For the complete documentation index, see llms.txt. This page is also available as Markdown.

πŸ”ŽAccess Inventory

Discover production assets, identities, and access risks across AWS, Google Cloud, Kubernetes, Okta, and Google Workspace with P0's access inventory.

Use P0's access inventory to view your production assets, all the identities that can access them, and associated access risks.

IAM assessment is currently available for AWS, Google Cloud, Kubernetes, Okta, and Google Workspace.

Features

  • Combines IAM data from disparate sources, including your identity provider, your IAM policies, and your cloud access logs

  • Evaluates issues based on risks of individual privileges, using P0's comprehensive open-source IAM Privilege Catalog

  • Detects lateral movement across identities and clouds

How it works in P0

P0 connects to your IAM systems, reading your configuration.

P0 data collection progress indicator showing Collecting Data at 3% while fetching IAM policy data

P0 builds a complete end-to-end access graph for your environment:

Access inventory graph visualization showing identities, entitlements, and resources connected by lateral movement paths

You can query your access graph to find sensitive access to specific resources, specific risks, or more:

Inventory query results table filtered by storage exfiltration risk showing principals, roles, and affected resources
  • Access inventory details β€” Search your inventory, view asset lists, and explore the access graph

  • Query search β€” Write queries to find specific identities, entitlements, and resources

  • Posture overview β€” See access-vulnerability findings detected from your inventory data

Get started with P0's access inventory

Getting set up and collecting your organization's inventory takes about 15 minutes.

  1. Sign up for a P0 account at p0.app/create-account.

  2. Follow the instructions in Creating an Environment.

  3. For a complete walkthrough, see the Getting started with Access Inventory guide.

Last updated