Identity is where small companies accumulate risk fastest, because access is granted in a hurry and almost never taken back. Nobody sets out to leave a former contractor with admin rights. It just happens, quietly, and then stays true.
We check whether multi-factor authentication is actually enforced rather than merely available, and name the accounts still outside it. We read the password policy, the recovery options attached to each account, and whether legacy sign-in methods that skip modern protection are still accepted.
We count super admins and say how far that runs past what a company your size should have. We find accounts that are dormant or suspended and still hold access, and roles whose permissions reach well past the work the person is doing.
People are not the only things with access. We list the third-party apps holding a grant and the scopes each one was given, along with the service accounts, delegation, and keys that were issued once and set never to expire.
Those questions are the shape of it, not the inventory. Underneath them is a larger set of individual settings we read on each platform, and it moves every time a platform ships something new.
Where a CIS safeguard fits the evidence, the finding carries it, so the answer you give an auditor is the answer we already gave you. Where none fits, we leave it unmapped rather than claim a control we cannot stand behind.
Each finding names the specific account or role, not just the setting.
Every change is prepared for you, made only once you approve it, logged, and reversible where the platform allows. How that works
Today we read identity from Google Workspace, AWS, GitHub, Cloudflare and Vercel. More platforms are in development.