One screen, and every question answered from the same data
These are the questions a security lead opens a control plane to ask. Each answer below is computed from the estate on this site — the counts, the matches and the figures — because a page asserting that the platform could answer them would be the weakest possible way to make the point.
15 questions, 14 of which the seeded estate currently has something to say about. A question with nothing to report is kept rather than hidden: "none" is an answer, and a view that only shows findings cannot be used to establish that something is absent.
The questions
- 6 of 7
Which identities belong to AI agents?
An agent is a machine identity that decides what to do next, which makes it the only kind that can surprise you.
- 3 of 7
Which have no owner?
An identity nobody is accountable for keeps working exactly as well as one somebody watches.
- 4 of 7
Which use static credentials?
A secret that does not expire is most of the risk in this module, and the list is the migration backlog.
- 3 of 7
Which credentials are about to expire?
Something stops working when they do, and the owner finds out from an incident rather than a calendar.
- 1 of 7
Which identities are dormant?
Not being used is not the same as not being able to. Dormant is a finding, not a resting state.
- 2 of 7
Which are administrators?
Administrative permission changes what everything else is allowed to do.
- 3 of 7
Which can access customer data?
The question a regulator asks first, and the one an inventory without data classification cannot answer.
- 1 of 7
Which can move money?
Financial permission held by something that authenticates unattended deserves its own list.
- 1 of 7
Which can create new identities?
An identity that can create identities and grant them roles can grant itself anything.
- none
Which can issue or read secrets?
Credential management is the permission that makes every other one recoverable by whoever holds it. Nothing in this estate has it, and that is the answer.
- 2 of 7
Which can move between cloud accounts?
A trust relationship is a path, and a path between accounts is how a contained incident stops being contained.
- 1 of 7
Which credentials are shared?
An action taken through a shared credential cannot be attributed to one consumer, which ends an investigation early.
- 4 of 7
Which workloads could stop holding a secret at all?
Every static credential here is a candidate for federation, which removes the thing that can be stolen rather than rotating it.
- 1 of 7
Which is behaving abnormally right now?
Measured against a baseline the platform established itself, not a threshold somebody guessed at during onboarding.
- 7 of 7
Which hold permissions they never use?
Granted and unused is the only least-privilege argument an owner cannot dispute.
And the last two
What happens if one of these is compromised, and can I stop it?
Those are the questions the other fourteen exist to make answerable, and neither is a list. Each identity carries the systems it reaches and the agents that depend on it, so containment can be judged before it is ordered rather than discovered afterwards.
The worst-scoring identity in the estate is Production Billing Service at 81, and across the whole estate 283 granted actions have not been used in ninety days — which is the least-privilege backlog stated as a number rather than as an adjective.