AI Agent Identity Simulation

Demo

See how agent sprawl + inherited credentials create hidden risk

Legend
Read-only
Stale
Sensitive
D0
051015202530
D30
Speed
0/30

Starting Point

Starting clean: 1 agent, 3 read-only tokens. This is how it should be.

Agent Graph1 agent ยท 3 systems
Read
Stale
Write/Admin
AGENTSSYSTEMSSASupport Agent๐Ÿ’ฌ Slackโ˜๏ธ Salesforce๐Ÿ“‹ Jira
Event Stream
4 events
Day 0okta

Support Agent Created

Enterprise Support Agent provisioned with read-only access to Slack, Jira, and Salesforce.

Day 0slack

Read-only Token Issued โ€” Slack

OAuth token granted with read:messages scope. Least privilege enforced.

Day 0jira

Read-only API Key โ€” Jira

API key issued with read:issues scope. Token expires in 90 days.

Day 0salesforce

Read-only Token โ€” Salesforce

OAuth token with read:contacts scope. No write access.