READ-ONLY AGENT EXPOSURE SCANNER

Every agent gets an owner. Every privilege gets an expiry.

PermitGraph surfaces unmanaged AI agents and machine identities in customer-supplied metadata, maps what they can reach, and shows which credentials can outlive the job, without collecting secret values.

  • Metadata only
  • Customer-run scanner
  • No infrastructure changes
IDENTITY LINEAGELIVE MODEL
AGENTinvoice-reconcilerOwner missing
CREDENTIALprod-finance-keyNever expires
RESOURCEvendor-masterCritical · Write
92 CRITICAL

Built for teams deploying agents across

AWSGITHUBENTRAMCPSUPABASE

THE CONTROL POINT

See the path before you police the action.

Broad identity suites are moving into agent security. PermitGraph starts with the portable evidence layer they do not make easy: one normalized map of ownership, credentials, privileges, and consequential access.

01

Discover

Normalize customer-approved agent and machine-identity metadata into one graph. AWS, Entra, GitHub, MCP, and Supabase adapters are working today; other exports use an agreed field map.

02

Trace

Map agent to owner to credential to privilege to resource, including shared credentials and unconstrained delegation paths.

03

Prove

Prioritize exposures and export a tamper-evident evidence package with a stable SHA-256 integrity digest.

WORKING PRODUCT

Run an AWS, Entra, GitHub, MCP, or Supabase exposure scan.

Inspect AWS IAM paths, Entra service principals, GitHub Actions workflows, MCP tool grants, or Supabase functions and data surfaces through the same scanner used by the CLI. Secret-like fields are rejected before processing, and the hosted demo does not persist submissions.

PERMITGRAPH / HOSTED DEMONO PERSISTENCE

Hosted sample boundary: this selected sample is sent to PermitGraph's hosted scan API and is not persisted.

Open the browser-local worksheet
Service principals + permissions + credential metadata
EXPOSURE REPORTWAITING
No report yet.Run the selected sample to map its identity exposure.

SAMPLE DELIVERABLE

See the evidence package before the pitch.

A buyer-ready sample shows the exposure score, prioritized register, recommended controls, integrity digest, and explicit assessment limits.

PermitGraph sample evidence report

Two pages. Real scanner output. No invented certification claims.

Download the sample PDF
DESIGN-PARTNER TERMS

60-day pilot brief

Scope, success criteria, zero-custody delivery, data boundary, and the $4,000 commercial structure.

Download brief

PRODUCT PATH

A wedge, not another identity suite.

The free scanner earns access to real environments. Continuous evidence earns the subscription. Runtime authorization becomes the strategic control point.

Now

Read-only scanner

Normalized input plus AWS, Entra, GitHub, MCP, and Supabase adapters; ownership; lineage; exposure scoring; evidence export.

Next

Continuous posture

Scheduled collection, ownership inbox, drift detection, Slack/Jira alerts, and remediation workflow.

Then

Runtime authorization

Short-lived grants, action-level policy, human approval thresholds, revocation, and signed decision logs.

FOUNDING DESIGN PARTNERS

Turn one inventory export into a board-readable exposure map.

A fixed-scope, customer-run engagement for security and identity teams that need evidence before they commit to another platform.

$4,000fixed / 60 days
  • Up to three mapped metadata sources
  • Zero-custody customer-run scan
  • Ownership and credential-lineage workshop
  • Prioritized exposure register
  • Executive evidence package
  • Production roadmap and ROI baseline
Check pilot fit Build a redacted execution path Review the full pilot brief

Raw metadata stays in your environment by default. No secret values. No infrastructure mutation.

FIT CHECK

Tell us what the scanner needs to map.

Andrew replies within one business day. The fit check covers your metadata sources, identity volume, security question, safe first export, and whether a fixed $4,000 pilot can reach a decision.

Qualified teams receive a written scope for security and commercial review. No payment or data transfer starts before a mutually signed agreement.

Prefer email? Contact pithstrategies@gmail.com
Metadata sources in your environment *

Choose the system families in the first path. Supabase, AWS IAM, GitHub, Entra, and MCP tool registries have current customer-supplied metadata adapters; other selections use an agreed field map.

Business contact details only. Do not submit credentials, secrets, customer data, or infrastructure exports here. View the exact stored fields and contact-data boundary.