Token Security has added an Entitlements Inventory feature to its non-human identity (NHI) security platform, giving security and identity teams a centralized view of who has access to what across cloud, SaaS, and database environments.
The feature provides a severity-ranked inventory of permissions, including roles, policies, groups, and permission sets, spanning AWS, Azure, GCP, SaaS applications, and databases. Security teams can filter and search by entitlement type, environment, permission level, and consuming principals, including both human identities and AI agents.
The tool allows teams to drill into a specific entitlement to see what permissions it grants, which principals are connected to it, and whether those permissions are actively being used. A team investigating broad cloud access can open an entitlement such as Amazon S3 Full Access and immediately identify connected identities or agents that have not exercised certain permissions in the last 90 days, flagging opportunities for right-sizing.
Entitlements Inventory also surfaces dormant entitlements: permissions that grant administrative or sensitive access but are currently assigned to no one. Token Security says these represent latent risk, as forgotten access paths could be exploited if rediscovered or improperly reassigned.
The platform uses three levels of classification confidence: verified entitlements confirmed through direct integrations, inferred entitlements based on naming patterns, and unknown states flagged for user review. The company says this approach helps teams assess both the scope and reliability of their access data.
The feature arrives as identity security vendors expand tooling to address the growing challenge of machine and non-human identity management. As AI agents and service accounts multiply across enterprise environments, security teams face increasing difficulty maintaining visibility into delegated access and enforcing least-privilege principles. Companies like Clarity Security have also introduced platforms governing access across human, non-human, and AI agent identities.
The Entitlements Inventory integrates with Token Security’s broader platform, which covers identity discovery, lifecycle management, security posture assessment, threat detection, and automated remediation. The company recently introduced Enzo, an AI-native application builder for identity security, and has integrated Anthropic’s Claude Compliance API into its control plane. The feature is available now to platform customers.
Sources: Token Security
–
By the ID Tech Editorial Team







Follow Us