SaaS, identity & machine access
Find services that never appear in a network scan
Build a SaaS population from SSO enterprise applications, identity logs, OAuth grants, browser or secure-web-gateway observations where approved, expense and procurement records, contracts, domains, certificates, email integrations, API gateways, security questionnaires and owner attestations. Record tenant ID, verified domains, service owner, data categories, authentication method, privileged roles, integrations, retention, supplier status, renewal date and offboarding plan.
Inventory service principals, managed identities, API clients, bots, automation accounts, certificates, keys and secrets as security assets linked to their owners and target resources. Record issuer, scope, privilege, storage location, rotation or expiry, last use and emergency revocation. Avoid placing secret values in the inventory; link to the authorized secret-management system.
Flag direct local accounts when centralized identity is expected, dormant tenants, ownerless OAuth applications, high-privilege consent, shared administrative accounts, integrations that bypass SSO, and renewals without current business need. A contract cancellation does not prove that accounts, exports, connectors, tokens or retained data were removed.