NEWFreshservice is now a Ploy integrationSee what shipped
1.0ACCESS GRAPH

Understand where access originates.

Ploy holds every employee, identity, app and resource in one graph, and shows you the path from a person to the thing they can open.

Book a demoSee how Luna works
Focus:All identities61 resources across 4 identities
Maya OseiDesign · Product Designer
maya.oseiOkta · Corp IdP
Engineering-AllGroup
SSO · MetabaseIdP App
Design-TeamGroup
maya@company.comGoogle Workspace
Design SharedDrive
Brand AssetsDrive
design@companyGroup
m-oseiGitHub
design-systemRepository
GitHub · Repository(23)
+12 more
AWSReservedSSO_designAWS · Identity Center
ReadOnlyAccessPermission set
prod-assetsBucket
AWS · Role(8)
design-systemRepository
TypeRepository
IntegrationGitHub
StatusActive
Granted12 Jan 2025
Access Levelmaintain
EntitlementsRole · Maintainer
1.1INVENTORY

Everything you run, counted

Four inventories feed one graph: employees, identities, apps and resources. Every count on this page is a filter you can open, not a number in a slide.

Employees found0Users and accounts across all systems
Identities found0Human and non-human, in one estate
Apps found0Connected applications and services
Resources found0Including teams and security groups
Access Grants found41,207Active permissions mapped

One estate, four inventories

Resources, Apps, Employees and Identities each get their own table, their own filters and their own saved views. All four are doors into the same graph.

GROUPREPOSITORYROLEPERMISSION SETDRIVELICENSECHANNEL
One vocabulary for the whole estate.

Resources are 25 kinds of thing

A group, a repo, a role, a permission set, a shared drive and a Salesforce territory all sit in one table with one governance model.

Managed128
Unmanaged271
Blocked13

Apps in three states

Apps are Managed, Unmanaged or Blocked. Promoting one from discovery to managed is one click, and it carries the owner and the cost with it.

Okta groups, no ownerSHARED
SOX-tagged resources412
Dynamic membership63

Saved views, shared with the team

Any filter combination becomes a tab (Type, Integration, Tags, Employee) and can be published to the whole org.

1.2WHY DOES SHE HAVE THIS?

Every grant explains itself.

Ploy answers the question every audit starts with as a walk: hop by hop to the source that granted the access, with direct and inherited access never blurred together.

Focus:All identities61 resources across 4 identities
Maya OseiDesign · Product Designer
maya.oseiOkta · Corp IdP
Engineering-AllGroup
SSO · MetabaseIdP App
Design-TeamGroup
maya@company.comGoogle Workspace
Design SharedDrive
Brand AssetsDrive
design@companyGroup
m-oseiGitHub
design-systemRepository
GitHub · Repository(23)
+12 more
AWSReservedSSO_designAWS · Identity Center
ReadOnlyAccessPermission set
prod-assetsBucket
AWS · Role(8)
design-systemRepository
TypeRepository
IntegrationGitHub
StatusActive
Granted12 Jan 2025
Access Levelmaintain
EntitlementsRole · Maintainer
1.3IDENTITIES

One person, six logins

okta-maya, m.osei@github and a mailbox nobody claims are the same person, or they are not, and that matters more. Ploy resolves accounts to employees and keeps the answer when the next scan disagrees.

maya.osei@company.comMaya Osei · primary
okta-mayaOkta
m.oseiGitHub
m.osei@legacy-co.comLegacy domain
maya.o@company.comGoogle Workspace · alias
1.4SHADOW IT

The apps nobody bought

Staff sign up for tools all day, and the receipt lands in a mailbox nobody reads. Ploy finds those apps four different ways and puts each one in front of the person who first used it.

NameDomainStatusUsersAccess ToFirst detected userPermissions
Notionnotion.soTO REVIEW64FILESEMAILLena Fischer
Airtableairtable.comTO REVIEW22FILESCALTom Ligeti
Calendlycalendly.comTO REVIEW41EMAILCALJon Adeyemi
Miromiro.comTO REVIEW18FILESMSGSMaya Osei
Linearlinear.appTO REVIEW9MSGSRavi Shah
New shadow IT41apps still to review

Discovered, ranked, and answerable

Every discovered app carries the domain, the first person to use it, the date it first appeared, and what its OAuth grant can reach. The riskiest ones sort to the top on their own.

OAuth grantsscopes, and who granted them
Signup receiptsthe welcome email nobody reads
Browser extensioncaught at the moment of signup
Integrationsthe apps you already connect

Four ways to find an app

Discovery runs four ways: OAuth grants, signup receipts in mail, the browser extension, and the integrations you already run. Each one sees what the others miss.

Lena Fischerfirst seen 14 Mar
There is always someone to ask why it is here.

Patient zero, by name

The first person to use an app is on the row. There is always someone to ask why it is here.

gmail.readonlyreads email
drive.filereads files
The strongest scope sets the number.

Risk is the scope, not a vibe

An app's risk is the strongest permission it was granted. Hover it and you get the scope list that produced the number.

airtable.comBLOCKED
Use Notion instead
The answer is not just no.

Blocking comes with somewhere to go

A blocked app shows the approved alternative right in the browser, so a no still points at the tool to use instead.

Avantia Law
Ploy has transformed how we do access requests & we wouldn't be able to go back to the way it was.
Peter F.Head of IT & Infosec, Avantia Law
Read the story
Liberis
Ploy has enabled us to completely automate employee onboarding and offboarding, saving us 150 manual actions, clicks, and hours of time per employee.
Paul HartHead of IT, Liberis
Welcome to the Jungle
With Ploy, we've turned a tedious weekly task into easy automated flows. We're saving half a day a week and have completely streamlined onboarding across all our SaaS tools. Total game changer.
Devon BrownSenior IT Engineer, Welcome to the Jungle
Luno
Ploy saved me from drowning in spreadsheets, manual licence assignment and SaaS sprawl. It lets us easily make sense of what's being bought, used, and wasted which is more than I can say for most software tools. The best part? They listen, iterate fast, and don't take themselves too seriously. Perfect match.
Simon FishleyGlobal IT Director, Luno
Read the story

Know how access actually reaches people.