Industries · Technology & SaaS

Machine identities outnumber humans, by a lot

Software companies have the most extreme non-human identity ratio of any sector and the least tolerance for a breach narrative, because their customers are running the same security review on them that they run on their own vendors.

The question behind the budget

“What could a compromised pipeline credential reach in production?”

Regulated data at stake Customer data · source code · production secrets · tenant isolation boundaries
Frameworks you evidence against
SOC 2 Type IIISO 27001GDPRCustomer security reviews
What makes it different here

How the risk takes shape.

01

The pipeline is the privileged user

CI/CD identities deploy to production by design. They hold more effective authority than most engineers, are shared across teams, and are governed by repository permissions rather than identity governance.

02

OIDC subject claims are the new secret

Workload federation removed long-lived secrets and replaced them with trust conditions. A subject claim scoped to a whole organization rather than one repository and branch is an open door that looks like a best practice.

03

Your customers audit your identities

Enterprise security reviews increasingly ask about non-human identity governance directly. Being able to answer with a graph rather than a policy document shortens the cycle.

Recurring patterns

What we look for first.

These are structural patterns this operating model tends to produce — not findings from any particular organization. They are where an assessment starts, because the architecture makes them likely.

Whether they are present in your estate is an empirical question. That is the point of looking.

  • GitHub Actions OIDC credentials with organization-wide rather than repository-scoped subject claims
  • Terraform and IaC identities holding subscription Owner
  • Ephemeral environments provisioning identities that outlive the environment
  • Internal tooling service principals with production data-plane access
  • AI coding and review agents granted repository and cloud access with no expiry
What an assessment produces

Evidence, in your framework's language.

The reach set

Every identity that can reach your customer data, with the path each one takes — direct, inherited, nested, eligible or federated.

Control-mapped findings

Findings tied to the control families you evidence against — SOC 2 Type II and ISO 27001 — with the underlying facts attached.

One ranked decision

Not a backlog. The single highest-consequence move, with its projected outcome labeled as projected and its evidence trail intact.

Get started

Test these patterns against your own estate.

A scoped, read-only assessment on a subscription you choose. We answer the question above with your numbers, and tell you plainly where we could not determine something.

Free forever on a bounded estate · 30-day trial unlocks everything · No credit card

Read-only access · No agents · No log ingestion · Azure generally available