SAINTCON 26 · Session

Mapping the SaaS Attack Surface: An Open-Source Identity Graph and Change-Detection Engine

Speakers

Most companies I've worked with can name maybe half their SaaS apps from memory, and almost none can tell you who holds admin across all of them or what changed last week. SSPM tools check configurations app by app, which helps, but they don't connect identities to permissions to the third-party OAuth apps that quietly hold access. ControlPlane is an open-source project I'm building that takes a different angle: it pulls users, groups, roles, permissions, resources, and OAuth grants out of each SaaS and stitches them into one normalized identity graph, then snapshots that graph on every sync so it can be diffed. That diff is where the value is. It surfaces the things that actually matter, like a new admin, a privilege bump, an over-scoped OAuth install, or external sharing getting flipped on. In this session I'll explain how it's built, demo it live against a couple of test tenants, show the read-only connector framework for Okta, GitHub, Slack, Google Workspace, and Microsoft 365, and walk through the architecture tradeoffs (including the parts I got wrong the first time).

← Full schedule

Security Briefing

Join the mission log

Occasional emails with training announcements, CFP windows, and what's launching at SAINTCON. No spam, no selling your address. Ever.

By subscribing you agree to the Privacy Policy.