Pilot observations

What the graph found,
stated carefully.

These are observations from pilot discovery runs against real estates. Every organization, subscription, resource and identity name has been removed. So has every outcome claim — because proving that a fix reduced risk requires a capability we have not shipped yet, and we are not going to imply otherwise.

What these are
  • Measurements taken during real pilot discovery runs
  • Fully anonymized — no organization, person, or resource identifiers
  • Patterns the architecture makes likely, confirmed empirically
  • Numbers we can trace back to a specific run
What these are not
  • Customer success stories — we are not naming customers
  • Outcome claims — we cannot yet prove risk reduction
  • Testimonials or endorsements
  • A representative sample — pilots are few and self-selected
Observation 01 Measured

Most of the identity count was not theirs.

A pilot tenant enumerated 6,731 identities. After scoping to the identities the organization actually owns and is accountable for, the number was 1,150.

6,731 raw enumerated
1,150 customer-owned

Why the gap exists

A Microsoft tenant contains a large population of first-party and platform-managed service principals — identities Microsoft provisions and controls, not ones the customer created or can govern. They are real identities. They are not the customer's attack surface.

Why it matters commercially

A vendor priced per identity, or one reporting a headline count, has a direct incentive not to make this distinction. Reporting 6,731 is more impressive and less true. It also buries the 1,150 that someone actually has to do something about.

This is why AuditGraph is priced per subscription rather than per identity, and why platform-managed identities are excluded from customer-facing counts by default rather than as an option someone has to find.

Observation 02 Measured

160 AI agents, with computed reach.

A pilot estate contained 160 AI agent identities. Their reach to classified data was computed through the scope hierarchy rather than assumed from what the agents were nominally for.

  1. Agent SPN Identified from pattern library
  2. Assignments Every role actually held
  3. Scope cascade Resolved, not transcribed
  4. Reach set Resources genuinely reachable
  5. Classified? Against Data Trust Zones
Computed per agent — the same path used for any non-human identity

Why "computed, not assumed" is the whole point

The intuitive approach is to reason from purpose: a documentation agent handles documents, so it probably reaches document storage. That reasoning produces a confident answer that owes nothing to the configuration.

What resolution changes

An agent granted a role at a resource group inherits everything in it. Its reach is determined by where the assignment was made, not by what the agent was built to do — and those two facts are frequently unrelated.

Observation 03 Pattern

Inheritance is where the reach hides.

Across pilot runs, the identities with the largest reach were rarely the ones with the most role assignments. They were the ones with a single assignment made at a high scope.

Looks small

One assignment. One line in an access review. A role named in a way that sounds bounded. Nothing about the record suggests scale.

1 × Owner @ /subscriptions/{id}

Is not small

Every resource group in that subscription. Every resource in those groups. Including the ones classified as holding regulated data — which appear nowhere in the assignment.

→ the entire subscription tree

The reason this pattern survives access reviews is that reviews operate on the assignment record, and the assignment record is honest — it really is one line. The reach is not in the record. It is in the hierarchy the record points at.

What is missing from this page

There are no outcome numbers here. On purpose.

The case study you would expect — "organization reduced identity risk by N%" — requires recomputing reachability with a remediation applied and comparing it to the original. That is the counterfactual engine, and it is on the roadmap rather than in the product.

Until it ships, any percentage we published would be a projection dressed as a measurement. Every competitor page you have read this month contains that number. We would rather you notice that ours does not.

When the capability ships, this page will carry measured before-and-after figures, and they will be labeled as measured — which will mean something, because we did not spend the intervening period claiming them.

Get started

The next observation could be yours.

A scoped, read-only pilot against a subscription you choose. Anonymized findings stay yours — nothing appears on this page without your explicit approval.

Free forever on a bounded estate · 30-day trial unlocks everything · No credit card

Read-only access · No agents · No log ingestion · Azure generally available