Access Intelligence

Know what it can reach.Not what it was granted.

Access Intelligence resolves declared grants into effective access — through role trust, group membership, inline policy and credential — and turns it into a blast radius you can point at, with the evidence attached.

Availableeffective access, transitive reach, paths and blast radius (M7)Future capabilityoverprivilege from observed permission use

Problem

Declared access is the map. Effective access is the territory.

Identity stores show what an identity was granted. Few show what it can reach once grants compound across roles, accounts and environments.

Policies Compound

Roles assume roles, groups inherit grants and trust policies span accounts until no single policy editor shows the result

Paths Cross Boundaries

A key minted for staging, a runner trusted by production, a connected app installed in every tenant — invisible from inside any one account

Grants Outlive Purpose

Access remains after the project, the owner and the reason are gone, because revoking it needs evidence nobody has collected

How it works

Resolve. Measure. Explain.

Four things Access Intelligence does on the identity graph that a per-account policy view cannot.

Effective access

Effective access, not declared access

Trustivan follows grants across role trust, group membership and inline policy statements, and computes reach at read time from the edges connectors reported. The result is an upper bound: managed policy documents are not read, and Deny statements and conditions are not evaluated.

  • Every hop is explicit: which role, which permission, which credential carried it.
  • Declared grants and computed reach side by side, so widened access is visible, not assumed.
  • Current on every read, because a new trust relationship can widen reach without touching the identity itself.
Explore effective access for NHIs
Blast radius

Blast radius you can point at

A blast radius is not a score. It is the list of systems, datasets and environments an identity can reach right now — direct and transitive — ordered by what it would cost to lose them.

  • Direct and transitive reach, separated: what a credential opens versus what a role chain reaches from there.
  • Production and restricted data first, each with the path that makes it reachable.
  • Owner and recommendation attached, so the next step is a remediation a second person approves — not another meeting.
See blast radius for NHIs
Environment boundaries

Hidden machine-to-machine paths across environments

The riskiest paths rarely sit inside one account. They run from a development key, through a role trusted by production, into data nobody meant to expose.

  • Cross-account trust mapped as ASSUMES edges from the AWS connector, not footnotes in a policy document.
  • Transitive reach followed from the credential through every role it can assume to the resources behind it.
  • Environment labels are a future capability: no connector reports whether an account is development, staging or production.
Read the hidden M2M access use case
Evidence

Explainable, with evidence

Every access finding answers why, what, who, where, how and blast radius — with the connector sync record or ingested event that proves it. Where evidence is missing, the field says unknown.

Which identity, through which credential, can reach which resource — and who can change that today?

Why risk must be explainable
HighOrphaned identityLong-lived credential

Orphaned service identity with reachable production data

Why
Orphaned service account still holds active production credentials
What
svc-billing-export (service identity)
Who
Owner unknown — no owner tag and no assigned owner
Where
cloud account prod-core · region eu-west-1
How
Long-lived access key (age 611 days), still active, on a machine IAM user
Blast radius
2 production databases, 1 backup bucket, 4 downstream services
Recommendation
Assign owner, rotate to short-lived credential, scope role to export-only
Action
Propose remediation · assign owner · quarantine in platform
Evidence
AWS IAM sync 2026-08-19 · access-key metadata · owner tag absent
Evidence before claims — when evidence is missing, Trustivan shows unknown, never a fabricated score.Illustrative finding · sample environment

Capabilities

What Access Intelligence computes

Nine capabilities on the identity graph that discovery and ownership populate — seven computed today, two waiting on facts no connector collects.

Effective Permissions

Resolve an upper bound on what an identity can do from trust, group membership and inline policy statements

Permission Graph

Model every grant as an edge so access can be traversed, queried and explained instead of read policy by policy

Access Paths

Show every hop between an identity and a resource, and the connector-reported edge each hop relies on

Blast Radius

Enumerate the resources and systems within reach if this identity were compromised right now

Overprivilege

Future capability: comparing effective access with observed use needs permission-usage facts no connector collects

Dormant Access

Surface stale identities and inactive identities still holding an active credential — last use is reported by AWS, for roles

Environment Boundaries

Future capability: flagging reach across development, staging and production needs an environment no connector reports

Cross-Account Trust

Map AWS role trust between accounts as first-class ASSUMES relationships

Shared Credentials

Flag one credential shared between agents, so a single compromise is not mistaken for one identity’s problem

AvailableM7 · Phase 2

Effective access, reach and blast radius are available

Effective access (an upper bound), transitive reach, access paths, blast radius, cross-account trust and stale-access findings are built on the identity graph. Overprivilege and least-privilege analysis are a future capability: they need permission-usage facts nothing collects today.

See the full platform trajectory

See your effective access, not your policy text.

A demo walks through the permission graph, a blast radius and an explainable finding — on sample data or a scoped, read-only connector.

See what your identities can actually reach.

See how TRUSTIVAN connects identity, credential, access, agent and action context into one control plane.