Who and whatcan reachyour data.
An investigation of every identity, human and machine, that can reach each class of sensitive data, and the standing excess an adversary inherits the moment one account falls.
Access rarely arrives all at once. It accumulates.
An adversary needs only one over-privileged account. We find it before they do.
Permissions accrete over years, granted for a project long finished, inherited from a role long changed, extended for a convenience long forgotten, until the map of who can reach what bears no resemblance to who should. And every standing permission is an inheritance waiting for an adversary, who needs to compromise only a single over-privileged account to acquire all that it can touch.
This review reconstructs the true access map, every human identity, every service account, and, increasingly, every AI agent, and surfaces the excess that least privilege would remove. In the age of autonomous agents, this last category is the most urgent and the least examined: an AI granted broad access for convenience is a blast radius nobody measured.
One account falls. Everything it can touch becomes reachable.
The meaningful access map is not the list of roles an administrator intended. It is the effective reach created by groups, nested permissions, service connections, tokens, and autonomous agents.
See the true access. Remove the standing excess.
The engagement connects technical permissions to real business need and gives each unnecessary route a safe path to closure.
The true access map
Every identity, human, service, and AI, that can reach each class of data.
Standing-excess exposed
The accreted permissions that least privilege would, and should, remove.
Agent access, examined
The new and urgent question of what your AI agents can reach.
A remediation path
A prioritised plan to close the excess without breaking what works.
AI agents are identities with authority—not merely tools.
An agent can inherit a user role, service token, connected application, and broad repository scope. The review treats that combined authority as a first-class access path.
From intended permissions to verified least privilege.
Every conclusion preserves business context: the goal is to remove unnecessary reach without interrupting the access legitimate work depends on.
Map
Reconstruct identities, roles, groups, service accounts, and agents.
Resolve
Connect every effective permission to the sensitive data it reaches.
Challenge
Test whether the access is required, inherited, dormant, or excessive.
Remediate
Remove standing excess with a sequenced, owner-approved plan.
A defensible access register and a safe path to reduce it.
Security receives the effective graph and prioritised excess. System owners receive clear changes, dependencies, and validation steps. Leadership receives a concise account of blast-radius reduction.
Discuss your access estateMap your real access before someone else does.
Including the AI agents nobody has examined yet.