
Identity & Access ManagementAI Security
Obsidian Security Platform
Agentless SSPM and ITDR across SaaS apps, OAuth integrations, and AI agents.
Obsidian Security Platform Overview
What it does
Obsidian Security Platform is a SaaS Security Posture Management (SSPM) and identity threat detection platform covering third-party enterprise applications and the AI agents acting inside them. Its core mechanism is the Obsidian Knowledge Graph, which unifies identity, permission, and activity data reached through a single API connection per application into one model, so weak MFA, inactive accounts, shadow admins, and overly broad OAuth scopes surface as connected risk across the estate rather than as isolated per-application findings, human or non-human.
How it works
One API connection per application surfaces both managed and unmanaged apps tied to corporate identity, and a browser extension extends discovery to shadow apps and AI tools the API path misses while blocking credential submission to adversary-in-the-middle phishing sites. Configuration findings are scored for criticality against built-in or custom policies and mapped to SOC 2, ISO 27001, CIS, and NIST controls for audit evidence. Detection ships as out-of-the-box rules aligned to MITRE ATT&CK alongside machine-learning behavioural baselines, and runtime guardrails intercept policy-violating AI agent executions. Snowflake, T-Mobile, Wyndham Hotels & Resorts, Algolia, and Upwork are named customers.
Credentials and traction
SOC 2 Type II, ISO 27001, ISO 27701, and ISO/IEC 42001 certified, with an IRAP assessment to the PROTECTED classification for the Australian sovereign instance. Named a Strong Performer in The Forrester Wave: SaaS Security Posture Management, Q4 2023, and a Sample Vendor for SSPM in the 2026 Gartner Hype Cycle for Cyber-Risk Management. Received the SINET16 Innovator Award in 2023 and ranked No. 95 on the 2025 Deloitte Technology Fast 500. Sold to Fortune 1000 and Global 2000 enterprises.
Key Capabilities
mapped to solution categoriesIntegrates with enterprise SaaS applications through native admin APIs to assess tenant configuration, identity, and third-party connections, including Microsoft 365, Google Workspace, Salesforce, Slack, GitHub, ServiceNow, and Okta. Breadth and depth of coverage vary by product.
Maps SaaS configuration findings to CIS SaaS Benchmarks, NIST 800-53, and SOC 2 control requirements, generating evidence for auditors from automated assessment.
Discovers OAuth-connected third-party applications with access to core SaaS environments, maps their granted permissions, and flags high-risk or unused authorizations for revocation.
Maps integration connections between SaaS applications (API keys, webhooks, shared credentials) to surface unmanaged data flows and integration attack surface.
Identifies over-privileged users, dormant accounts, and excessive license assignments within SaaS applications, producing a right-sizing recommendation per application.
Automatically corrects specific SaaS misconfigurations or revokes excessive permissions without manual intervention.
Detects sensitive content shared publicly or externally from connected SaaS apps, such as world-readable files, anonymous share links, and over-shared folders, so exposure can be revoked before it leaks.
Discovers service accounts, OAuth apps, API keys, JWT tokens, and Kubernetes service accounts alongside human accounts, mapping the complete identity population.
Flags dormant and zombie accounts, weak access policies, and identity misconfigurations (such as missing MFA or risky discretionary access) so they can be cleaned up before attackers use them.
Compares granted permissions against observed usage to identify entitlements that exceed what an identity actually needs, candidates for right-sizing or revocation.
Detects indicators of identity compromise and attack activity (anomalous login sequences, MFA fatigue patterns, impossible travel), at the posture layer, enabling detection of active attacks alongside the static risk posture view. Distinct from EDR identity threat detection, which operates as real-time behavioral detection during an active attack.
Analyzes identity telemetry (authentication events, access patterns, privilege use) in real time with behavioral baselines and risk scoring; leading implementations detect identity attacks in sub-second time.
Detects credential-abuse techniques that defeat authentication controls, including MFA circumvention, session hijacking, and forged or replayed tokens.
Detects attacks against the IAM infrastructure itself - directories, identity providers, federation, and IAM configurations - including admin credential misuse and manipulation of identity controls.
Automatically discovers AI models, LLM API connections, ML pipelines, and AI-enabled SaaS applications in use across the organization, including those deployed without IT authorization.
Assesses the identities and service accounts that AI models, pipelines, and agents use, flagging over-permissioned non-human identities and access paths that violate least privilege. Reports identity risk as a posture finding, distinct from enforcing access policies at the model API at runtime.
Discovers and enforces least-privilege access for non-human and AI-agent identities across systems and data.
Monitors AI-agent behavior at runtime to detect anomalous or malicious actions and policy violations.
Detects sensitive or regulated data in AI training, fine-tuning, or third-party LLM flows without appropriate controls, such as unencrypted PII in inputs or PHI sent to external APIs.
Discovers AI model and inference endpoints and flags public exposure, weak authentication, default credentials, or excessive permissions as posture misconfigurations.
Maps data lineage and provenance across AI training and inference pipelines, tracing how PII, PHI, and IP move into models and external services.
Discovers and categorizes the organization's use of third-party AI, whether consumed as a service, installed locally, or embedded inside other applications, building a continuously updated inventory of AI usage including shadow AI.
Defines organizational AI usage policies and enforces them at the point of use - allowing, blocking, redirecting, or constraining specific AI services, models, and features per user, group, or data context.
Inspects prompts, uploads, and AI-generated responses for sensitive data across modalities, preventing exposure of regulated or proprietary information to third-party AI services.
Enforces AI usage controls through multiple local inspection points - browser, endpoint, and network - coordinated from a cloud-delivered control plane, so coverage does not depend on a single interception path.
Compliance
certificationsIntegrations
compatible toolsImplementation & support
Info last updated on July 26, 2026
Vendors
Is this your product?
Claim your profile to connect with the teams looking for your solutions.