A single graph of every machine identity and every path it can take.
Identrail ingests IAM principals, role chains, OIDC trust policies, Kubernetes service accounts, RBAC bindings and resource ACLs across every environment you connect, then resolves the closure: who can reach what, through which hops, under which conditions.
- Cross-account AssumeRole resolution
- OIDC federation through GitHub Actions, EKS, GKE
- Conditional policies (PrincipalTag, source IP, MFA) honoured
- Workload identity → cloud identity stitching