Identity Security Graph · Human · Non-Human · AI

See every identity.
Understand every risk.

AuditGraph reveals what every human, non-human, and AI identity can access, reach, and impact — derived from your cloud architecture, not your logs.

Free forever up to 2 subscriptions and 500 identities · 30-day trial unlocks every feature · No credit card · See what's included

  • Agentless
  • Read-only — never writes to your tenant
  • No log ingestion
  • Architecture-derived
The chain that matters

One graph, all the way down.

When a credential is compromised, the incident question is always the same: what is the chain from that credential to the data we lost? That chain crosses humans, non-humans, AI agents, models, and datasets. Most tools see one tier of it.

  1. Human Employee, admin, contractor
  2. Service Principal App registration
  3. Managed Identity System or user-assigned
  4. AI Agent A subtype of NHI
  5. Model Cognitive Services
  6. Classified Data PHI · PCI · PII
Every edge is a verified RBAC, OIDC trust, or data-classification relationship — read from your tenant's configuration. Patent provisional filed June 2026.
Most identity products see
User → Role → Resource

Accurate. Also the part you could already query yourself.

AuditGraph sees
Human → SPN → MI → AI Agent → Model → Dataset

The full authority path — including the tiers that have no owner today.

The problem

Every enterprise can list its identities.
Almost none can say which ones matter.

The market stops at truth: a list of principals, roles, permissions, misconfigurations, graph edges. All accurate — and all irrelevant to the person who has sixty seconds and a board meeting.

Truth and relevance are different properties. Detection is commoditized. The decision is the moat.

The tiers nobody owns

SailPoint stops at humans. CIEM stops at roles. NHI vendors stop at service accounts. AI security tools stop at runtime. Each covers one tier; none connects the chain.

Log-based tools miss static risk

An identity that has never signed in produces no telemetry — and can still hold Owner on a production subscription. Absence of activity is not absence of authority.

Non-human identities outnumber humans, and nobody is counting

Service principals, managed identities, workload and CI/CD identities, PATs, OAuth apps, AI agents. They accumulate permissions and rarely lose them.

Counts are not consequences

"You have 4,000 identities" is not a decision. "This one reaches regulated data and three people can assume it" is.

The approach

We read your architecture.
Not your logs.

Roughly 70% of organizations do not run the logging a behavior-based product depends on. AuditGraph derives risk from what is already there — role assignments, PIM, federated credentials, RBAC scopes, ARM, GitHub OIDC, network configuration.

Business-first

The headline is the business condition, never the role name. The role is how we prove it; the consequence is what we say.

Every number has provenance

Each value carries its basis — measured, computed, projected, estimated, attested, or unknown. A value without a basis does not render.

Unknown is a real answer

Absence is never painted as safety, never coerced to zero, never shown green. "We cannot see this" is a finding, not a gap to fill.

Deterministic, not generative

No language model sits in any reasoning, ranking, or narration path. Argus formats conclusions the engines reached. It cannot improvise.

On scoring

There is no AuditGraph risk score.
That is deliberate.

A single 0–10 number tells a CISO nothing they can act on and nothing they can defend to an auditor. Worse, it hides its own arithmetic — and a score you cannot decompose is a score you cannot argue with.

AuditGraph retired numeric severity scoring entirely. In its place: bands derived from checkable facts — the privilege tier an identity actually holds, the reach that privilege actually grants, the governance controls that are actually absent. Every band decomposes back to the assignments that produced it.

When your auditor asks where a rating came from, the answer is a scope string and a role definition — not a weighting we chose.

Lineage verdicts

Every identity gets a verdict.

Static association analysis assigns each identity in your tenant one of nine verdicts — continuously, with no dependency on sign-in telemetry.

Non-human identities default to risky-until-proven. On an NHI, the absence of a risk signal is itself a signal — never a neutral gap.

  • ORPHANED Parent resource is gone. Role assignments are still live.
  • GHOST_MSI System-assigned managed identity whose compute no longer exists.
  • AT_RISK Meaningful reach combined with weak or absent governance.
  • FEDERATED_MISCONFIGURED A federated credential subject claim broad enough to let unintended principals assume this identity.
  • STALE Provisioned, still privileged, no current association.
  • PAT_GOVERNANCE_RISK Active personal access tokens with no expiry, bypassing Entra ID token lifecycle governance.
  • UNUSED Exists and is entitled, but no use has been established.
  • NEEDS_REVIEW Something about this identity requires a human decision.
  • HEALTHY Well-scoped, governed, acceptable reach.
Coverage, stated honestly

Azure is generally available.
The rest is roadmap.

We do not claim coverage our connectors do not have. Here is exactly where the product stands today.

Microsoft Azure Generally available

Entra ID · Managed identities · App registrations · Service principals · Guest users · PIM · ARM · GitHub OIDC

Amazon Web Services Roadmap

Connector is a documented extension point. Not yet a coverage claim.

Google Cloud Roadmap

Connector is a documented extension point. Not yet a coverage claim.

Validated to a documented 100,000-identity / 950,000-role-assignment baseline. Larger estates should be sized with us before onboarding.

Get started

Start with the question you cannot answer today.

A scoped assessment against your own Azure tenant. Read-only, agentless, and nothing is written to your environment — ever.

Free forever on a bounded estate · 30-day trial unlocks everything · No credit card

Read-only access · No agents · No log ingestion · Azure generally available