Know every identity you have — human, machine and AI. Live in an hour.

Your identity provider governs the front door. Amberlock finds what is behind it, ranks what to fix, and proves it was fixed.

Read-only, OAuth in minutes. First findings within the hour.

An AI agent identity, drawn as a butterfly sealed in amber
Butterfly — the AI agent. Newly emerged, moves fast, and looks more fragile than it is. Most are running on a human’s credentials, which is why your directory counts them as that human.

The gap

You already own an identity provider. It cannot see this.

An employee identity, drawn as an ant sealed in amber

Ant — the employee. A colony: ordered, countable, and mapped to an org chart. The one population your directory already tracks well.

Your identity provider

Governs the front door.

Okta and Entra do this part well. They authenticate people, assign applications, and record the joiner–mover–leaver events as they happen. The front door is genuinely closed. Nothing below is an argument for replacing it.

  • Who has an account
  • Which apps they are assigned
  • Who left last month
A service account, drawn as a scorpion sealed in amber

Scorpion — the service account. Ancient, over-privileged, still venomous. Real scorpions turn up in real amber, which makes this the most literally accurate specimen in the set.

What it cannot see

Everything behind that door.

Your identity provider knows someone can open Salesforce. It does not know they hold the admin role inside it, that the NetSuite account was created outside SSO, or that a service account in on-prem Active Directory has held domain admin since 2014. Nobody provisioned it, so nobody governs it.

  • Permissions inside the app
  • Accounts created outside SSO
  • Service accounts, keys, AI agents
  • Whether revoked access actually went
An orphaned account, drawn as an empty air bubble sealed in amber

An empty air bubble — the orphaned account. Nobody home, and nobody left to ask. The only specimen in the set with no creature in it, which is the point.

What that costs you

Your auditor samples exactly that.

Reviewers certify application names, because application names are all they are shown. The permissions inside go unexamined for four quarters — until an auditor pulls a sample, finds an account nobody owns, and asks who approved it. That is the meeting you are preparing for.

  • 40–120 hours a quarter, by hand
  • Proof a review happened — not that access went
  • Findings you meet first in the auditor’s sample

Your compliance platform tracks that a review happened.

It does not see app-local entitlements, and it cannot verify the access actually disappeared. Drata is review-only by its own documentation; Vanta markets remediation workflows. Either way, what you hold is a record of the process, not proof of the outcome.

Amberlock performs the review — down to the entitlement, across on-prem Active Directory as well as SaaS — and pushes the evidence into the platform you already own. An item closes only when a re-scan confirms the access is gone.

How the evidence works