Skip to content

Know Early access

See every identity that can act.

AI tools, agents, API keys and people all hold access. qbrin puts them in one list, scores how much damage each could do, and writes the fix next to it.

  • People, agents, keys, tools
  • Scored from your own records
  • Every action confirmed and audited
Identity · support-triage agentIllustrative
AI agentOn watchlistLast 30 days

This agent can read everything and act on it with nobody approving.

Alerts
33 high
Blast radius
Acts on its own
Exposures
5
Sign-off
Not required
Incidents
0

Can read

  • gmail
  • calendar
  • gdrive
  • slack
  • github
  • jira
  • no data scope: every source

Investigate

3

3 things a person should look at

  • Possible prompt injection caught (2 times)
  • An agent was refused an action
  • +1 more

Fix

5

5 settings to change to shrink the damage

  • Reads everything and can act on it
  • Can act without sign-off
  • Can read the whole company’s data
  • +2 more

Remove

0

Nothing to do

This is the Overview tab. Each identity also has Access, Activity and Risks tabs in the console.

What counts

Anything that can act is an identity.

Not just people. Every AI agent, AI tool, key and connection can read or change something in your company, so each one gets a row and a score.

People

Members of your workspace. Know flags an admin nobody has seen in a long time.

AI agents

Agents that read and act for you. Each one shows what it can read and whether a person approves its actions.

AI tools

Outside tools such as a code-review bot or a support assistant. They show up as the key or agent they use to call qbrin.

API keys

Keys that let software call qbrin. Know shows keys with full access, keys that never expire and keys nobody uses.

Integrations

The mail, chat and drive accounts qbrin reads from. Know flags connections that are failing, revoked or gone quiet.

Unmanaged tools

Tools qbrin’s detector sees in your mail, calendar and chat that are not connected through qbrin.

In the console, the Security page has three views, called Discover, Protect and Defend. On this site the three jobs are Know, Scope and Check.

What Know does

List it. Score it. Act on it.

One inventory, one score, one feed of what the gate caught, and one set of confirmed responses, all built from the same records.

01 · Inventory

One list of everything that can act.

Know pulls people, agents, API keys, connections and unmanaged tools into one inventory. Filter it by kind, sort it by exposure, and open any row to see why it scored what it did.

  • Filter by kind or exposure level, or search by name or owner
  • Each row says what the identity can do and when it last did anything
  • Tools the detector finds sit in the same list, marked as unmanaged
Discover · everything that can actIllustrative
    • HighToken has full access

      It has no scope limit, so anything holding it can read and change everything in the workspace.

      Fix: Replace it with a token limited to read, or to write only where needed.

    • MediumToken never expires

      If it leaks, it works until someone notices and revokes it.

      Fix: Set an expiry (for example 90 days) and rotate it.

Showing 8 of 8 identities. Select a row to see why it scored what it did.

02 · Exposure

A score you can act on. Fixes, biggest first.

Each identity is scored on what it can actually do: a key with full access, an agent that reads everything, an action nobody approves. The company grade is not a plain average, because an average hides the one identity that is the real problem. qbrin adds a penalty when many agents can read everything, and holds the grade down whenever any identity is rated Critical or High.

  • Every line of the score is something qbrin counted in your own records
  • Fixes are ranked biggest first, each one linked to the identities it affects
  • Hundreds of tidy identities cannot average one dangerous one away
Protect · what to fix, biggest firstIllustrative

2 of your 3 AI agents can read your whole company.

Posture runs 0 to 100, higher is safer. It is worked out from the 8 identities in this sample workspace.

  • −7 because 2 of 3 active agents can search everything, so losing any one of them exposes everything.
  • 1 agent can write, send or run code with no person approving.
  1. CriticalReads everything and can act on it1 identity

    Fix: Break the pair: narrow what it can read, or require sign-off for what it can do.

  2. HighCan act without sign-off1 identity

    Fix: Require a person’s sign-off, or limit it to a specific list of targets.

  3. HighToken has full access1 identity

    Fix: Replace it with a token limited to read, or to write only where needed.

  4. MediumCan read the whole company’s data2 identities

    Fix: Give it a data scope: only the sources and folders its job needs.

  5. MediumToken never expires2 identities

    Fix: Set an expiry (for example 90 days) and rotate it.

03 · What the gate caught

See what was caught, refused or held.

One feed of every detection, refused action and held action, with a count per day. Nothing in it is scored or guessed: each row is a record that already exists, with the next step written under it.

  • Detections such as possible prompt injection, a secret leaving the workspace or a spending limit reached
  • Actions the check step refused, or held for a person to decide
  • Filter by time window, severity and kind
How the check step decides
Defend · what the gate caughtIllustrative

11 items caught, refused or held in the last 7 days. 412 actions were allowed.

Allowed actions

412

Refused actions

6

Flagged in total

11

Flagged per day
  • HighBlocked

    Possible prompt injection caught

    Text in a support ticket told the agent to ignore its rules and write to another system.

    support-triage agent · 2 hours ago

    Check where the text came from, and keep this agent’s write and send actions on sign-off.

  • MediumHeld for a person

    An action was held for a person

    write on finance sheet: needs a person to approve

    finance-reports agent · yesterday

    Review it in Approvals; it will not run until someone decides.

  • MediumBlocked

    Secret leaving the workspace was blocked

    A meeting summary draft contained what looked like an API key.

    meeting-notes agent · 3 days ago

    Find which source held the secret and rotate it if it was real.

04 · Respond

Respond with one confirm.

From an identity’s page you can require sign-off for every action, pause or resume an agent’s schedules, or revoke a key. Each action is confirmed first, written to the audit log, and only offered when it would change something. Add an identity to the watchlist to keep an eye on it.

  • A person confirms every action, in plain words about what will happen
  • Each action writes an audit record that says who did it
  • The watchlist is an append-only trail, so changes to it are audited too
Identity · actionsIllustrative
Pick an identity to act on

support-triage agent

Critical87

Pick an action. Nothing runs until you confirm.

Audit trail

Nothing yet. Every action you confirm is recorded here.

These actions really change the sample workspace on this page. Scroll back up to the list and the grade after you confirm one.

See who can act in your company.

Book a demo to see the inventory, the exposure score and the response actions. Know is in early access.