← Back to Labs

Security / Visualization / Experiment

Trust Map

Security controls are often reviewed one object at a time. Trust Map asks a different question: what becomes visible when identities, devices, applications, permissions and data are viewed as one connected system?

InteractiveSecurityVanilla JS

Interactive prototype

Explore a small trust graph.

Select a node to inspect what it can reach. Use the filters to focus on one part of the system.

IDMarc DEVLaptop APPCRM AIAgent DATACustomer APPMail DATAReport DATAFiles

Trust is rarely attached to one object.

An identity can use a device. The device can run an approved application. The application can access data. An AI agent may inherit the application’s permissions and add a new ability to act.

Each individual permission may be reasonable. The combination can create a much broader capability than anyone intended.

The visualization is the question.

Trust Map is not intended to become another inventory. Its purpose is to make relationships easier to question: which node creates the most reach, where does trust propagate, and which connection would matter most if it were abused?

  • Reach: Which trusted component can reach the largest number of consequential assets?
  • Propagation: Where does one permission implicitly unlock another action?
  • Concentration: Which identity, application or agent has become a single point of excessive trust?
  • Control: Which relationship should require an additional checkpoint?