Start at the asset.
See everyone who can reach it.
Premium Every other view in the product runs identity → resource. AuditMap runs it backwards. Name the thing you actually care about protecting — the clinical storage account, the claims database, the model endpoint — and get the complete set of identities that can reach it.
Two directions. Two different jobs.
Both questions run on the same canonical graph. They are not the same question, and answering one does not answer the other.
Identity → Resource
“This service principal looks dangerous. What can it get to?”
The investigation direction. You have a suspect and you need its reach. Used during triage, offboarding, and incident response.
Resource → Identity
“This database holds cardholder data. Who can reach it?”
The assurance direction. You have an asset you are accountable for and you need the complete population that can touch it. Used during audit, certification, and design review.
You cannot answer it
by reading the resource.
Look at a storage account in the portal and you will see the assignments made at it. That is a small and misleading fraction of who can reach it.
The rest arrive from above — subscription Owners, resource-group Contributors, management-group inheritance — and from sideways: group nesting, PIM-eligible activation, federated credentials whose subject claim is broader than anyone intended, and non-human identities that hold the role on behalf of a pipeline.
Assembling that population by hand is a multi-day exercise that is stale the moment it finishes. AuditMap computes it continuously, and shows the path for every identity in the set.
Illustrative path taxonomy. Only the first row is visible from the resource itself.
The answer, and the proof.
The complete reach set
Every identity — human, service principal, managed identity, workload, AI agent — that can reach the asset, with inheritance and nesting fully resolved.
The path for each one
Not just membership in the set, but how each identity got there. Direct, inherited, nested, eligible, or federated — attributed per identity.
Privilege, not just presence
Read differs from write differs from ownership. The map separates who can see the asset from who can exfiltrate, alter, or delete it.
Classification-aware
Reach into a PHI or PCI zone is a materially different finding from reach into a scratch environment. Data Trust Zones supply the anchor.
Audit-ready output
“Show me everyone who could reach cardholder data last quarter” is a question you can now answer with a document rather than a project.
Honest about blind spots
Where classification is undefined or a connector cannot see, the map says so. Unknown renders as unknown — never as safe.
AuditMap is enabled per account.
It is not bundled into a plan tier. AuditMap is granted per organization by the AuditGraph sales team, so scope, data-classification setup, and the reachability configuration it depends on are agreed before it is switched on.
That is deliberate: a resource-first exposure map is only as honest as the Data Trust Zone definitions underneath it. Turning it on without that groundwork produces a confident-looking map of the wrong thing.
Pick one asset you are accountable for.
Name the storage account, database, or dataset that would hurt most. The assessment answers who can reach it — against your tenant, not a demo.
Free forever on a bounded estate · 30-day trial unlocks everything · No credit card
Read-only access · No agents · No log ingestion · Azure generally available