The thesis

The enterprise has no trustworthy map of itself. Agents are about to make that fatal.

Everything Samyoga builds follows from that one sentence. This page is the argument behind it, in full, including the parts we cannot yet do.

One

The map was always wrong. It barely mattered.

Every enterprise keeps a register of what it owns. A CMDB, a spreadsheet, an asset inventory in a procurement tool, usually all three disagreeing. It is assembled by hand, signed off once, and stale by the following week, because the only thing keeping it true is a person remembering to update it.

For thirty years that was survivable. Humans moved at human speed. A wrong row in the CMDB cost you a support ticket routed to the wrong team, or a server nobody patched because nobody knew it was there. Annoying, occasionally expensive, rarely fatal.

The register was never the control. It was paperwork about the control. Nobody made a decision at three in the morning on the strength of a CMDB entry.

Two

Then something started reading it.

Non-human identities now outnumber human ones inside a typical enterprise, and the gap is widening every quarter. Service accounts, CI runners, integration users, and now agents: things that hold credentials, act without being watched, and never sleep.

An agent is given a scoped credential and told to get on with it. That scope is a claim about reach — these systems, this data, no further. And the scope is computed from a map. Somebody looked at an inventory, decided what this thing needs to touch, and cut the permissions to fit.

If the map is wrong, the scope is wrong. The difference is that the agent will exercise the whole of its actual reach, at machine speed, and nobody finds out what that was until afterwards.

This is the part that makes an old problem newly fatal. A stale inventory used to produce a missed patch. A stale inventory now produces a confident, automated, wildly over-scoped actor operating on your behalf, and an incident review that starts with the sentence we did not know it could reach that.

Three

Why thirty years of fixes did not fix it.

A CMDB is a system of record. Its defining property is that it is true only while somebody keeps it true. Every serious attempt to improve it has been an attempt to make that somebody faster, better resourced, or better disciplined: import scripts, reconciliation rules, data-quality dashboards, a quarterly attestation ritual.

All of it treats human maintenance as the thing to optimise. None of it questions whether the map should be maintained at all.

The fix is to stop declaring the map and start deriving it.

Your estate already emits an account of itself, continuously, in enormous volume. Every authentication, every firewall session, every endpoint event, every cloud API call, every vulnerability scan is a statement about what exists and what talks to what. Nothing was reading it as a description of the enterprise. It was being read as alerts.

Four

What deriving it actually looks like.

Read what the estate already emits. Connectors take XDR, firewall, identity, vulnerability, cloud, and OT telemetry over API or syslog. Nothing to install on an endpoint, nothing to migrate, no new agent asking for a credential of its own.

Resolve every record to a canonical entity. The same host arrives spelled nine ways across nine tools; the same person is an email in one system, a SAM account in another, a service principal in a third. Normalize, fold case, merge duplicates, and the nine become one.

Join identity to asset to OT in a single graph, and the reachability question becomes answerable for the first time: from this account, through these credentials and trusts, what can actually be touched, and which of those routes has nothing watching it.

Then keep doing it. The graph is rebuilt continuously, because a derived map that goes stale is just a CMDB with better provenance.

Your data lakeSnowflakeDatabricksClickHouseS3 / IcebergBigQueryno data movementSamyoga Control PlaneDetectcampaigns + outliersConnectidentities + assetsNarrateattack dispatchesmulti-tenant + on-premOutcomesBoard-ready dispatchesSOC analyst alignmentSIEM reliefAuto-remediationLake-native by construction. Your data stays where it lives.
Five

What an accurate map is good for.

A map is not the product. Three answers come out of it, and they are the reason anyone pays for the first four sections of this page.

How it works

Three Ps. One graph.

Pagerank for Posture
CSF 2.0 · IDENTIFY

Rank every path an attacker could take.

Every identity and asset scored by what an attacker could reach from it — ranked attack paths on demand.

NODES SIZED BY REACHIDPSVC-ACCTENG-ADMINCI-RUNNERVAULTPROD-DBPPR 0.42BLAST RADIUS: 3 HOPS
Placements for Deception
CSF 2.0 · DETECT

Put the tripwire where they will walk.

The graph knows which routes to your crown jewels have nothing watching them — that is where the decoys go.

THE ROUTE NOTHING WATCHESIDPSVC-ACCTENG-ADMINCI-RUNNERVAULTPROD-DBDECOY / TRIPWIRE
Prescriptions for Playbooks
CSF 2.0 · RESPOND · IMPROVE (ID.IM)

Prescribe the playbook. Then measure it.

Each dispatch ships the playbook change that would have deflected it — and claims a tier lift only after measured deflection clears the bar.

DEFLECTION, SAMPLED WEEKLYPB-041 Token-Reuse Isolate0.31TIER 3→4PB-017 OAuth-Grant Revoke0.27TIER 2→3PB-063 Svc-Acct Quarantine0.19MEASURING
NIST CSF 2.0

From Risk Informed to Adaptive. Measured, not asserted.

Tier 2 means you know your risks. Tier 4 means your program adapts to them on its own evidence. Every prescription carries a recorded tier claim — 2 to 3, 3 to 4 — and none advances until measured deflection clears the bar. Your CSF tier moves, and you can prove it moved.

And what you log into.

Four surfaces over the one graph. Same data, four questions.

Setu, the graph layer

Reads your existing lake and resolves humans, machines, AI agents, and service principals into a single graph, ranked by what an attacker could reach from each one.

Detection Content

Rules, models, and narrators ship as a versioned canon you can review, audit, and override per tenant. No black-box detections and no surprise prompt changes after a procurement review.

Threats

What is currently lit up: where intel matches your environment and which campaigns are actively running. The surface your SOC opens at the start of a shift.

Anomalies

Outliers across the identity graph, similarity clusters, causal edges with confidence intervals, and forecasted edges before they fire.

Detection methods

How a dispatch is built.

The algorithms that turn raw events into a versioned, ranked, narrated operation cluster. Each is a single function ingo/internal/dispatches/with paired tests, auditable end to end.

Bipartite-CC clustering

Events become nodes; entities and MITRE techniques become connecting nodes. Connected components reveal coordinated activity that single-alert pipelines miss because no single alert crossed a threshold.

Jaccard identity

A new cluster is matched against active dispatches by Jaccard overlap on entities and techniques. Same operation, fresher view bumps a version number; a new operation gets its own dispatch.

PPR with event-biased restart

Personalized PageRank biased by recent events scores per-node activity inside the entity graph. Used to pick the bridge entity each dispatch points its narrative at.

Composite rank-score decay

Severity, blast radius, and freshness combine into a single rank. Decay pushes stale dispatches down the feed without auto-closing them, so an analyst still gets the option to dismiss.

Prompt-injection-scrubbed narrator

Cluster events feed a hardened LLM template. A scrubber strips injection patterns from event-derived strings before prompt assembly, so a malicious payload cannot hijack the narrative an analyst reads.

HMAC share nonces

Public share links carry an HMAC-signed nonce of the formv1.<id>.<exp>.<rnd>.<sig>with a tenant-scoped signing key. Path-independent: rotating the key invalidates outstanding links instantly.

Six

What we can put a number on.

From one production deployment. Identifying details are withheld until consent is on the record, which is also why you should treat the numbers as illustrative of the method rather than as a benchmark.

231

identities that could reach one crown-jewel account, at a manufacturer running Samyoga today

76

of 155 paths to that account with no endpoint detection anywhere along the route

0

bytes moved out of the customer’s lake to produce either number

Their CMDB named none of those 231. Not because the CMDB was badly run — it was run about as well as these things get run. It named none of them because reachability is not a field you can fill in. It is a property of the whole graph, and it changes every time somebody grants a permission.

Seven

What we are not claiming.

Samyoga reads and reasons. It builds the map and answers questions about it. It does not act across your enterprise systems on its own initiative, and anything that writes back runs through a staged approval gate, including the local model in air-gapped deployments.

That is a real limit and we would rather you heard it here than discovered it in a proof of concept. The half of this problem we have solved is knowing what is there and what it can reach. Doing something about it automatically is a different product, and anyone telling you they have shipped both should be asked to demonstrate the second one on your data.

We are also not an agent framework, an identity provider, or a replacement for your SIEM. Those all still do their jobs. None of them is the map.

We are not the first to notice.

Three venture firms published versions of this hypothesis during 2026, independently of each other and of us, using different words for the same missing layer. We read all 103 of their published ideas. 12 describe this problem. 79 have nothing to do with us, and we think publishing that second number is what makes the first one worth anything.

Read the evidence

See your own map.

A briefing runs on your data, not a demo tenant. Tell us a little about your stack and we reply within one business day.

Or email [email protected]