Skip to content
Data Access Review

Who and whatcan reachyour data.

An investigation of every identity, human and machine, that can reach each class of sensitive data, and the standing excess an adversary inherits the moment one account falls.

Effective access mapExcess path isolated
Identity plane
HumanFinance analyst
Expected
ServiceReporting connector
Inherited
AI agentReconciliation copilot
Excess
Data plane
Customer recordsRestricted
Financial modelsConfidential
Acquisition workspaceCritical
Identity resolvedPermission inheritedStanding excess confirmed
Quiet vulnerability

Access rarely arrives all at once. It accumulates.

An adversary needs only one over-privileged account. We find it before they do.

Permissions accrete over years, granted for a project long finished, inherited from a role long changed, extended for a convenience long forgotten, until the map of who can reach what bears no resemblance to who should. And every standing permission is an inheritance waiting for an adversary, who needs to compromise only a single over-privileged account to acquire all that it can touch.

This review reconstructs the true access map, every human identity, every service account, and, increasingly, every AI agent, and surfaces the excess that least privilege would remove. In the age of autonomous agents, this last category is the most urgent and the least examined: an AI granted broad access for convenience is a blast radius nobody measured.

Inherited blast radius

One account falls. Everything it can touch becomes reachable.

The meaningful access map is not the list of roles an administrator intended. It is the effective reach created by groups, nested permissions, service connections, tokens, and autonomous agents.

Compromise simulationEffective reach reconstructed
Initial identityFinance analystSession compromised
Inherited reachCRM exportCustomer dataShared driveBoard materialAI workspaceAcquisition data
One credentialThree sensitive destinations
What the review includes

See the true access. Remove the standing excess.

The engagement connects technical permissions to real business need and gives each unnecessary route a safe path to closure.

Access evidenceInvestigated

The true access map

Every identity, human, service, and AI, that can reach each class of data.

Analyst outputACCESS GRAPH
Least privilegeInvestigated

Standing-excess exposed

The accreted permissions that least privilege would, and should, remove.

Analyst outputEXCESS REGISTER
Agent authorityInvestigated

Agent access, examined

The new and urgent question of what your AI agents can reach.

Analyst outputAGENT SCOPE
Closure pathSequenced

A remediation path

A prioritised plan to close the excess without breaking what works.

Analyst outputREMEDIATION PLAN
Agent access

AI agents are identities with authority—not merely tools.

An agent can inherit a user role, service token, connected application, and broad repository scope. The review treats that combined authority as a first-class access path.

IdentityWho or what invokes the agentAuthorityRoles, tokens, and inherited connectorsReachSensitive information available to act upon
Agent authority modelHuman review required
PrincipalFinance team
AgentReconciliation AI
Effective reachBroad drive scope
Expected scope2 foldersEffective scope19 folders
Standing excessReduce before deployment
Review method

From intended permissions to verified least privilege.

Every conclusion preserves business context: the goal is to remove unnecessary reach without interrupting the access legitimate work depends on.

Map

Map

Reconstruct identities, roles, groups, service accounts, and agents.

Resolve

Resolve

Connect every effective permission to the sensitive data it reaches.

Challenge

Challenge

Test whether the access is required, inherited, dormant, or excessive.

Remediate

Remediate

Remove standing excess with a sequenced, owner-approved plan.

Engagement output

A defensible access register and a safe path to reduce it.

Security receives the effective graph and prioritised excess. System owners receive clear changes, dependencies, and validation steps. Leadership receives a concise account of blast-radius reduction.

Discuss your access estate
Standing-access registerAnalyst validated
Identities mapped184Excess routes23Priority closures07
AI agent with broad repository roleCriticalDormant project group retained accessHighService token without current ownerReview
Map · challenge · remediateOwner-ready
Confidential review

Map your real access before someone else does.

Including the AI agents nobody has examined yet.