Schedule 15 Minute Ai Risk Review
Platform

See Which Identities Your AI Is Using

Map every AI to the humans and non-human identities behind it, and everything those identities can reach.

100%
Identity Mapping
Real-time
Exposure Graphs
Zero
Blind Spots
Inheritance

How an AI agent ends up with permissions nobody approved

which means
so

IAM tools were not built to trace agents, MCP tools, and model calls back to the identity that made them. They answer who is this principal correctly, and what is calling as this principal, and how far does that call reach, not at all.

How It Works

Every AI Resource, the Identity It Runs As, and What That Identity Can Touch

AIBound resolves every AI back to the identity it operates as, and traces exactly what that identity can reach.

app.aibound.io / AI Identity Graph
AI ResourceIdentityConnectionsBlast Radius
Cursor Agentsvc-eng-01GitHub · Jira · Prod DBHigh
Sales GPTamy@corp.ioSalesforce · GmailMedium
Support Botsvc-ai-helpZendesk · S3Medium
MCP: FS-Readroot shell/ (full disk)Critical
Copilot Chatdev group (43)Repo scopeLow
Live Platform Preview
  • Map every AI resource to the human or service identity it operates as
  • Trace every data and system connection per AI resource
  • Reveal malicious or excessive skills and permissions
  • Visualize blast radius before an incident, not after

What Low, Medium, High and Critical Actually Mean

A blast radius rating is only useful if the scale behind it is published. These are the four tiers as they read against the graph above.

Low

The identity reaches a single scoped surface, and that surface holds no regulated or production data. Copilot Chat, running as a 43 person developer group with repository scope, sits here.

Medium

The identity reaches multiple business systems, at least one of which holds customer or employee records. Sales GPT reaching Salesforce and Gmail as a named human sits here, and so does Support Bot reaching Zendesk and S3 as a service account.

High

The identity reaches production. Cursor Agent, running as svc-eng-01 with GitHub, Jira and production database connections, sits here.

Critical

The identity reaches everything, with no boundary left to describe. The MCP filesystem read server, running as a root shell against the whole disk, sits here.

FAQ

Frequently Asked Questions

An AI identity graph maps every AI resource to the human or service identity it operates as, then traces every system, dataset, and agent that identity can reach. It answers two questions a permissions list cannot: what is calling as this principal, and how far does that call reach. A permissions list is a static inventory of grants. A graph is a map of reach, which is what determines the damage if the resource is compromised.

Source: Definitional. Derived from AIBound's own live product description on this page. No third party statistic used.

A non-human identity is a credential that belongs to software rather than to a person: a service account, an API token, a workload identity, or an agent's inherited credential. AI agents typically run as one. That is why an agent can hold entitlements without any named individual being accountable for the grant, and why the agent's reach is usually discovered after an incident rather than before one.

Source: Definitional. Scope wording matches Cybersecurity Insiders, 2026 CISO AI Risk Report, January 2026, which defines AI identities as service accounts, agents, and other non-human identities.

IAM platforms govern the lifecycle of identities and their entitlements. They do not observe which AI resource is calling as a given identity, nor which downstream systems that call actually touches. IAM was specified before agents, MCP servers, and model calls existed as callers, so this is a scope boundary rather than a defect. AIBound sits on the calling side of that boundary and resolves the caller back to the identity.

Source: Definitional, plus AIBound's own live claim on this page that IAM tools were not built to trace agents, MCP tools, and model calls back to the identity that made them.

Blast radius is the full set of systems, datasets, and agents a single AI resource could reach through the identity it operates as, assuming that resource were compromised. It is a property of the identity's entitlements, not of the AI tool's intended function. A summarization assistant running as a production service account has a production blast radius even though summarizing is harmless.

Source: Definitional.

Yes. The graph resolves AI resources operating as named human accounts and as service accounts alike, which is why one row in the published example reads amy@corp.io and the next reads svc-ai-help. This matters because the two cases fail differently: a service account has no owner to ask, and a human account carries that person's full standing entitlements into whatever the agent does.

Source: AIBound's own published example table on this page, rows Sales GPT and Support Bot.

"
We had no idea our agents were running with the same rights as our engineers, until we saw the graph.
Head of Identity
Global Financial Services Firm

Map Every AI to the Identity Behind It

See every AI resource, the identity it runs as, and everything that identity can reach, in one view.