Agent Readiness Scan
Find what your agents can reach before somebody else does.
Read-only connectors pull the permissions your systems already hold. We reconcile them into one graph. Then people read it.
- Check before you deploySee what an agent would inherit on day one, for every person it acts for.
- Find what nobody remembers grantingThe access added by a project, a reorganisation or an acquisition that no review has looked at since.
- Give security an answerFindings worst first, systems named and paths traced, written to be forwarded to whoever has to fix it.
An agent should never reach further than the person it is acting for.
So the scan reads the human layer underneath, and fixes the agent problem by proxy. You are not remediating an estate, you are closing the specific paths that let one question assemble something it should not.
The connectors are read-only OAuth, scoped by you and revocable by you at any time. They read who has access to each file, table and record, never what is inside it.
The graph maps your estate without carrying readable names, paths or titles. Obscured is not the same as anonymous, so the key that makes it readable stays with you.
When the scan ends, take the graph straight into Watchdog, and watching starts where the scan left off.
- 01Scoping callWe agree what the first scan covers, and what it deliberately leaves out.
- 02ConnectRead-only OAuth, granted by you, one system category at a time.
- 03ReconcileThe permissions are pulled into one graph, and the paths between them are traced.
- 04Read it togetherThe report, walked through with whoever has to act on it.
Every finding ends in a change somebody can make.
Built the way a penetration test report is: ranked worst first, each one traced to the grant behind it.
- The path
- Which systems, which grants, and the groups and roles that join them. Traced, not inferred.
- Who holds it
- How many people the path is open to, and which groups give it to them.
- Rank
- Worst first, by how much an agent could reach through it.
- The change
- The specific fix, in the system that owns it. You make it, or your integrator does, and it is written to be forwarded to them as it stands.
- Retest
- Re-run the same scope after the work. The finding closes, or it does not.
The ceiling behind each person
Everything each person can reach, across every system at once. An agent acting for them inherits all of it.
Paths that exist only between systems
Access created because two systems disagree about a group. No single system can see one of these, which is why nothing has ever reported them.
Access held outside any group
Direct grants and sharing links that bypass the roles your access reviews look at.
What an agent would inherit today
The same question asked as the agent rather than as a person, so the answer is what it could reach, not what it should.
The review you already run.
Access reviews are already in the calendar. Owners certify what their people are entitled to, the evidence is kept, and the cycle starts again. The scan is written to land in that cycle rather than beside it.
A review certifies entitlements one system at a time, because that is how the entitlements were granted and how the owners understand them. The question it has never had to answer is what one person can reach across all of the systems at once, and an agent asks that question on its first day.
Same cycle, same signatories, one more thing it can now certify.
Your identity provider and your posture tooling stay exactly where they are. The scan reads what the first already knows, reconciles it with the grants your data platforms enforce, and finds the paths that exist between them.
Findings arrive with systems named and paths traced, ready for whoever signs the review.