Rank every path an attacker could take.
Every identity and asset scored by what an attacker could reach from it — ranked attack paths on demand.
Everything Samyoga builds follows from that one sentence. This page is the argument behind it, in full, including the parts we cannot yet do.
Every enterprise keeps a register of what it owns. A CMDB, a spreadsheet, an asset inventory in a procurement tool, usually all three disagreeing. It is assembled by hand, signed off once, and stale by the following week, because the only thing keeping it true is a person remembering to update it.
For thirty years that was survivable. Humans moved at human speed. A wrong row in the CMDB cost you a support ticket routed to the wrong team, or a server nobody patched because nobody knew it was there. Annoying, occasionally expensive, rarely fatal.
The register was never the control. It was paperwork about the control. Nobody made a decision at three in the morning on the strength of a CMDB entry.
Non-human identities now outnumber human ones inside a typical enterprise, and the gap is widening every quarter. Service accounts, CI runners, integration users, and now agents: things that hold credentials, act without being watched, and never sleep.
An agent is given a scoped credential and told to get on with it. That scope is a claim about reach — these systems, this data, no further. And the scope is computed from a map. Somebody looked at an inventory, decided what this thing needs to touch, and cut the permissions to fit.
If the map is wrong, the scope is wrong. The difference is that the agent will exercise the whole of its actual reach, at machine speed, and nobody finds out what that was until afterwards.
This is the part that makes an old problem newly fatal. A stale inventory used to produce a missed patch. A stale inventory now produces a confident, automated, wildly over-scoped actor operating on your behalf, and an incident review that starts with the sentence we did not know it could reach that.
A CMDB is a system of record. Its defining property is that it is true only while somebody keeps it true. Every serious attempt to improve it has been an attempt to make that somebody faster, better resourced, or better disciplined: import scripts, reconciliation rules, data-quality dashboards, a quarterly attestation ritual.
All of it treats human maintenance as the thing to optimise. None of it questions whether the map should be maintained at all.
The fix is to stop declaring the map and start deriving it.
Your estate already emits an account of itself, continuously, in enormous volume. Every authentication, every firewall session, every endpoint event, every cloud API call, every vulnerability scan is a statement about what exists and what talks to what. Nothing was reading it as a description of the enterprise. It was being read as alerts.
Read what the estate already emits. Connectors take XDR, firewall, identity, vulnerability, cloud, and OT telemetry over API or syslog. Nothing to install on an endpoint, nothing to migrate, no new agent asking for a credential of its own.
Resolve every record to a canonical entity. The same host arrives spelled nine ways across nine tools; the same person is an email in one system, a SAM account in another, a service principal in a third. Normalize, fold case, merge duplicates, and the nine become one.
Join identity to asset to OT in a single graph, and the reachability question becomes answerable for the first time: from this account, through these credentials and trusts, what can actually be touched, and which of those routes has nothing watching it.
Then keep doing it. The graph is rebuilt continuously, because a derived map that goes stale is just a CMDB with better provenance.
A map is not the product. Three answers come out of it, and they are the reason anyone pays for the first four sections of this page.
Every identity and asset scored by what an attacker could reach from it — ranked attack paths on demand.
The graph knows which routes to your crown jewels have nothing watching them — that is where the decoys go.
Each dispatch ships the playbook change that would have deflected it — and claims a tier lift only after measured deflection clears the bar.
Tier 2 means you know your risks. Tier 4 means your program adapts to them on its own evidence. Every prescription carries a recorded tier claim — 2 to 3, 3 to 4 — and none advances until measured deflection clears the bar. Your CSF tier moves, and you can prove it moved.
Four surfaces over the one graph. Same data, four questions.
Reads your existing lake and resolves humans, machines, AI agents, and service principals into a single graph, ranked by what an attacker could reach from each one.
Rules, models, and narrators ship as a versioned canon you can review, audit, and override per tenant. No black-box detections and no surprise prompt changes after a procurement review.
What is currently lit up: where intel matches your environment and which campaigns are actively running. The surface your SOC opens at the start of a shift.
Outliers across the identity graph, similarity clusters, causal edges with confidence intervals, and forecasted edges before they fire.
The algorithms that turn raw events into a versioned, ranked, narrated operation cluster. Each is a single function ingo/internal/dispatches/with paired tests, auditable end to end.
Events become nodes; entities and MITRE techniques become connecting nodes. Connected components reveal coordinated activity that single-alert pipelines miss because no single alert crossed a threshold.
A new cluster is matched against active dispatches by Jaccard overlap on entities and techniques. Same operation, fresher view bumps a version number; a new operation gets its own dispatch.
Personalized PageRank biased by recent events scores per-node activity inside the entity graph. Used to pick the bridge entity each dispatch points its narrative at.
Severity, blast radius, and freshness combine into a single rank. Decay pushes stale dispatches down the feed without auto-closing them, so an analyst still gets the option to dismiss.
Cluster events feed a hardened LLM template. A scrubber strips injection patterns from event-derived strings before prompt assembly, so a malicious payload cannot hijack the narrative an analyst reads.
Public share links carry an HMAC-signed nonce of the formv1.<id>.<exp>.<rnd>.<sig>with a tenant-scoped signing key. Path-independent: rotating the key invalidates outstanding links instantly.
From one production deployment. Identifying details are withheld until consent is on the record, which is also why you should treat the numbers as illustrative of the method rather than as a benchmark.
identities that could reach one crown-jewel account, at a manufacturer running Samyoga today
of 155 paths to that account with no endpoint detection anywhere along the route
bytes moved out of the customer’s lake to produce either number
Their CMDB named none of those 231. Not because the CMDB was badly run — it was run about as well as these things get run. It named none of them because reachability is not a field you can fill in. It is a property of the whole graph, and it changes every time somebody grants a permission.
Samyoga reads and reasons. It builds the map and answers questions about it. It does not act across your enterprise systems on its own initiative, and anything that writes back runs through a staged approval gate, including the local model in air-gapped deployments.
That is a real limit and we would rather you heard it here than discovered it in a proof of concept. The half of this problem we have solved is knowing what is there and what it can reach. Doing something about it automatically is a different product, and anyone telling you they have shipped both should be asked to demonstrate the second one on your data.
We are also not an agent framework, an identity provider, or a replacement for your SIEM. Those all still do their jobs. None of them is the map.
Three venture firms published versions of this hypothesis during 2026, independently of each other and of us, using different words for the same missing layer. We read all 103 of their published ideas. 12 describe this problem. 79 have nothing to do with us, and we think publishing that second number is what makes the first one worth anything.
A briefing runs on your data, not a demo tenant. Tell us a little about your stack and we reply within one business day.