Identity risk
Entitlements, federation topology and machine identity in one model, so the role that quietly bridges two accounts stops being invisible.
human and machine identities modelled
What identity risk actually does
Entitlement graph
Who can assume what, from where, and what that grants once assumed.
Machine identity
Service principals, deploy identities and access keys, with last-use and blast radius.
Toxic combinations
Pairs of entitlements that are harmless apart and dangerous together, surfaced as one finding.
Factor coverage
Which populations are exempt from strong authentication, and what those exemptions reach.
See it working on demo data
- Human accounts, service principals, deploy identities and access keys sit on one entitlement graph.
- Toxic entitlement pairs are raised once, with both contributing grants shown together.
- Factor coverage shows which populations are exempt from strong authentication and what those exemptions reach.
Scroll the graph sideways to reach every stratum
Select any node to focus its one-hop neighbourhood, or filter by relationship type above.
Okta, Microsoft Entra ID and Ping are supported directly; anything with SCIM and a directory API can be modelled with the generic connector.
No. We model entitlements and metadata. Secrets are never read, and the secrets-manager connector reads lease telemetry only.
By blast radius and last use. An unused identity with wide reach ranks above a busy identity with narrow reach.
Put identity risk against your own estate
A four-week proof of value connects one cloud account, your DNS and your identity provider, and ends with a written readout. Lodemark stays read-only throughout.
Illustrative product data. Nothing on this site performs a live scan.