Know every identity you have — human, machine and AI. Live in an hour.

Your identity provider governs the front door. Amberlock finds what is behind it, ranks what to fix, and proves it was fixed.

Read-only, OAuth in minutes. First findings within the hour.

An AI agent identity, drawn as a butterfly sealed in amber
Butterfly — the AI agent. Newly emerged, moves fast, and looks more fragile than it is. Most are running on a human’s credentials, which is why your directory counts them as that human.

The gap

You already own an identity provider. It cannot see this.

An employee identity, drawn as an ant sealed in amber

Ant — the employee. A colony: ordered, countable, and mapped to an org chart. The one population your directory already tracks well.

Your identity provider

Governs the front door.

Okta and Entra do this part well. They authenticate people, assign applications, and record the joiner–mover–leaver events as they happen. The front door is genuinely closed. Nothing below is an argument for replacing it.

  • Who has an account
  • Which apps they are assigned
  • Who left last month
A service account, drawn as a scorpion sealed in amber

Scorpion — the service account. Ancient, over-privileged, still venomous. Real scorpions turn up in real amber, which makes this the most literally accurate specimen in the set.

What it cannot see

Everything behind that door.

Your identity provider knows someone can open Salesforce. It does not know they hold the admin role inside it, that the NetSuite account was created outside SSO, or that a service account in on-prem Active Directory has held domain admin since 2014. Nobody provisioned it, so nobody governs it.

  • Permissions inside the app
  • Accounts created outside SSO
  • Service accounts, keys, AI agents
  • Whether revoked access actually went
An orphaned account, drawn as an empty air bubble sealed in amber

An empty air bubble — the orphaned account. Nobody home, and nobody left to ask. The only specimen in the set with no creature in it, which is the point.

What that costs you

Your auditor samples exactly that.

Reviewers certify application names, because application names are all they are shown. The permissions inside go unexamined for four quarters — until an auditor pulls a sample, finds an account nobody owns, and asks who approved it. That is the meeting you are preparing for.

  • 40–120 hours a quarter, by hand
  • Proof a review happened — not that access went
  • Findings you meet first in the auditor’s sample

Your compliance platform tracks that a review happened.

It does not see app-local entitlements, and it cannot verify the access actually disappeared. Drata is review-only by its own documentation; Vanta markets remediation workflows. Either way, what you hold is a record of the process, not proof of the outcome.

Amberlock performs the review — down to the entitlement, across on-prem Active Directory as well as SaaS — and pushes the evidence into the platform you already own. An item closes only when a re-scan confirms the access is gone.

How the evidence works

The taxonomy

What’s in your amber

Eight identity types, eight findings. Amber preserves a thing perfectly while making it invisible and inert — which is exactly what happened to the account somebody created in 2014 for a print server.

  • An employee identity, drawn as an ant sealed in amber

    Employee

    Access that outlived the role. The promotion added permissions; nothing took the old ones away.

  • A contractor identity, drawn as a worker bee sealed in amber

    Contractor

    Brought in for a job, belongs to another hive, should have left when the work did.

  • A service account, drawn as a scorpion sealed in amber

    Service account

    Unowned and over-privileged. No joiner–mover–leaver event will ever touch it.

  • An API key or secret, drawn as a spider and web sealed in amber

    API key / secret

    Stale keys threaded across repositories, CI and vendor consoles. Rotation was somebody’s job once.

  • An AI agent identity, drawn as a butterfly sealed in amber

    AI agent

    Shadow agents running on a human’s credentials, so every action they take is attributed to that human.

  • A privileged account, drawn as a scarab sealed in amber

    Privileged account

    Dormant admin. Standing privilege that nobody has used in nine months and nobody will give up.

  • An orphaned account, drawn as an empty air bubble sealed in amber

    Orphaned account

    No owner, no manager, no leaver record. The account your auditor will find first.

  • A toxic privilege combination, drawn as two specimens fused in one piece of amber

    Toxic combination

    Two entitlements that should never have met in one identity. Raise the invoice and approve it.

How it works

Discover, fix, prove

01

Discover

Every identity type mapped to an owner, its access and its activity — humans, service accounts, keys and agents, across SaaS and on-prem.

First meaningful findings within an hour of your first connector. Findings, not a finished inventory — the inventory keeps growing as connectors land.

See every identity

02

Fix

Ranked, explainable findings with an owner attached and a time-to-remediate you can hold people to.

Verified remediation: an item closes only when a re-scan confirms the access is gone. Not when someone ticks a box.

Close the gaps that matter

03

Prove

Access-review campaigns and one-click evidence, mapped to the frameworks your auditor actually asks about.

Reviewers act in Slack, Jira, ServiceNow and email. They never learn a console, which is why the campaign finishes.

Reviews and evidence

The difference

Depth, not breadth.

Most tools in this category count how many logos they connect to. That number does not help you, because reviews do not fail across four hundred applications — they fail inside about ten.

So we go entitlement-deep on the systems where privilege actually accumulates: Okta, Entra ID and on-prem Active Directory, Google Workspace, AWS, Azure and GCP IAM, Salesforce, NetSuite, Workday, GitHub, Snowflake, Microsoft 365. Not “connected” — we read the roles, the permission sets, the group nesting and the local accounts that never touched SSO.

On-prem Active Directory is the clearest gap. It is where the oldest service accounts live and where SaaS-only competitors structurally cannot reach. We read it through one lightweight read-only collector per site.

What we connect to, and how deep

An API key or secret, drawn as a spider and web sealed in amber

Spider and web — the API key. Sticky, spread everywhere, threading across systems that were never meant to touch. You find the web long before you find the spider.

Time to value

Live in a day. Findings in an hour.

  1. 1

    Connect

    OAuth into your identity provider and your first application. Read-only scopes, granted per connector. No agents on endpoints.

  2. 2

    See findings

    Within the hour: orphaned accounts, dormant admins, service accounts nobody owns, access that survived a leaver.

  3. 3

    Keep going

    Add connectors as you go. Active Directory needs one read-only collector per site — the one place “agentless” needs qualifying.

It has to survive you.

Mid-market identity programmes die when one champion leaves. So Amberlock runs itself: no deployment project, no professional services, no quarterly tuning, no console anyone has to be trained on. If the person who bought it moves on, the reviews still run and the evidence still lands.

The agent

The agent does the work.

Agentic, not a bolt-on chatbot

The agent runs review preparation, drafts owner assignments, proposes auto-certification policies for low-risk access, and chases remediation until it is confirmed — with a human approval gate at every step that changes something.

The bar is low. Incumbent AI features demo well and then sit unused; under half of the seats that have them switch them on. Doing the work rather than describing it is the whole claim.

The hard rule: the language model explains and orchestrates. It is never the source of truth for evidence. Every certification, every revocation and every re-scan result is a deterministic record the agent can read but cannot author.

Built to be scripted

A public API and a CLI from day one, with the prompt interface as the power-user front door rather than the only door. Extensibility decided field evaluations, so it is table stakes rather than a nice-to-have.

There is a symmetry worth stating once and then leaving alone: the product that governs your AI agents is itself agentic.

Terminal example pending. The command grammar is being finalised with the people building it. We would rather leave this space empty than print syntax that turns out to be wrong.

Trust posture

Read-only by default.

Read-only unless you say otherwise

Every connector starts read-only. Write scopes — the ones that let us revoke access directly rather than raise a ticket — are granted per connector, by you, and can be withdrawn.

Scopes granted per connector

Not one blanket grant. You see exactly what each connector reads before it reads anything, and connectors are independent of each other.

A deterministic system of record

Findings, certifications and remediation proofs are stored as records, not as model output. The AI layer explains and orchestrates; it never authors evidence.

No endpoint agents

Nothing installed on laptops or servers. Active Directory is the one exception worth stating plainly: it needs a single lightweight read-only collector per site.

Find out what is in your amber.

Register for early access. Connect one system read-only, and see your first findings within the hour — the accounts nobody owns, the privilege nobody granted, the access that was never actually removed.

A service account, drawn as a scorpion sealed in amber

Scorpion — the service account. Ancient, over-privileged, still venomous. Real scorpions turn up in real amber, which makes this the most literally accurate specimen in the set.