It gave us a number we could actually reduce. Before this, our attack-surface conversations were mostly theoretical. We knew there were OAuth grants, dormant accounts, and unsanctioned apps out there; we just couldn’t quantify any of it. The first full scan pulled together every connected app, every token, every account that didn’t map to an active employee, and every app with a weak security posture score. All of a sudden, we had a clear list ranked by risk, plus a practical way to work it down week by week. Review collected by and hosted on G2.com.
Funny enough, my only complaint is that I want more of what they’re already best at. The direct integrations are so good that now I find myself wishing there were one for every tool we use, even the obscure regional vendors that nobody else seems to integrate with. To be fair, they keep adding more, and there’s a universal connector that helps cover the gaps, so this is really just a temporary gripe at best. Review collected by and hosted on G2.com.