One graph.
Eight ways to ask it a question.
AuditGraph is not a collection of tools that happen to share a login. Every surface renders the same canonical facts, produced once, by one owner. If two screens disagree, that is a defect — not a perspective.
- Human Employee, admin, contractor
- Service Principal App registration
- Managed Identity System or user-assigned
- AI Agent A subtype of NHI
- Model Cognitive Services
- Classified Data PHI · PCI · PII
Connect, discover, decide.
- 01
Grant read-only access
Microsoft Graph and ARM, read scopes only. No agent is installed. No write permission is ever requested — the product is architecturally incapable of changing your tenant.
- 02
Discovery builds the graph
Every identity across every class — human, service principal, managed identity, workload, CI/CD, PAT, OAuth app, AI agent — with role assignments, scopes, federated credentials, and PIM state.
- 03
Engines compute consequence
Reachability, blast radius, attack paths, and data exposure — derived from configuration, not inferred from behavior. Each identity receives a lineage verdict.
- 04
One ranked decision
Ranked by business consequence — never by population or node count — with the evidence trail attached, ready to hand to an auditor.
Every capability, with honest maturity.
Maturity below is copied from our internal feature catalog, not written for this page. GA ships and reconciles. Beta is functional and hardening. Alpha is usable but not yet trustworthy for a buying decision. We would rather you know.
Decision Center
What is the biggest identity risk to the business today, and what is the one move?
- Executive Summary Beta
The one-minute decision story. One decision, above the fold.
- Risk Center Beta
The ranked risk landscape, with drill-through to evidence.
- Risk Reduction Planner Beta
Programs and their projected outcomes — tracked as reduction, not tasks.
- Argus Beta
Natural-language query over the graph. Answers reconcile to canonical facts or it declines to answer.
Identity Security
Who and what exists, what do they hold, and when was it last used?
- Identity Estate — All / Human / NHI / AI GA
The discovered estate by class. The substrate everything else is computed from.
- Identity Investigation GA
The canonical per-identity investigation: story, one recommendation, evidence.
- Privileged Access Beta
Standing privilege, PIM eligibility, and activation reality.
- Identity Hygiene Beta
Credential age, expiry, secret and certificate posture.
Investigations
How would an attacker get from here to something that matters?
- Identity Graph GA
Relationships and reachability. The moat and the evidence.
- Attack Simulator GA
Attack-path and blast-radius analysis, computed before exploitation.
Governance
Where is privilege excessive, and who signs off on reducing it?
- Role Mining / Role Optimization Beta
Find and reduce excess and standing privilege at scale.
- Entitlements Beta
What an identity truly holds once scopes resolve.
- Toxic Access Beta
Privilege combinations that enable escalation when held together.
- Access Reviews Beta
Reviewer-driven certification with a defensible trail.
Data Security
Who can reach our regulated data, and by what path?
- AuditMap Premium
The resource-first exposure map. Start at the asset, see everything that reaches it.
- Data Trust Zones Beta
PHI / PCI / PII classification — the value anchor every exposure number depends on.
- Data Reachability Beta
Which identities reach which classified data. The core business-risk link.
AI Security
What AI is running in our tenant, and what can it reach?
- AI Findings Beta
AI-identity risk surfaced as identity risk, on the same graph.
- AI Runtime Alpha
The AI-identity runtime surface — the fastest-growing identity class.
- Model Registry Alpha
Inventory of models and AI workloads discovered in the tenant.
- Supply Chain Alpha
Federation and provenance trust for AI and non-human identities.
Compliance
Can we prove this to an auditor?
- Compliance Posture Beta
Framework-by-framework rollup per control family.
- Compliance Evidence Beta
Evidence-first control posture tied to identity facts.
- Auditor Pack Beta
The artifact you hand to an auditor, reconciled to the same canonical numbers.
Operations
Is what I am looking at fresh, and what changed?
- Findings Beta
The operational backlog where investigation meets action.
- Drift Analysis Beta
Change between snapshots. Requires at least two — and says so when it has one.
- Operations Center Beta
Discovery and producer health. Freshness you can verify rather than assume.
The honest list.
- Prove reduction. Recomputing reachability with a remediation applied — the counterfactual engine — is on the roadmap. Until it ships, we show projected outcomes labeled as projected, never as measured.
- AWS and GCP discovery. Both are documented extension points with stub connectors. Azure is the generally available provider.
- Owner inference. We do not guess who owns an identity. Unowned identities display as unowned.
- Per-object event history. Where we do not model an event timeline, the timeline is empty rather than filled with something plausible.
- WCAG AA certification. The product is keyboard-operable and theme-aware; a formal audit and VPAT are pending.
This list lives at Trust → Known limitations and is maintained alongside the product, not the marketing.
Start with the question you cannot answer today.
A scoped assessment against your own Azure tenant. Read-only, agentless, and nothing is written to your environment — ever.
Free forever on a bounded estate · 30-day trial unlocks everything · No credit card
Read-only access · No agents · No log ingestion · Azure generally available