Nobody owns this account

Every service account, key and token gets a name against it.

Govern and Posture, non-human identity governance

Non-human accounts sorted by last sign-in, with the dormant one that holds Directory.ReadWrite.All and has no owner
01Where it goes wrong

The deploy account was created for a migration two years ago. The engineer who made it has left. It still holds Directory.ReadWrite.All.

For the platform team that inherited them.

02What the industry reports

What the industry reports

  • 82 to 1machine identities to human identities inside the average organizationCyberArk 2025 Identity Security Landscape
  • 44%growth in non-human identities in a single yearEntro Labs, H1 2025
  • 87%of the identities holding unused sensitive permissions are machinesSonrai, enterprise cloud tenants
03What changes

What changes

Classification comes from behavior

Service, break-glass, shared mailbox and resource accounts are told apart by how they are used, whatever they were named.

They sit in the same graph as the people

A dormant deploy account holding Global Administrator is comparable to a person holding it, because reach is measured the same way for both.

Dormant comes with a date

Last sign-in travels with the account. An account with no sign-in in four hundred days is a different conversation from one running every hour.

04What it covers

Everything this covers.

Five accounts across four systems resolving to one person, each link naming its match method
01Discovery and inventory
01

Discovery and inventory

  • Every service account, key and token in the directory and the applications
  • Accounts matched automatically, and linked by hand where they are not
  • Re-classified on every sync, one account at a time
Five accounts across four systems resolving to one person, each link naming its match method
02

Classification and ownership

  • Service, break-glass, shared mailbox and resource accounts told apart
  • Classification from how the account behaves
Accounts broken down by classification, with the naming rule that classified one service account
03

Entitlements and reach

  • Non-human identities sit in the same graph as the people
  • Blast radius comparable between a person and a service account
  • A last sign-in date on every account, human or not
What one compromised account reaches, drawn as rings: its groups and roles, then the applications behind them
05What does the work

The parts of the product this uses.

Identity associationsFive accounts across four systems resolve to one person
Identity graphFollow the path from any person to everything they can reach
Blast radiusSee everything one compromised account can reach
06On your own tenant

See it on your own tenant.

Book a demo

Connect your directory and see findings the same day.

The graph behind it