Graph-Based SaaS Identity Mapping

Diving deeper into

Obsidian Security

Company Report
The graph allows analysts to run cross-application queries that individual SaaS admin consoles cannot answer
Analyzed 7 sources

This graph turns SaaS security from app by app checking into relationship level investigation. A Salesforce console can show one user or one token inside Salesforce, but it cannot show how that identity connects to Slack, Okta, Google Workspace, or an AI agent that acts through a borrowed service account. Obsidian’s model is built to stitch those objects together, so analysts can ask who can reach what, through which path, and when that path changed.

  • The practical gain is path analysis. Instead of reviewing separate admin screens, a team can trace a chain from employee, to OAuth app, to token, to service account, to data source. That is how dormant accounts, overbroad grants, and agent driven privilege mismatches become visible.
  • This is becoming the core product battle in SaaS security. CrowdStrike now pitches Falcon Shield as coverage across more than 175 SaaS apps with AI agent visibility, and Microsoft exposes a cross workload exposure graph. The category is shifting toward graph based systems of record, not single app posture checks.
  • The time versioning matters as much as the graph itself. During an incident, security teams need to reconstruct when an OAuth grant was added, when an account became dormant, or when an agent gained access. A static snapshot misses the sequence that explains how access actually spread.

The next step is for SaaS security tools to become control planes for human and non human identity across apps. As AI agents create more indirect access paths, the winning products will be the ones that can continuously map those paths, score which ones are dangerous, and shut down risky chains before data leaves the system.