Posture
Close the door first
Fix the four exposures worth fixing, not the fourteen hundred.

What the industry reports
- 92%of identities with sensitive permissions never used them in 90 daysSonrai, enterprise cloud tenants
The moment
Nobody breaks the door down. They sign in as the admin who never turned on MFA, and that finding has been open since June.
For the security engineer who has to pick.
Findings rank by what they reach
A service principal holding Directory.ReadWrite.All outranks a dormant guest, because the blast radius says so. Severity alone puts them side by side.
A finding is a standing condition
The scan opens it and the scan closes it when the misconfiguration is gone. A person can acknowledge it in between, which records who and when.
What the consent cannot reach is reported as unevaluated
A check the current permissions cannot run is marked unevaluated, so the gap is visible instead of showing as a pass.
What you get
Everything this covers.
Posture assessment
- Users, groups, applications, service principals and domains
- Re-scanned every six hours, and every open finding re-confirmed
- A check the current consent cannot run is reported unevaluated

Risk prioritization
- Findings ranked by what the affected account can reach
- An impact score weighted by reach as well as severity
- Paths from a low-risk account into a privileged group, found before anyone uses them

Remediation
- Remediation guidance on the rule, with a script where one applies
- Acknowledging a finding records who did it and when
- The scan closes what the scan opened, on a stable dedup key

What does the work