Map the real scope of every AI agent's authority across your SaaS environment. Obsidian Security correlates agent configuration with delegated entitlements, OAuth grants, and inherited credentials so you see what an agent can actually do, not what its config says it should.

Inventory tells you what agents are running. It does not tell you what damage each one can do if compromised, misconfigured, or manipulated. The answer to that question lives in delegated entitlements, OAuth scopes, and inherited credentials, which sit in different systems than the agent configuration itself. Standard posture tools cannot connect those systems in real time. Boards, regulators, and CISOs are now asking the question directly: if this agent goes wrong, how far does the damage spread.
Blast radius is the second pillar of agentic security, after inventory. Obsidian Security correlates every agent with the SaaS entitlements, OAuth grants, and human or service identities behind it. Security teams see the actual reach of every agent, prioritized by toxic combinations, so the highest-severity agents get attention first.
Maker Mode is the most visceral blast radius example. An agent built by a Salesforce administrator runs on the admin's credentials. A business analyst with no Salesforce license invokes the agent and receives CRM data the analyst has no right to access. IAM sees the maker's identity making authorized calls. SIEM sees normal API activity. SSPM sees that maker mode is enabled in configuration. None of them sees that a different user invoked the agent or whether it has actually been exploited. Obsidian's Identity Graph correlates the three things that exist in separate systems: agent configuration, invoker identity, and SaaS entitlements.


A lower-privileged user manipulates a shared or credential-bearing agent into using its elevated permissions on their behalf. Downstream systems see a normal API call from the agent's credentials, identical to one the agent would make for any other invoker. The misuse is invisible from logs alone. Obsidian's Unified Identity Graph correlates the invoker's identity with the credential being exercised, so the confused deputy pattern surfaces before the action completes.
Alert fatigue is the silent killer of agent security programs. A flat list of every theoretical risk buries the agents that actually matter. Obsidian uses Operational Network Intelligence to score agents by toxic combinations, where Maker Mode, orphaned credentials, org-wide access, and sensitive data exposure stack on the same agent. The ranked queue sends the highest-blast-radius agents to the top of the review list automatically.

AI blast radius is the real scope of an agent's authority across the SaaS environment: what an agent can actually do via delegated entitlements, OAuth grants, and inherited credentials, not just what its configuration says it should be able to do. The two are rarely the same. Blast radius answers a question that inventory cannot: if this agent is compromised, misconfigured, or manipulated, how far does the damage spread.
Configuration is a declaration. Blast radius is reality. An agent's configuration shows the credentials and connectors it was built with. It does not show whether those credentials are over-scoped, whether OAuth grants extend further than the immediate workflow needs, or whether the agent has inherited authority from a higher-privileged maker. Real blast radius lives in the intersection of those things, and it can only be assessed by correlating agent metadata with actual SaaS entitlements.
Obsidian correlates three signals that traditionally live in separate systems: agent configuration (which credentials are embedded), the invoker identity (which user actually triggered the action), and SaaS entitlements (whether the invoker should have access to what the agent can reach). The graph maps every privileged path end to end, surfaces toxic combinations where multiple risk factors stack on a single agent, and ranks agents by the severity of their real authority.
A toxic combination is the stacking of multiple risk factors on a single agent: a shadow agent that is also org-wide accessible, also runs on Maker Mode credentials, and also has sensitive data exposure, for example. Each factor alone might be medium risk. Combined, they create a critical-priority alert because the blast radius compounds. Obsidian scores toxic combinations and ranks them so security teams see the agents that matter first, not a flat list of every theoretical risk.
Because the answer requires correlating signals from systems they were not built to connect. IAM sees the maker's identity making authorized calls but not that a different user invoked the agent. SIEM sees normal API activity but not who asked the agent to do it. SSPM sees that Maker Mode is enabled in configuration but not whether it has been exploited. Native platform logs see agent execution events but not the invoker identity or downstream data accessed. None of those tools fail individually. They were each built for a different question.
The agent layer can be mapped without standing up SaaS integrations across every platform first. Obsidian hooks directly into AI platforms (Copilot as well as Claude, Cursor, and others in the near future) at the agentic layer. SaaS connectors deepen the picture for downstream entitlement correlation against Salesforce, Google Workspace, and others, and they make blast radius scoring more precise. You can start at the agent layer and add SaaS depth as your program matures.
CISOs are increasingly being asked direct questions by Audit Committees about AI exposure. Inventory answers "how many agents." Blast radius answers "how much damage could each agent do." Continuous blast radius mapping gives you audit-ready evidence of which agents you are tracking, what authority each one holds, and how that authority changed over time. The board question moves from "do you have a policy" to "can you prove it worked."
Obsidian offers a free AI agent risk assessment. In Week 1, you receive an executive report showing every AI agent, who created it, the SaaS apps it touches, and its privileges. In Week 2, you work with an Obsidian security expert for tailored guidance on enforcing least privilege and policy alignment. Get the assessment.