The difference
Depth, not breadth.
Most tools in this category count how many logos they connect to. That number
does not help you, because reviews do not fail across four hundred applications
— they fail inside about ten.
So we go entitlement-deep on the systems where privilege actually accumulates:
Okta, Entra ID and on-prem Active Directory, Google Workspace, AWS, Azure and
GCP IAM, Salesforce, NetSuite, Workday, GitHub, Snowflake, Microsoft 365. Not
“connected” — we read the roles, the permission sets, the group
nesting and the local accounts that never touched SSO.
On-prem Active Directory is the clearest gap. It is where the
oldest service accounts live and where SaaS-only competitors structurally cannot
reach. We read it through one lightweight read-only collector per site.
What we connect to, and how deep
Spider and web — the API key. Sticky, spread everywhere, threading
across systems that were never meant to touch. You find the web long before
you find the spider.