Access control & privilege security checks across 49 apps
Admin roles, standing privileges, permission scopes and policy enforcement — the settings that decide how much damage one compromised account can do.
Why it matters
Standing global-admin rights and over-broad API scopes turn a small compromise into a large one. Least privilege is the control an incident review cites first when it asks why one account could do so much, and it is the easiest one to let drift as a tenant grows.
Browse by app
- Microsoft 365 62 checks
- Anthropic 31 checks
- Google Cloud 30 checks
- Teleport 21 checks
- Salesforce 21 checks
- GitHub 21 checks
- Okta 21 checks
- Datadog 20 checks
- DocuSign 20 checks
- OpenAI 19 checks
- Sentry 18 checks
- Google Workspace 17 checks
- Atlassian 17 checks
- OVH Cloud 17 checks
- Grafana Cloud 16 checks
- Shopify 16 checks
- Discord 15 checks
- 1Password 15 checks
- Cloudflare Access 14 checks
- Google Ads 14 checks
- Vercel 13 checks
- LastPass 13 checks
- Terraform Cloud 12 checks
- Grafana 12 checks
- Microsoft Teams 12 checks
- AWS 11 checks
- Snowflake 11 checks
- Workato 10 checks
- Dropbox 10 checks
- Cloudflare 9 checks
- GitLab 9 checks
- Slack 9 checks
- Azure 8 checks
- Zoom 8 checks
- CircleCI 7 checks
- Box 7 checks
- Akamai 6 checks
- PagerDuty 6 checks
- Notion 6 checks
- OpenRouter AI 5 checks
- incident.io 5 checks
- Chrome Enterprise 4 checks
- Cisco Duo 4 checks
- Amazon Bedrock 4 checks
- ServiceNow 4 checks
- Jamf Pro 3 checks
- Workday 3 checks
- n8n 3 checks
- Hugging Face 3 checks
Highest-severity checks
The 8 most severe Access control & privilege checks across all 49 apps — each links to the connector page where the setting, its remediation and its framework mapping are documented.
- Admin Exempt From Login Verification — Box severity: critical
- Admin Staff MFA Disabled — Shopify severity: critical
- Admin User Not Verified — Datadog severity: critical
- Admin Without MFA — Atlassian severity: critical
- Application Without Policies — Cloudflare Access severity: critical
- Bedrock Agent Overprivileged Execution Role — Amazon Bedrock severity: critical
- Cloud KMS Key Publicly Accessible — Google Cloud severity: critical
- Cloud Wildcard Access Policy — Grafana Cloud severity: critical
Where to start
Connect Microsoft 365 first — it carries the most Access control & privilege checks in the catalog(setup guide, read-only access). A first scan takes about 15 minutes and reports every failing check on this page with its remediation steps.