NEWFreshservice is now a Ploy integrationSee what shipped
1.0IDENTITY RISK SCAN

Your IdP shows you what’s connected. We show you the rest.

An IdP-anchored review of identity and access exposure. Every application, admin role, service account and dormant grant sitting around your identity provider — found, rated by urgency, and handed back as a register your team can work through.

Read-onlyOkta, Entra ID or Google WorkspaceNothing is exploited, nothing is changed

Identity risk scanREAD-ONLYIdP-ANCHOREDSCANNINGNothing is exploited · nothing is changed
YOUR IdP128246347APPS FOUND
Behind SSOOutside SSOCriticalNon-human
What it turns up
214applications outside single sign-on
185non-human identities with no named owner
388dormant guest accounts, none MFA-enrolled
9,140live grants held by people who have left
5findings rated critical — act within days
1.1HOW IT RUNS

Minutes to connect. A few weeks to be worth reading.

The review reads your identity provider and the activity around it. It does not touch anything: no agent, no write access, no change to a single policy or group.

01~10 MINUTES

Connect

Read-only access to your identity provider — Okta, Entra ID or Google Workspace. One person, one sitting, and revocable whenever you like.

02ABOUT THREE WEEKS

Observe

The window is the point. A snapshot shows you what is true this morning; watching for a few weeks shows access accumulating, credentials ageing and accounts going quiet.

03WALKED THROUGH WITH YOU

Review

You get the findings rated by urgency, a risk register with stable IDs, and a 30/60/90 plan. We go through it with your team rather than emailing a PDF.

You are only involved in the first step and the last

The middle is a waiting period, and it is what separates a review from a screenshot.

1.2WHAT IT LOOKS AT

Six places exposure collects

Every one of them sits just outside what an identity provider reports on by itself, which is why they go uncounted for years at a time.

214apps found outside SSO

Shadow identities and access

The SaaS footprint beyond your IdP: tools holding company data with no single sign-on, no review and no owner.

38%of apps integrated to the IdP

IdP surface and hygiene

What is actually integrated versus what people simply log into. Group sprawl, direct assignments, and admin roles nobody has counted.

61sanctioned apps with no owner

Ownership and accountability

Who owns each app and each group. Where ownership is missing, reviews default to IT — who have no context to decide with.

146accounts holding admin

Privileged access

Admin roles, elevated rights and standing privilege held for months. Where it is permanent, who holds it, and whether it is time-limited.

212non-human identities

Non-human identities

Service accounts, integrations and automation. Credential lifecycle, who owns them, and what they can still reach.

9,140grants held by inactive accounts

Drift, dormancy and auth strength

Access that accumulated and never went away, accounts inactive but still entitled, and how much of the estate MFA really covers.

1.3WHAT IT DOES NOT

And the four things it is not

Worth saying plainly, because a review that claims to find everything is a review nobody should trust.

It is not a penetration test

Nothing is exploited and nothing is attacked. The review reads configuration and activity, and reports what it finds.

It is not a compliance audit

Findings map onto the obligations you already have, but this is not an assessment against a named standard and does not produce a certificate.

It is not a tooling assessment

We do not score the products you run or recommend replacing them. The finding is the exposure, not the vendor.

Where the data is thin, we say so

Some areas depend on what your tenant exposes and how long we have been watching. Any section running on partial data is labelled as such rather than padded out.

1.4WHAT COMES BACK

Findings, rated by how long you have to act

Not a list of everything wrong. A ranked, evidenced set of findings, each with what it is, why it matters, what to do about it, and who should own it.

Identity & Access Exposure ReviewALL DEPARTMENTSALL SEVERITIESEXAMPLE REVIEW
IDENTITIES IN SCOPE
1,640human + machine
APPLICATIONS FOUND
347214 outside SSO
FINDINGS RAISED
395 critical

39 findings, by urgency

The rating is a deadline, not an adjective. Each band says how long you have before it stops being a housekeeping item.

Critical5ACT WITHIN DAYS
Real and immediate business or compliance risk
High11ACT WITHIN WEEKS
Material exposure, but not imminent
Medium14ACT WITHIN THE QUARTER
Worth resolving as part of standing governance
Low9HOUSEKEEPING
Address through normal cycles

Where people actually sign in

Sign-ins through your identity provider against sign-ins that never touched it. The gap is the part no policy currently reaches.

Salesforce97% VIA SSO
Slack90% VIA SSO
Zoom81% VIA SSO
Notion39% VIA SSO
Figma33% VIA SSO
CanvaNO SSO
TypeformNO SSO
Through your IdPStraight to the app

Where the exposure concentrates

Each department against each kind of exposure, scored 0–100 by the share of that team carrying it. Standing is permanent admin; dormant is access still held by inactive accounts. Hover a cell for its score.

Shadow SaaSUnownedStandingDormantWeak MFAStale NHI
Engineering
Finance
Sales
Marketing
Operations
People
Contractors
LOWHIGHCONTRACTORS AND ENGINEERING CARRY THE MOST

Non-human identities, by owner

Service accounts, integrations and automation. The number that matters is not how many there are — it is how many have somebody's name against them.

CI/CD and deployment9/64 OWNED
Data pipelines and ETL4/52 OWNED
HR and finance sync11/38 OWNED
Monitoring and backup2/34 OWNED
Internal tooling1/24 OWNED
OwnedCredential overdueUnowned

27 of 212 have a named owner. When one of the rest breaks, or is breached, nobody is on the hook for deciding what to do with it.

The figures on this page are an illustrative profile, not a customer’s and not an average. Your review reports your own estate, whatever it turns out to hold — including the sections where the data is thin, which we label rather than pad out.

1.5WHAT YOU GET

A register and a plan, not a slide deck

Every finding lands in a register with a stable ID and a named owner, and every register entry lands in a dated plan. That is what makes it work rather than reading.

Appendix A · Risk registerIDS ARE STABLE — A CLOSED RISK KEEPS ITS ID, MARKED CLOSEDEXAMPLE
IDRISKEVIDENCEURGENCYOWNER
R-1.1External supplier holds permanent tenant adminStanding global administrator, in daily use, no time-limiting and no audit trail shared with you.CRITICALHead of ITWITHIN 5 DAYS
R-1.2Dormant guest identities with no MFA388 external guests still enabled, none MFA-enrolled. 96 never accepted their invitation.CRITICALIdentity leadWITHIN 5 DAYS
R-3.1Non-human identity ownership effectively zero185 of 212 service accounts have no named owner. 81 hold a credential past its rotation date.CRITICALPlatform leadWITHIN 5 DAYS
R-4.1Disabled accounts with recent sign-in activity47 accounts marked disabled show sign-ins inside the review window. 8 within the last week.CRITICALSecurity leadINVESTIGATE NOW
R-4.2Inactive members retain live access612 inactive accounts hold 9,140 active grants. Offboarding does not consistently revoke.HIGHIdentity leadWITHIN 30 DAYS
R-2.1Group sprawl and overlapping admin populationsTwo admin groups covering the same system, 140 groups with no description, one named “do not use” with 9 members.HIGHIdentity lead30–90 DAYS
0–7 days
  • SConvert supplier admin to time-limited activation
  • SBulk-disable the never-accepted guest cohort
  • SPull audit logs for disabled accounts showing sign-ins
  • MAssign an owner and rotate the expired integration credentials
8–30 days
  • MBulk-revoke grants held by inactive accounts
  • SEnforce MFA on guests and the named exceptions
  • MCertify the admin populations with each system owner
  • LBring the highest-traffic unmanaged apps behind SSO
31–90 days
  • LOwnership sprint: every non-human identity gets a named owner
  • MPopulate the department field across the directory
  • LProvisioning for the top five applications
  • MStand up recurring access reviews, scoped by department
APPENDIX B · 30/60/90 DAY PLAN · EFFORT: S UNDER A DAY, M A FEW DAYS, L A WEEK OR MORE
1.6WHY RUN ONE

Because nobody has counted, and it is not in one place

Identity exposure accumulates quietly across an IdP, a dozen admin consoles and a directory nobody has read end to end. It is nobody's job to add it up, which is exactly why it goes unadded.

01

Your IdP was never going to tell you this

It reports faithfully on what is connected to it. Everything the review is looking for — the app nobody integrated, the service account nobody owns, the admin nobody time-limited — is outside that by definition.

02

Read-only, and nothing is touched

No agent, no write access, no policy changes, and nothing exploited. The review reads configuration and activity. You can revoke access the day the report lands.

03

You get a register, not a lecture

Findings come rated by urgency with evidence attached, a named owner and a dated action. Your team can work through it without a follow-up call to work out what any of it means.

04

It is useful whatever you do next

The exposure is real whether or not you buy anything, and most of the first week of actions are things you can do yourself with tools you already have.

Avantia Law
Ploy has transformed how we do access requests & we wouldn't be able to go back to the way it was.
Peter F.Head of IT & Infosec, Avantia Law
Read the story
Liberis
Ploy has enabled us to completely automate employee onboarding and offboarding, saving us 150 manual actions, clicks, and hours of time per employee.
Paul HartHead of IT, Liberis
Welcome to the Jungle
With Ploy, we've turned a tedious weekly task into easy automated flows. We're saving half a day a week and have completely streamlined onboarding across all our SaaS tools. Total game changer.
Devon BrownSenior IT Engineer, Welcome to the Jungle
Luno
Ploy saved me from drowning in spreadsheets, manual licence assignment and SaaS sprawl. It lets us easily make sense of what's being bought, used, and wasted which is more than I can say for most software tools. The best part? They listen, iterate fast, and don't take themselves too seriously. Perfect match.
Simon FishleyGlobal IT Director, Luno
Read the story

Find out what is outside the ring

Connect your identity provider read-only, give us a few weeks of watching, and we will walk your team through everything the review turns up.