Fix

Findings, not dashboards.

Nobody needs another pane of glass to log into. Amberlock produces a ranked list of things that are wrong, each one explainable, each one owned, and each one closed only when a re-scan proves it.

A toxic privilege combination, drawn as two specimens fused in one piece of amber
Two specimens fused — the toxic combination. Two entitlements that should never have touched, now inseparable in one identity.

The catalogue

What we find, and how hard it bites.

Severity is a property of the finding, not a mood. Each one carries the reason it ranks where it does, so an owner can disagree with the ranking rather than with the tool.

  • Critical

    Leaver with live access

    Someone left, and something did not get the message. The gap between an HR termination date and the last surviving entitlement is the single most defensible number on this page.

  • Critical

    Unowned service account with standing privilege

    Domain admin, no owner, no rotation, no joiner–mover–leaver event that will ever touch it. The 2014 print server account, still holding the keys.

  • High

    Orphaned account

    No owner, no manager, no leaver record. It belongs to nobody, so nobody will certify it, so it survives every review by default.

  • High

    Toxic privilege combination

    Two entitlements that are each defensible alone and indefensible together. Raise the invoice and approve it; write the code and deploy it unreviewed.

  • High

    Shadow AI agent on human credentials

    An agent acting continuously under a person’s identity. Every log line attributes its actions to them, including the ones they would never have taken.

  • Medium

    Dormant privileged account

    Admin rights unused for months. Not yet a breach, and exactly the account an attacker wants: powerful enough to matter, quiet enough that nobody watches it.

  • Medium

    Stale key or secret

    Credentials with no rotation history, often scoped far wider than the job they were minted for, often tied to someone who has left.

  • Low

    MFA and SSO coverage gap

    An application people reach without going through the front door, or an account that skipped the second factor. Individually minor, collectively the reason the front door does not hold.

Severity is shown as a colour and a word, always. Rank never depends on hue alone.

Ownership

A finding with no owner is a complaint.

Every finding gets a name

Amberlock infers the owner from the graph — the manager, the application administrator, the last human who used the credential, the team that owns the resource — and the agent drafts the assignment for approval rather than waiting for someone to triage a queue.

Where no owner can be inferred, that absence is the finding, and it escalates. An unownable account is a governance failure, not a data gap.

Time-to-remediate is tracked

The clock starts when the finding is raised and stops when a re-scan confirms the access is gone — not when someone marks it done. That makes it a real operational metric you can take to a board, and a real number to put in front of an auditor.

It also makes us accountable. If findings sit open, that is visible in the same place as everything else.

Remediation

Two tiers, honestly labelled.

Native revoke

Where you have granted write scopes

Amberlock removes the entitlement directly in the system that holds it, then re-scans to confirm it is gone. Fastest path, and the only one that closes without a human in the loop.

You grant write scopes per connector, and you can withdraw them.

Tracked ticket-out

Everywhere else

We raise the change in Jira or ServiceNow with everything the assignee needs, then keep watching. The ticket closing does not close the finding — the re-scan does.

This is the honest default. Most estates will not grant write scopes on day one, and should not have to.

The closing rule

Verified remediation.

An item closes when a re-scan confirms the access is gone. Not when a ticket is resolved, not when a reviewer certifies, not when someone types “done” in a comment.

This sounds pedantic until you have watched a revocation fail silently — the group removed but a nested group still granting it, the account disabled in the directory but the local application login still live, the key rotated in one repository and not the other three.

Every other tool in this category stops at the ticket. That is the difference between evidence that a process ran and evidence that the risk is gone, and it is the tier competitors do not reach.

A privileged account, drawn as a scarab sealed in amber
Scarab — the privileged account. Revered, ceremonial, powerful. Nobody wants to be the one who takes it away.

Find out what is in your amber.

Register for early access. Connect one system read-only, and see your first findings within the hour — the accounts nobody owns, the privilege nobody granted, the access that was never actually removed.

A service account, drawn as a scorpion sealed in amber

Scorpion — the service account. Ancient, over-privileged, still venomous. Real scorpions turn up in real amber, which makes this the most literally accurate specimen in the set.