NHI risk

Risk you can explain.Evidence you can audit.

A score without evidence is worse than no score. Trustivan describes machine-identity risk with named factors a human can trace to a source, explains every finding, and shows unknown when the evidence is not there.

Availableexplainable risk · Understand Risk · M4

Risk context with evidence available · every factor labelled by status

HighOrphaned identityLong-lived credential

Orphaned service identity with reachable production data

Why
Orphaned service account still holds active production credentials
What
svc-billing-export (service identity)
Who
Owner unknown — no owner tag and no assigned owner
Where
cloud account prod-core · region eu-west-1
How
Long-lived access key (age 611 days), still active, on a machine IAM user
Blast radius
2 production databases, 1 backup bucket, 4 downstream services
Recommendation
Assign owner, rotate to short-lived credential, scope role to export-only
Action
Propose remediation · assign owner · quarantine in platform
Evidence
AWS IAM sync 2026-08-19 · access-key metadata · owner tag absent
Evidence before claims — when evidence is missing, Trustivan shows unknown, never a fabricated score.Illustrative finding · sample environment

The problem

Opaque scores fail three audiences at once.

A risk score is a compression of evidence. Hide the evidence and the score stops being useful to the people who are supposed to act on it.

Analysts stop trusting

One false critical discounts every critical that follows it

Owners cannot act

A score of 87 has nothing to fix; five named factors have five fixes

Nobody can audit

When the model changes, yesterday’s comparisons silently break

Framework

Named factors. Each one traceable.

An explainable model, not a formula to trust blindly. Each factor adds a stated contribution with the evidence behind it, and a factor with no evidence stays unknown.

Risk =Privilege+Reachability+Exposure+Credential risk+Ownership & lifecycle+Observed activity

Available

Privilege

What could it do if it tried?

Evidence

  • Effective permissions
  • Role chains
  • Escalation capability
Available

Reachability

What high-impact resources can it reach?

Evidence

  • Transitive reach
  • Resource impact class
Available

Exposure

Has the credential been reported as leaked?

Evidence

  • Ingested exposure reports
  • Public visibility
Available

Credential risk

What kind of credential is it, and how old?

Evidence

  • Credential type
  • Age & rotation
  • Expiry
Available

Ownership & lifecycle

Is anyone still responsible for it?

Evidence

  • Ownership confidence
  • Lifecycle state
  • Last use, where reported
Available

Observed activity

Has it acted, and could anyone attribute the action?

Evidence

  • Ingested activity
  • Unattributed access
Not built

Behavioral anomaly

Is it doing something new?

Evidence

  • No behavioural baseline is kept, by design
unknown

Unknown instead of fabricated

When a factor has no evidence it is displayed as unknown — never folded into a number that looks confident.

Last usedunknown — Vault does not report last use for this AppRoleResolve: submit activity through the ingestion API

Findings

Every finding answers a responder’s questions.

A responder should be able to act without opening another tool. If a question cannot be answered yet, the finding says so instead of guessing.

Why

Name the condition that makes this a finding, in one sentence

What

Identify the identity or credential the finding is about

Who

Show the accountable owner — or state plainly that nobody is

Where

Locate the identity: the connector and scope it was discovered in

How

Show last use where the provider reports it, and activity you have ingested

Reach

Show what the identity can reach, resolved on the identity graph

Recommendation

State the recommended action and how to remediate

Action

Offer what the platform can do: assign an owner, quarantine, or propose a change for approval

Evidence

Attach the provider snapshots and records behind it, with timestamps

Action

Act from the finding, not from another tool.

Recommendation and action are part of the finding. The recommended change comes first, a second person approves anything that would touch a provider, and every action is labelled by what is available today and what is not.

  • Assign an owner and quarantine in the platform are available now, written to the audit trail.
  • Rotate, scope and revoke at a provider are proposed and approved today; executing them is a future capability.
  • Ticket and notification records are available; SIEM and ITSM integration are not built yet.

Availableassign owner · quarantine in platform · ticket recorded

Future capabilityrotate · scope · revoke at the provider

Explore NHI governance
HighUnowned identity

svc-billing-exportlong-lived key · reachable production data

  1. Assign ownerAssign the team accountable for it; the change is written to the audit trailevidence: owner record · actor · time
    Available
  2. Quarantine in platformMark the identity quarantined; the runtime gate then denies every action it attemptsevidence: lifecycle change · actor · time
    Available
  3. Record a ticketRecord a ticket or an owner notification against the finding; no ITSM or SIEM integration yetevidence: ticket record · actor · time
    Available
  4. Rotate credentialReplace the 611-day access key at the provider — proposal and second-person approval are recorded today; execution is notevidence: proposal · approval · no provider executor
    Future capability
  5. Scope roleReduce export-admin at the provider; which permissions are used is not observedevidence: proposal · effective access re-evaluated
    Future capability
  6. Revoke at providerDisable the key at AWS when compromise is suspectedevidence: proposal · approval · no provider executor
    Future capability
Every action is written to the audit trail with actor, time and evidenceIllustrative · sample environment

See one explainable finding on your own identities.

A demo opens a finding end to end: the factors, the evidence behind each and the action available from the same screen.