Least privilege for the identitiesthat never log off.
Posture for non-human identities is not a checklist of settings. It is the gap between what an identity can reach and who answers for it — across accounts, environments and the trust relationships that quietly connect them.
AvailableUsed vs granted: future capabilityM4 · Understand Risk
Declared policy is the claim · effective access is the evidence
Cloudprod-coreAdminrole: deploy-admin
Repositoriesplatform-orgWriteGitHub App
Clusterprod-paymentsEditrole binding
MCP toolmcp://ticketsMCPdeclared entitlement
Other accountanalytics-prodReadassumes role
Vaultapprole/paymentsPolicypolicy name
deploy-agentowner: Platform team
Illustrative access lineage · sample environment · effective access is an upper bound
Posture signals
Too much. Too long. Too exposed.
Three questions posture has to answer for every machine identity and agent before a misconfiguration becomes a path.
Overprivilege
Privileged and high-impact access, broad permissions and escalation capability — worst on identities nobody owns
Dormant access
Stale identities that still hold credentials that would work today
Exposed & expiring
Credentials reported exposed, past rotation or near expiry, on the identities that hold them
How it works
Computed on the graph, judged by policy
Roles, trust policies, group memberships and inline policy statements combine into effective access. Posture policies turn that reach, the credentials and the ownership into findings.
Effective access
Effective access is the evidence. Policy turns it into a finding.
Trustivan resolves what an identity can reach across roles, trust policies and cross-account assumption — an upper bound, since managed policy documents are not read and Deny and conditions are not evaluated. Comparing that with what the identity actually exercised needs per-grant usage no provider reports, so right-sizing is a future capability and unused stays unknown.
Used versus granted is a future capability: nothing collects per-grant use today.
Privileged and high-impact grants ranked by what they reach, not by how they are spelled.
Nothing recommended for removal on a guess: unknown is shown as unknown.
Permissions used vs grantedLast 90 days · 5 highest-gap identities
Used
Granted, never used
prod-platform-admin212wildcard on 2 services
deploy-agent92
svc-billing-export15
etl-runner14right-sized
support-copilot41inherits tool permissions
Illustrates a future capability · per-grant usage is not collected today
Environment boundaries
The path from staging to production is usually an identity
Shared service accounts and permissive trust policies connect environments that are supposed to be isolated. Trustivan follows trust and permission paths on the graph, so a non-production identity whose effective access reaches a production resource is visible — with the edge that makes the crossing possible.
Environment from the connector, not from account names: the account or cluster the connector covers.
Paths, not guesses: every hop is an edge a connector reported.
Tenant and account trust drawn from the trust policy that grants it.
How the identity proves itself matters as much as what it can do
Keys past rotation, credentials near expiry, expired credentials still in use, exposures that were never cleaned up, credentials shared between agents — each lets an attacker become the identity rather than exploit it. Each is a posture policy, raised per identity with its evidence.
Policies per credential, each with the identities affected and the owner who answers.
Agents included: shared agent credentials and entitled tools that reach high-impact resources.
Findings route to owners with the remediation to propose, not just the failed check.
Available
Posture findingsFailing policies by affected identities
1Exposed credential still present3 credentials · reported through ingestionCriticalExposureOpen