One inventory, three different arguments

The product does not change by segment. What changes is which question it answers first: an auditor asking for evidence, a platform team asking what breaks, or a small team asking who has access at all.

For a security team preparing an audit

The evidence exists before the auditor asks

Quarterly campaigns assign every grant to a named reviewer, record approve or remove with a reason, and produce a signed report. SOC 2 CC6.1 and ISO 27001 A.9.2.5 both ask for exactly this.

Undecided is a state, not a gap

A campaign closes on its date. Grants nobody reviewed are marked NOT REVIEWED and counted separately, because a report that refuses to close proves nothing.

Every decision is attributable

Who proposed, who approved, when, and on what evidence. The audit log is append-only and exportable.

For a platform team that owns the blast radius

Impact before action

Every grant carries its dependents: what breaks outright, what degrades, what is unaffected. Computed from provider activity, not declared by anyone.

Notice, then cutover

Removal serves notice to the recorded owner, opens a grace window, and cuts over on schedule. An incident skips the window; a cleanup does not.

Service accounts treated as such

A machine identity cannot answer a challenge, leaves no HR record, and nobody notices when it stops. They hold most of the grants and get their own inventory.

For a small team with no security function

One connection, real answers

The free tier scores your whole Workspace. Nobody needs to configure a policy engine to find out that a transcription tool has been reading every mailbox for a year.

Alerting that stays quiet

One rule, one channel, thresholds that mean something. Allowlist what you have decided to keep so it stops resurfacing.

No implementation project

Consent at the provider, wait two minutes, read the inventory. There is nothing to deploy and nothing to integrate.

What each buyer usually asks for first

Not a feature matrix. The order in which the same product gets adopted.

BuyerFirst questionSurface that answers it
Security and complianceCan I prove we reviewed access?Access reviews, audit log, signed report
Platform and infrastructureWhat breaks if I remove this?Grant dependencies, governed removal
IT for a small teamWho has access to our mail?Grants list, risk bands, one alert rule
Regulated or air-gappedCan it run in our own VPC?Self-hosted deployment, licence file
CISO reporting upwardHow do we compare?Cohort benchmark, exposure over time

Whichever question you came with

Connect one provider and the answer is on screen in about two minutes. No call required, and nothing is revoked without you deciding to.