Resources
FAQ

Frequently asked questions

Quick answers about what IntegraTrace does, the access it needs, the clouds it covers, and how to get started securing every identity in your environment.

Read-only by design
IntegraTrace is agentless and connects with read-only access only. It analyzes your IAM posture without the ability to modify your cloud environment.

General

What is IntegraTrace?

IntegraTrace is an identity security platform for the AI era. It discovers, maps, and continuously verifies every human and non-human identity across your AWS, Azure, and Google Cloud environments — so over-privileged access, dormant credentials, and risky privilege chains have nowhere to hide.

What problem does IntegraTrace solve?

In modern cloud environments, non-human identities outnumber people by as much as 82 to 1, and roughly 80% of cyber attacks exploit IAM weaknesses. Those identities accumulate permissions faster than any team can audit them. IntegraTrace gives you a single, continuously updated view of who and what can access your cloud, ranks the identities that put you most at risk, and tells you exactly which permissions to remove.

Who is IntegraTrace for?

Cloud security, IAM, DevOps, and platform teams responsible for securing multi-cloud infrastructure — plus the compliance and audit stakeholders who need defensible evidence of least-privilege access.

Non-human identities (NHIs)

What is a non-human identity?

A non-human identity is anything that authenticates programmatically, without a person at the keyboard: service accounts, API keys and tokens, CI/CD pipelines, OAuth applications, machine-to-machine identities, and AI agents. They typically hold long-lived credentials, rarely use multi-factor authentication, and are frequently over-privileged — which makes them a prime target.

How does IntegraTrace discover NHIs?

IntegraTrace connects to your cloud providers with read-only access and automatically catalogs every service account, API key, machine identity, and AI agent. There are no agents to install and no blind spots — discovery is continuous, so new identities are picked up as they are created.

Can IntegraTrace secure AI agents?

Yes. IntegraTrace is purpose-built for the age of autonomous systems. It tracks every action an AI agent takes, flags anomalous behavior, and shows the full blast radius of what a compromised agent could reach — giving you the visibility and control to adopt AI confidently.

Platform & features

Which clouds does IntegraTrace support?

AWS, Microsoft Azure (including Entra ID), and Google Cloud. Identities and access are normalized into a single model, so you get one consistent view across all three providers.

What is identity blast radius?

Blast radius is everything a single identity could reach if it were compromised. IntegraTrace builds a live access graph connecting every identity to the roles, policies, and resources it can touch — directly or through privilege-escalation chains — so you can instantly see which compromised credential would be catastrophic.

How does IAM risk analysis work?

IntegraTrace analyzes effective permissions — the access an identity actually has once every role, policy, and group is resolved — to surface risk that raw policy reviews miss. It ranks over-privileged and dormant identities, highlights toxic permission combinations and drift from least privilege, and recommends exactly which permissions to remove.

What are System Access Requests (SAR)?

System Access Requests replace standing privilege with just-in-time access. Users request the access they need, approvers grant it in one auditable click, and every grant is automatically time-boxed so it expires when the work is done — shrinking the window an attacker can exploit while leaving a clean audit record.

What are Access Trails?

Access Trails are an immutable, queryable history of who and what touched every resource. IntegraTrace normalizes IAM and audit events from each cloud into a single timeline, so investigations and audits that used to take weeks take minutes.

Security & access

What access does IntegraTrace need to my cloud?

Read-only access only. On AWS that means an IAM role with IAMReadOnlyAccess, on Azure an app registration with the Reader role, and on Google Cloud a service account with the Viewer role. IntegraTrace analyzes your IAM posture without the ability to modify your environment.

Does IntegraTrace install agents in my environment?

No. IntegraTrace is agentless. It connects through native, read-only cloud APIs, so there is nothing to deploy, patch, or maintain inside your infrastructure.

How are my credentials protected?

Connection credentials are encrypted, and access is scoped to the minimum read-only permissions required to analyze your identity posture. IntegraTrace never requests write access to your resources.

Compliance

Is IntegraTrace compliant with security standards?

IntegraTrace maintains a SOC 2 Type II certification, independently issued by a licensed CPA firm and available under NDA on request, and helps you generate audit-ready evidence for frameworks such as SOC 2, ISO 27001, and other regulatory requirements.

Can IntegraTrace help with audits?

Yes. Because every IAM change and access event is captured in an immutable timeline, you can demonstrate least-privilege access and answer auditor questions in minutes instead of assembling evidence by hand across multiple clouds.

Getting started

How long does setup take?

Most teams connect a cloud environment in minutes. You create a read-only role for each provider you want to monitor, connect it, and IntegraTrace begins discovering identities and building your access graph automatically.

How do I get started?

Follow the environment setup guide for your cloud (AWS, Azure, or Google Cloud) to create a read-only role, then connect it. If you'd like a walkthrough, reach out through the get-started page and the team will help you scope your first analysis.

Still have questions?

These guides go deeper on the concepts and setup referenced above:

  • Knowledge Center — non-human identities, permissions sprawl, and how IntegraTrace solves them
  • How It Works — complete visibility into every identity in three steps
  • Environment Setup — connect a read-only role for AWS, Azure, or Google Cloud
  • Multi-cloud: AWS, Azure, and Google Cloud
  • Agentless, read-only, encrypted credentials
  • SOC 2 Type II Certified
  • Set up in minutes