Skip to main content

Security Operations

The identity risk cluster, your top findings, the identity exposure breakdown, and an inventory of the autonomous AI agents operating in your tenant.

The Security Operations view composed on a live tenant — top findings, top 10 identity risks, NHIs by type, agentic AI inventory, and the identity risk cluster

Top findings

Which single fix retires the most risk?

Ranked by how many identities are affected, so it surfaces systemic hygiene problems over one-off outliers. Selecting a finding opens its drill-down — evidence, affected identities, and remediation steps.

The top findings widget

Top 10 riskiest identities

Who, by name?

People, machine accounts, and certificates in one list, so nothing hides behind a category. Selecting an identity opens its blast-radius drill-down.

The top 10 riskiest identities widget

Non-human identities by type

How many machine accounts do we really have?

Usually more than people expect. Pair it with the agent inventory.

The non-human identities by type widget

Agentic AI inventory

What AI agents are running, and what can they touch?

The tool surface column matters most — it is what the agent can act on. Autonomy tells you whether a human approves first.

The agentic AI inventory widget

Identity risk cluster

What am I not seeing?

The one to open when you don't yet know what you're looking for. Tight groups of large bubbles are concentrations worth a look.

The identity risk cluster widget

Top kill chain

The kill-chain flow panel is temporarily unavailable while it is reworked — it is coming back in a future release.