Assessment

Non-Human Identity Security Assessment

Find the service accounts, API keys, OAuth grants, workload identities, and AI agents your existing access review missed. Avistar gives MSPs and security teams a read only machine identity inventory, prioritized risk findings, compliance evidence, and remediation recommendations.

Amazon Web Services logoMicrosoft Azure logoGoogle Cloud Platform logo
What it covers

Inventory, ownership, risk, and evidence

Four outputs, produced from one read only connection to the environments in scope.

Complete identity inventory

Every nonhuman credential in scope, enumerated and deduplicated: what exists, where it lives, and when it was last used.

Ownership attribution

Each identity is tied back to a team, workload, or vendor, so orphaned credentials stop being nobody's problem.

Blast radius risk scoring

Findings are ranked by the privilege and resources a credential can reach if abused, not by raw finding counts.

Compliance evidence

Findings map to ISO 27001, SOC 2, NIST 800-53, FedRAMP, and HIPAA controls, so the output is usable in an audit.

Identity types discovered

Every credential that is not a person

  • Cloud IAM roles and users
  • Service accounts
  • Long lived access keys
  • API tokens and secrets
  • OAuth grants and app registrations
  • Workload identities and federated roles
  • Certificates and signing keys
  • Credentials used by AI agents and automations
Supported environments and access

Agentless, read only, least privilege

AWS, Azure, and GCP

Accounts, subscriptions, and projects you nominate. Coverage of any additional identity source is confirmed during scoping.

Required access

A read only role scoped to identity and policy metadata. No agents, no write access for discovery, and no change window.

How it runs

From connection to remediation plan

1

Scope and connect

You pick the accounts, subscriptions, or projects in scope and grant a read only, least privilege role. Nothing is installed and no production change window is needed.

2

Discover and attribute

Avistar enumerates every nonhuman identity in scope, resolves ownership, and records permissions, age, and last activity.

3

Score and map

Each finding is scored by blast radius and mapped to the control frameworks you report against.

4

Review and remediate

You get a prioritized findings review with remediation guidance: what to rotate, what to scope down, what to retire, and what breaks if you get it wrong.

Deliverables

What you receive

  • Machine identity inventory export for the environments in scope
  • Prioritized findings list ranked by blast radius
  • Ownership and orphaned credential report
  • Control mapping for ISO 27001, SOC 2, NIST, FedRAMP, and HIPAA
  • Remediation plan with step by step guidance per finding
  • White label version of the report for MSP and MSSP partners

Timeline

Discovery for a single environment usually completes within a day of the read only role being granted. The findings review follows immediately after attribution.

MSP and MSSP option

Partners run the assessment for one client as a gap assessment, deliver it white labeled, and bill the remediation work that follows. See the partner model.

Questions

Assessment FAQ

The questions buyers ask before granting access.

See every machine identity in your cloud

Book a walkthrough, or start with a single client gap assessment: agentless, read only, no commitment.