Know every identity you have — human, machine and AI. Live in an hour.
Your identity provider governs the front door. Amberlock finds what is behind it, ranks what to fix, and proves it was fixed.
Read-only, OAuth in minutes. First findings within the hour.
The gap
You already own an identity provider. It cannot see this.
Ant — the employee. A colony: ordered, countable, and mapped to an org chart. The one population your directory already tracks well.
Your identity provider
Governs the front door.
Okta and Entra do this part well. They authenticate people, assign applications, and record the joiner–mover–leaver events as they happen. The front door is genuinely closed. Nothing below is an argument for replacing it.
- Who has an account
- Which apps they are assigned
- Who left last month
Scorpion — the service account. Ancient, over-privileged, still venomous. Real scorpions turn up in real amber, which makes this the most literally accurate specimen in the set.
What it cannot see
Everything behind that door.
Your identity provider knows someone can open Salesforce. It does not know they hold the admin role inside it, that the NetSuite account was created outside SSO, or that a service account in on-prem Active Directory has held domain admin since 2014. Nobody provisioned it, so nobody governs it.
- Permissions inside the app
- Accounts created outside SSO
- Service accounts, keys, AI agents
- Whether revoked access actually went
An empty air bubble — the orphaned account. Nobody home, and nobody left to ask. The only specimen in the set with no creature in it, which is the point.
What that costs you
Your auditor samples exactly that.
Reviewers certify application names, because application names are all they are shown. The permissions inside go unexamined for four quarters — until an auditor pulls a sample, finds an account nobody owns, and asks who approved it. That is the meeting you are preparing for.
- 40–120 hours a quarter, by hand
- Proof a review happened — not that access went
- Findings you meet first in the auditor’s sample
Your compliance platform tracks that a review happened.
It does not see app-local entitlements, and it cannot verify the access actually disappeared. Drata is review-only by its own documentation; Vanta markets remediation workflows. Either way, what you hold is a record of the process, not proof of the outcome.
Amberlock performs the review — down to the entitlement, across on-prem Active Directory as well as SaaS — and pushes the evidence into the platform you already own. An item closes only when a re-scan confirms the access is gone.