IAM
Privilege Discovery
Privilege Discovery scans cloud accounts, directories, and target infrastructure to inventory who has access to what. Each discovered privilege is classified by sensitivity (read, write, admin, secrets-bearing) and assigned a 0-100 risk score reflecting blast radius, recency of use, and exposure to the public internet.
BFS traversal of the identity graph surfaces escalation paths -- for example, a support user who can assume a role that manages production IAM. Findings feed directly into access review campaigns and role mining suggestions.
Key Configuration
- Scan targets (cloud accounts, directories, session targets)
- Scan interval (daily, weekly, on-demand)
- Risk score weights (blast radius, staleness, exposure)
- Escalation path depth limit