SOC 2 Type II · ISO 27001 · 1,400 security teams
SOC 2 Type II · ISO 27001 · 1,400 security teams
Palisade
Palisade
Risk score82/100open
Next page/
Home
Identity · Identities
Know every account, and what it can reach.
Every account, human or machine, and what it can reach.
WatchedHuman accountsWatchedService accountsWatchedAdmin rolesWhat it closes.
0 of 4 closed
01Open
Leaver check
Every directory account is matched against HR each night. An account without a person is a finding within the hour.
02Open
Admin map
Who holds which admin role, how they got it and when they last used it.
03Open
MFA coverage
Every sign-in path that still accepts a password alone, per person and per app.
04Open
Machine identities
Service accounts, API tokens and OAuth grants with their owner and their reach.
Palisade reads your identity provider, your cloud roles and your SaaS admin panels, then draws one list of who can do what. Leavers who still hold admin, contractors without MFA and service accounts with keys that never rotate surface in the first hour.
What it closes
- Admin rights that outlived the job
- Sign-ins with a password only
- Shared and never-rotated credentials
What you get in week one
- A list of accounts with no owner, admins first
- Every sign-in path without MFA
- The ten grants that reach the most data
How it connects
Read-only access to your identity provider and your HR system. Nothing is installed on a laptop, and no password ever passes through Palisade.
Identity · Identities
Know every account, and what it can reach.
Every account, human or machine, and what it can reach.

What it closes.
0 of 4 closed
01Open
Leaver check
Every directory account is matched against HR each night. An account without a person is a finding within the hour.
02Open
Admin map
Who holds which admin role, how they got it and when they last used it.
03Open
MFA coverage
Every sign-in path that still accepts a password alone, per person and per app.
04Open
Machine identities
Service accounts, API tokens and OAuth grants with their owner and their reach.
Palisade reads your identity provider, your cloud roles and your SaaS admin panels, then draws one list of who can do what. Leavers who still hold admin, contractors without MFA and service accounts with keys that never rotate surface in the first hour.
What it closes
- Admin rights that outlived the job
- Sign-ins with a password only
- Shared and never-rotated credentials
What you get in week one
- A list of accounts with no owner, admins first
- Every sign-in path without MFA
- The ten grants that reach the most data
How it connects
Read-only access to your identity provider and your HR system. Nothing is installed on a laptop, and no password ever passes through Palisade.
Identity · Identities
Know every account, and what it can reach.
Every account, human or machine, and what it can reach.
WatchedHuman accountsWatchedService accountsWatchedAdmin rolesWhat it closes.
0 of 4 closed
01Open
Leaver check
Every directory account is matched against HR each night. An account without a person is a finding within the hour.
02Open
Admin map
Who holds which admin role, how they got it and when they last used it.
03Open
MFA coverage
Every sign-in path that still accepts a password alone, per person and per app.
04Open
Machine identities
Service accounts, API tokens and OAuth grants with their owner and their reach.
Palisade reads your identity provider, your cloud roles and your SaaS admin panels, then draws one list of who can do what. Leavers who still hold admin, contractors without MFA and service accounts with keys that never rotate surface in the first hour.
What it closes
- Admin rights that outlived the job
- Sign-ins with a password only
- Shared and never-rotated credentials
What you get in week one
- A list of accounts with no owner, admins first
- Every sign-in path without MFA
- The ten grants that reach the most data
How it connects
Read-only access to your identity provider and your HR system. Nothing is installed on a laptop, and no password ever passes through Palisade.
Sources
Connects to what you already run.
Read-only access, no agents to roll out for the first findings. Most teams connect their identity provider and one cloud account in the first hour.
0 / 12 connected· Read-only by default · no credentials stored
- IdentityOktaUsers, groups, admin roles and sign-in policyNot connected
- IdentityEntra IDDirectory roles, conditional access and guestsNot connected
- IdentityGoogle WorkspaceAccounts, super admins and third-party app grantsNot connected
- CloudAWSAccounts, IAM roles, storage and network rulesNot connected
- CloudAzureSubscriptions, role assignments and exposed servicesNot connected
- CloudGoogle CloudProjects, service accounts and public resourcesNot connected
- CodeGitHubSecret scanning on every push and pull requestNot connected
- CodeGitLabPipelines, tokens and repository visibilityNot connected
- DevicesJamfPatch level, encryption and screen lock on Apple devicesNot connected
- DevicesIntuneCompliance state for Windows and mobile devicesNot connected
- AlertsSlackFindings sent to the owner, fixes confirmed in threadNot connected
- TicketsJiraIssues opened with the fix and closed when it landsNot connected
Sources
Connects to what you already run.
Read-only access, no agents to roll out for the first findings. Most teams connect their identity provider and one cloud account in the first hour.
0 / 12 connected· Read-only by default · no credentials stored
- IdentityOktaUsers, groups, admin roles and sign-in policyNot connected
- IdentityEntra IDDirectory roles, conditional access and guestsNot connected
- IdentityGoogle WorkspaceAccounts, super admins and third-party app grantsNot connected
- CloudAWSAccounts, IAM roles, storage and network rulesNot connected
- CloudAzureSubscriptions, role assignments and exposed servicesNot connected
- CloudGoogle CloudProjects, service accounts and public resourcesNot connected
- CodeGitHubSecret scanning on every push and pull requestNot connected
- CodeGitLabPipelines, tokens and repository visibilityNot connected
- DevicesJamfPatch level, encryption and screen lock on Apple devicesNot connected
- DevicesIntuneCompliance state for Windows and mobile devicesNot connected
- AlertsSlackFindings sent to the owner, fixes confirmed in threadNot connected
- TicketsJiraIssues opened with the fix and closed when it landsNot connected
Sources
Connects to what you already run.
Read-only access, no agents to roll out for the first findings. Most teams connect their identity provider and one cloud account in the first hour.
0 / 12 connected· Read-only by default · no credentials stored
- IdentityOktaUsers, groups, admin roles and sign-in policyNot connected
- IdentityEntra IDDirectory roles, conditional access and guestsNot connected
- IdentityGoogle WorkspaceAccounts, super admins and third-party app grantsNot connected
- CloudAWSAccounts, IAM roles, storage and network rulesNot connected
- CloudAzureSubscriptions, role assignments and exposed servicesNot connected
- CloudGoogle CloudProjects, service accounts and public resourcesNot connected
- CodeGitHubSecret scanning on every push and pull requestNot connected
- CodeGitLabPipelines, tokens and repository visibilityNot connected
- DevicesJamfPatch level, encryption and screen lock on Apple devicesNot connected
- DevicesIntuneCompliance state for Windows and mobile devicesNot connected
- AlertsSlackFindings sent to the owner, fixes confirmed in threadNot connected
- TicketsJiraIssues opened with the fix and closed when it landsNot connected
Start here
Run the sweep on your domain.
Tell us where to look. We set up a read-only connection with you on a short call, and you see your own findings the same day.
We will sweep
- Identity providerNot connected
- Cloud accountsNot connected
- DevicesNot connected
- Code repositoriesNot connected
Start here
Run the sweep on your domain.
Tell us where to look. We set up a read-only connection with you on a short call, and you see your own findings the same day.
We will sweep
- Identity providerNot connected
- Cloud accountsNot connected
- DevicesNot connected
- Code repositoriesNot connected
Start here
Run the sweep on your domain.
Tell us where to look. We set up a read-only connection with you on a short call, and you see your own findings the same day.
We will sweep
- Identity providerNot connected
- Cloud accountsNot connected
- DevicesNot connected
- Code repositoriesNot connected
