Know Early access
See every identity that can act.
AI tools, agents, API keys and people all hold access. qbrin puts them in one list, scores how much damage each could do, and writes the fix next to it.
- People, agents, keys, tools
- Scored from your own records
- Every action confirmed and audited
- Alerts
- 33 high
- Blast radius
- Acts on its own
- Exposures
- 5
- Sign-off
- Not required
- Incidents
- 0
Can read
gmailcalendargdriveslackgithubjira- no data scope: every source
Investigate
3
3 things a person should look at
- Possible prompt injection caught (2 times)
- An agent was refused an action
- +1 more
Fix
5
5 settings to change to shrink the damage
- Reads everything and can act on it
- Can act without sign-off
- Can read the whole company’s data
- +2 more
Remove
0
Nothing to do
This is the Overview tab. Each identity also has Access, Activity and Risks tabs in the console.
What counts
Anything that can act is an identity.
Not just people. Every AI agent, AI tool, key and connection can read or change something in your company, so each one gets a row and a score.
People
Members of your workspace. Know flags an admin nobody has seen in a long time.
AI agents
Agents that read and act for you. Each one shows what it can read and whether a person approves its actions.
AI tools
Outside tools such as a code-review bot or a support assistant. They show up as the key or agent they use to call qbrin.
API keys
Keys that let software call qbrin. Know shows keys with full access, keys that never expire and keys nobody uses.
Integrations
The mail, chat and drive accounts qbrin reads from. Know flags connections that are failing, revoked or gone quiet.
Unmanaged tools
Tools qbrin’s detector sees in your mail, calendar and chat that are not connected through qbrin.
In the console, the Security page has three views, called Discover, Protect and Defend. On this site the three jobs are Know, Scope and Check.
What Know does
List it. Score it. Act on it.
One inventory, one score, one feed of what the gate caught, and one set of confirmed responses, all built from the same records.
01 · Inventory
One list of everything that can act.
Know pulls people, agents, API keys, connections and unmanaged tools into one inventory. Filter it by kind, sort it by exposure, and open any row to see why it scored what it did.
- Filter by kind or exposure level, or search by name or owner
- Each row says what the identity can do and when it last did anything
- Tools the detector finds sit in the same list, marked as unmanaged
HighToken has full access
It has no scope limit, so anything holding it can read and change everything in the workspace.
Fix: Replace it with a token limited to read, or to write only where needed.
MediumToken never expires
If it leaks, it works until someone notices and revokes it.
Fix: Set an expiry (for example 90 days) and rotate it.
Showing 8 of 8 identities. Select a row to see why it scored what it did.
02 · Exposure
A score you can act on. Fixes, biggest first.
Each identity is scored on what it can actually do: a key with full access, an agent that reads everything, an action nobody approves. The company grade is not a plain average, because an average hides the one identity that is the real problem. qbrin adds a penalty when many agents can read everything, and holds the grade down whenever any identity is rated Critical or High.
- Every line of the score is something qbrin counted in your own records
- Fixes are ranked biggest first, each one linked to the identities it affects
- Hundreds of tidy identities cannot average one dangerous one away
2 of your 3 AI agents can read your whole company.
Posture runs 0 to 100, higher is safer. It is worked out from the 8 identities in this sample workspace.
- −7 because 2 of 3 active agents can search everything, so losing any one of them exposes everything.
- 1 agent can write, send or run code with no person approving.
CriticalReads everything and can act on it1 identity
Fix: Break the pair: narrow what it can read, or require sign-off for what it can do.
HighCan act without sign-off1 identity
Fix: Require a person’s sign-off, or limit it to a specific list of targets.
HighToken has full access1 identity
Fix: Replace it with a token limited to read, or to write only where needed.
MediumCan read the whole company’s data2 identities
Fix: Give it a data scope: only the sources and folders its job needs.
MediumToken never expires2 identities
Fix: Set an expiry (for example 90 days) and rotate it.
03 · What the gate caught
See what was caught, refused or held.
One feed of every detection, refused action and held action, with a count per day. Nothing in it is scored or guessed: each row is a record that already exists, with the next step written under it.
- Detections such as possible prompt injection, a secret leaving the workspace or a spending limit reached
- Actions the check step refused, or held for a person to decide
- Filter by time window, severity and kind
11 items caught, refused or held in the last 7 days. 412 actions were allowed.
Allowed actions
412
Refused actions
6
Flagged in total
11
HighBlocked
Possible prompt injection caught
Text in a support ticket told the agent to ignore its rules and write to another system.
support-triage agent · 2 hours ago
Check where the text came from, and keep this agent’s write and send actions on sign-off.
MediumHeld for a person
An action was held for a person
write on finance sheet: needs a person to approve
finance-reports agent · yesterday
Review it in Approvals; it will not run until someone decides.
MediumBlocked
Secret leaving the workspace was blocked
A meeting summary draft contained what looked like an API key.
meeting-notes agent · 3 days ago
Find which source held the secret and rotate it if it was real.
04 · Respond
Respond with one confirm.
From an identity’s page you can require sign-off for every action, pause or resume an agent’s schedules, or revoke a key. Each action is confirmed first, written to the audit log, and only offered when it would change something. Add an identity to the watchlist to keep an eye on it.
- A person confirms every action, in plain words about what will happen
- Each action writes an audit record that says who did it
- The watchlist is an append-only trail, so changes to it are audited too
support-triage agent
Critical87Pick an action. Nothing runs until you confirm.
Audit trail
Nothing yet. Every action you confirm is recorded here.
These actions really change the sample workspace on this page. Scroll back up to the list and the grade after you confirm one.
Next
Seeing it is step one.
Know shows who holds too much. Scope shrinks what each one can read, and Check stops the action itself.
Scope
Give each agent and each AI-tool key only the sources its job needs, and preview what that would have cut before you save it.
See how scoping worksLiveCheck
Before an agent acts, qbrin checks the proof against current evidence and policy, and answers go, hold or ask a person.
See how the check worksSee who can act in your company.
Book a demo to see the inventory, the exposure score and the response actions. Know is in early access.