One inventory, three different arguments
The product does not change by segment. What changes is which question it answers first: an auditor asking for evidence, a platform team asking what breaks, or a small team asking who has access at all.
For a security team preparing an audit
The evidence exists before the auditor asks
Quarterly campaigns assign every grant to a named reviewer, record approve or remove with a reason, and produce a signed report. SOC 2 CC6.1 and ISO 27001 A.9.2.5 both ask for exactly this.
Undecided is a state, not a gap
A campaign closes on its date. Grants nobody reviewed are marked NOT REVIEWED and counted separately, because a report that refuses to close proves nothing.
Every decision is attributable
Who proposed, who approved, when, and on what evidence. The audit log is append-only and exportable.
For a platform team that owns the blast radius
Impact before action
Every grant carries its dependents: what breaks outright, what degrades, what is unaffected. Computed from provider activity, not declared by anyone.
Notice, then cutover
Removal serves notice to the recorded owner, opens a grace window, and cuts over on schedule. An incident skips the window; a cleanup does not.
Service accounts treated as such
A machine identity cannot answer a challenge, leaves no HR record, and nobody notices when it stops. They hold most of the grants and get their own inventory.
For a small team with no security function
One connection, real answers
The free tier scores your whole Workspace. Nobody needs to configure a policy engine to find out that a transcription tool has been reading every mailbox for a year.
Alerting that stays quiet
One rule, one channel, thresholds that mean something. Allowlist what you have decided to keep so it stops resurfacing.
No implementation project
Consent at the provider, wait two minutes, read the inventory. There is nothing to deploy and nothing to integrate.
What each buyer usually asks for first
Not a feature matrix. The order in which the same product gets adopted.
| Buyer | First question | Surface that answers it |
|---|---|---|
| Security and compliance | Can I prove we reviewed access? | Access reviews, audit log, signed report |
| Platform and infrastructure | What breaks if I remove this? | Grant dependencies, governed removal |
| IT for a small team | Who has access to our mail? | Grants list, risk bands, one alert rule |
| Regulated or air-gapped | Can it run in our own VPC? | Self-hosted deployment, licence file |
| CISO reporting upward | How do we compare? | Cohort benchmark, exposure over time |
Whichever question you came with
Connect one provider and the answer is on screen in about two minutes. No call required, and nothing is revoked without you deciding to.