Discover
Normalize customer-approved agent and machine-identity metadata into one graph. AWS, Entra, GitHub, MCP, and Supabase adapters are working today; other exports use an agreed field map.
READ-ONLY AGENT EXPOSURE SCANNER
PermitGraph surfaces unmanaged AI agents and machine identities in customer-supplied metadata, maps what they can reach, and shows which credentials can outlive the job, without collecting secret values.
Built for teams deploying agents across
AWSGITHUBENTRAMCPSUPABASETHE CONTROL POINT
Broad identity suites are moving into agent security. PermitGraph starts with the portable evidence layer they do not make easy: one normalized map of ownership, credentials, privileges, and consequential access.
Normalize customer-approved agent and machine-identity metadata into one graph. AWS, Entra, GitHub, MCP, and Supabase adapters are working today; other exports use an agreed field map.
Map agent to owner to credential to privilege to resource, including shared credentials and unconstrained delegation paths.
Prioritize exposures and export a tamper-evident evidence package with a stable SHA-256 integrity digest.
WORKING PRODUCT
Inspect AWS IAM paths, Entra service principals, GitHub Actions workflows, MCP tool grants, or Supabase functions and data surfaces through the same scanner used by the CLI. Secret-like fields are rejected before processing, and the hosted demo does not persist submissions.
Hosted sample boundary: this selected sample is sent to PermitGraph's hosted scan API and is not persisted.
Open the browser-local worksheet ↗SAMPLE DELIVERABLE
A buyer-ready sample shows the exposure score, prioritized register, recommended controls, integrity digest, and explicit assessment limits.
Two pages. Real scanner output. No invented certification claims.
Download the sample PDF ↓Scope, success criteria, zero-custody delivery, data boundary, and the $4,000 commercial structure.
PRODUCT PATH
The free scanner earns access to real environments. Continuous evidence earns the subscription. Runtime authorization becomes the strategic control point.
Normalized input plus AWS, Entra, GitHub, MCP, and Supabase adapters; ownership; lineage; exposure scoring; evidence export.
Scheduled collection, ownership inbox, drift detection, Slack/Jira alerts, and remediation workflow.
Short-lived grants, action-level policy, human approval thresholds, revocation, and signed decision logs.
FOUNDING DESIGN PARTNERS
A fixed-scope, customer-run engagement for security and identity teams that need evidence before they commit to another platform.
Raw metadata stays in your environment by default. No secret values. No infrastructure mutation.
FIT CHECK
Andrew replies within one business day. The fit check covers your metadata sources, identity volume, security question, safe first export, and whether a fixed $4,000 pilot can reach a decision.
Qualified teams receive a written scope for security and commercial review. No payment or data transfer starts before a mutually signed agreement.
Prefer email? Contact pithstrategies@gmail.com