A founding document
Cybercrime changed sides of the login screen. Security never followed.
For thirty years we defended the private network, then the endpoint. Meanwhile the attack became a permission, the attacker became a login, and the battlefield became who-can-reach-what inside the world’s collaboration platforms. There is no shelf for the tool that watches this. So we built it.
Three eras
Private network. Endpoint. Identity.
The first era built walls: firewalls, gateways, DMZs. The attack was a packet, and the industry built a shelf of tools to inspect packets.
The second era followed the attack onto the machine: antivirus, then EDR. The attack was a process, and the industry built a shelf of tools to watch processes.
The third era is already here. The attack is a permission exercised by a valid login - no exploit to patch, no signature to match, no malicious process to kill. The industry built no shelf for it. SIEMs store the evidence without understanding it; IAM provisions identities without watching them; compliance scanners photograph the crime scene once a quarter.
The blind spot
Nobody knows who has access to what.
Not as a slogan - as the observed condition of essentially every Microsoft 365 tenant on Earth, including well-run ones. Access accumulates in seven places at once: direct grants, sharing links, group memberships, site roles, application permissions, agent knowledge sources, inheritance. No native surface joins them into one answer.
Attackers know this. It’s why they stopped breaking in.
- 600M/dayidentity attacks (Microsoft, 2024)
- 70%of breaches exploit excessive permissions
- 98%of granted permissions are never needed
Doctrine
What the category must do.
A tool that fails any of these is a dashboard, not a defense.
- 01
The map is always on
A quarterly scan is a photograph of a river. The permission map must be live, or it is already wrong.
- 02
The answer must not need an expert
The truth about access currently lives in the heads of a few people who understand SharePoint inheritance, nested Entra groups and Graph semantics - and it dies when they change jobs. A category that only pays out for specialists has not solved the problem; it has moved it. Anyone in the room should be able to read who can reach what, and be right.
- 03
Minutes to know, not months
The measure of this category is the clock. “Were we breached, and what did they reach?” is answered today in weeks of log forensics, by which time the answer is archaeology. It has to be minutes - not because speed is impressive, but because every hour between the question and the answer is an hour the intruder keeps the access.
- 04
Record everything, alert on your line
Every deviation is kept; the alert threshold belongs to you, not to a vendor’s idea of your risk appetite - and moving it re-classifies history instantly.
- 05
Findings must carry fixes
A finding without a remediation path is homework. Detection and repair belong on the same screen, with human review where it matters.
- 06
Every identity counts
Humans, service accounts, OAuth apps, AI agents, devices. If it can touch data, it is an identity - and it gets the same map, baseline and history as an employee.
- 07
It has to pay for itself on the simple things
Visibility of this kind is infrastructure: it must run on standard licenses, not behind an E5 upsell or a SIEM contract. And it has to be worth its price on the first, dullest use case - the guests who never left, the licenses nobody reclaimed - before any programme, transformation or roadmap. A product that only earns its keep after a services engagement is charging you to finish it. Expertise on top should be a partner adding judgement, never a tax for making the tool work.
The first instrument
1Security is the category’s first instantiation.
One living graph of every identity and every path to data in Microsoft 365 - watched in real time, remembered for three years, and wired to act. This is not a feature list; it is the doctrine above, running.
Not only our thesis
Microsoft’s own innovation programme backs it.
A manifesto is easy to write and cheap to believe. Microsoft’s Innovation Alley partners with 1Security and recommends it to the ecosystem - the platform whose tenants this category is about, arriving at the same conclusion independently. Being first in a category is only an advantage if somebody else can see the category too.
First to build it, and already trusted around the tenants it maps.
If you run Microsoft 365, you already have the problem.
Now there’s a tool for it. See it on your own tenant - read-only, today.