing they can act on and nothing they can defend to an auditor. Worse, it hides its own arithmetic — and a score you cannot decompose is a score you cannot argue with.

AuditGraph retired numeric severity scoring entirely. In its place: bands derived from checkable facts — the privilege tier an identity actually holds, the reach that privilege actually grants, the governance controls that are actually absent. Every band decomposes back to the assignments that produced it.

When your auditor asks where a rating came from, the answer is a scope string and a role definition — not a weighting we chose.

What an auditor gets back
bandcritical
basiscomputed
roleOwner
scope/subscriptions/{id}
reach312 resources
zonePHI · PCI
Lineage verdicts

Silence is not safety. Every identity gets a verdict anyway.

Static association analysis assigns each identity in your tenant one of nine verdicts — continuously, with no dependency on sign-in telemetry.

Non-human identities default to risky-until-proven. On an NHI, the absence of a risk signal is itself a signal — never a neutral gap.

ORPHANED
Parent resource is gone. Role assignments are still live.
GHOST_MSI
System-assigned managed identity whose compute no longer exists.
AT_RISK
Meaningful reach combined with weak or absent governance.
FEDERATED_MISCONFIGURED
A federated credential subject claim broad enough to let unintended principals assume this identity.
STALE
Provisioned, still privileged, no current association.
PAT_GOVERNANCE_RISK
Active personal access tokens with no expiry, bypassing Entra ID token lifecycle governance.
UNUSED
Exists and is entitled, but no use has been established.
NEEDS_REVIEW
Something about this identity requires a human decision.
HEALTHY
Well-scoped, governed, acceptable reach.
The platform

One graph. Four ways to act on it.

The graph is the evidence, never the headline. Each surface is a different question asked of the same canonical facts.

GA

Identity Graph

Relationships and reachability across the whole estate. Who can assume what, through which trust, to reach which resource. The depth that makes every other answer credible.

Explore the graph →
GA

Data reachability

The resource-first lens. Start at a storage account, a database, a dataset — and see every identity that can reach it, by what path, at what privilege.

See data exposure →
GA

AI Identities

AI agents are a subtype of non-human identity, not a separate product. The same graph, the same verdicts, extended to agents, models, and the data they can reach.

AI identity coverage →
GA

Attack paths & exposure

Blast radius and data reachability computed before exploitation, from configuration rather than from an incident. Ranked by business consequence.

Full platform →
Coverage, stated honestly

Azure is generally available today. AWS and GCP are roadmap.

We do not claim coverage our connectors do not have. Here is exactly where the product stands today.

Microsoft Azure
Generally available
Entra ID · Managed identities · App registrations · Service principals · Guest users · PIM · ARM · GitHub OIDC
Amazon Web Services
Roadmap
Connector is a documented extension point. Not yet a coverage claim.
Google Cloud
Roadmap
Connector is a documented extension point. Not yet a coverage claim.

Validated to a documented 100,000-identity / 950,000-role-assignment baseline. Larger estates should be sized with us before onboarding.

Get started

Find the reach you never granted.

A scoped assessment against your own Azure tenant. Read-only, agentless, and nothing is written to your environment — ever.

Free forever — 1 subscription, 500 identities · 30-day trial unlocks everything · No credit card

Read-only access · No agents · No log ingestion · Azure generally available