Which five identities
should you look at today?
A deterministic, explainable risk score over 18 components, 16 of which score — no black box, no LLM — plus posture trends, classification-driven attack-surface insight and a 30-second executive read.
Explainable by construction
Every score traces back to its reasons.
Dormant privileged grants, SoD violations, shadow access through nested groups, peer-group deviation, terminated identities with live access — each weighted, each visible in the breakdown.
- 18 components, 16 of which score, tenant-tunable weights, 0–100. Two are shown and deliberately contribute nothing — how fresh our data is says nothing about how risky the person is, so stale reconciliation and an unmeasured peer group each state their count and their reason and add zero. A number you cannot defend is worse than a number you do not have
- Peer-group outliers computed against the median — one outlier can't drag the baseline
- Entitlements score too: which permissions carry the privileged spread, the dormant holders, the SoD exposure
- Can't fix it this quarter? Accept the risk — justification and expiry are mandatory, and it comes back when it lapses
- Detectors feed one advisor inbox with the fix attached
The 30-second read
The board asks one question. This screen answers it.
The executive dashboard turns the same live model into tiles, headlines and trend — privileged exposure, NHI posture, governance activity — with drill-down to the underlying evidence. Classification adds the attack-surface lens: which systems carry the most sensitive, least-governed permissions.
- Executive tiles with drill-down to evidence — no separate BI tool. Four board questions, and seven standing domains that are answered every time — including the ones that are green. A dashboard that only speaks when something is wrong cannot be used to say that nothing is
- The dashboard is built per role: the security team gets exactly six risk signals — privileged exposure, SoD, NHI posture, JIT coverage, PAM posture and the risk trend, which leads as a chart rather than a tile — and every one of them drills through to the people behind the number. A tile you may see but not open does not exist here
- Every permission auto-classified: framework, function, sensitivity
- Attack-surface view per system, unclassified high-use permissions first
See your risk surface on your own data.
A 30-minute kickoff connects your HR feed and one system — working POC the same day.
Bring your HR feed plus one system you trust us to read — that is all the kickoff needs. No NDA, no second call with a sales engineer, no procurement form.