Synthetic product output

See what a Kavryl assessment delivers.

These sample reports use synthetic company, subscription, account, tenant, and resource IDs, but the format is modeled on Kavryl scanner output across Azure, AWS, GitHub, Microsoft 365 / Entra, Google Workspace, and MCP agent configs.

Sample company: Northstar Health Cloud Overall exposure: High Coverage: Cloud, SaaS, identity, code, agents No real customer data

Downloadable PDFs

Board-ready reports, not raw scanner noise.

A Kavryl assessment turns read-only evidence into executive summary, technical findings, OWASP API Top 10 mapping, MITRE ATLAS-style AI risk paths, and owner-ready remediation steps.

Executive report

AI Agent Permission Risk Report

Cross-cloud and SaaS summary for a CISO, CTO, auditor, or board audience. Shows business impact, top paths, and first actions.

Score
82 / 100 High
Assessment ID
KAV-ASM-2026-05-NSHC-001
Best for
Executive review
Download PDF
Cloud report

Azure and AWS AI Agent Risk Report

Uses synthetic Azure subscription IDs, AWS account IDs, resource ARNs, and cloud findings based on our Azure and AWS scanners.

Score
88 / 100 Critical path
Systems
Azure AI, Key Vault, Storage, AWS IAM, API Gateway
Best for
Cloud security
Download PDF
SaaS and identity report

SaaS, OAuth, GitHub, and Agent Risk Report

Shows what Kavryl output looks like for Microsoft 365 / Entra, Google Workspace, GitHub, OAuth grants, and MCP tools.

Score
76 / 100 High
Systems
M365, Entra, Google Workspace, GitHub, MCP
Best for
AppSec and IAM
Download PDF
Executive Summary

The report explains blast radius, not just misconfigurations.

Kavryl combines scanner evidence from cloud, SaaS, identity, repository, and agent configuration surfaces. The output tells security leaders which agent paths are dangerous, why they matter, and what owners should fix first.

Sample overall exposure score 82 / 100 High
Example Risk Path
Support Agent
Microsoft Graph
Azure Owner Role
Customer Data Exposure

A single finding may look manageable. The real risk appears when broad OAuth scopes, static secrets, public APIs, and privileged cloud roles combine into an agent action path.

Synthetic Evidence Examples
ID System Evidence Interpretation
CLD-001 Azure Service principal has Owner at subscription 4b812c7f-301d-45fb-8a4d-8a7750c4c19f. Compromised agent identity could mutate cloud resources or grant access.
SAA-001 M365 Support Agent OAuth App has Mail.Read, Files.Read.All, and offline_access. Delegated access can expose mail and files beyond the current workflow.
AWS-001 AWS arn:aws:iam::391742608155:role/agent-bedrock-admin-role includes wildcard signal. Agent or automation compromise could create broad cloud blast radius.
MCP-001 MCP Filesystem and shell tools are available in the same support-agent profile. Tool combination increases unsafe action and data movement risk.
Action Plan

First 7 days

Disable shell-capable MCP tools for support agents, require approval before outbound Slack/email actions, and pause new agent grants.

First 30 days

Replace broad Azure/AWS roles, remove unused OAuth scopes, split agent service identities, and restrict RAG data sources.

First 60 days

Run recurring scans, assign owners to every agent/tool, and create an approval workflow for new SaaS and cloud permissions.

Framework Mapping

Kavryl maps evidence to OWASP API Security Top 10 categories such as Broken Authentication, Broken Function Level Authorization, Security Misconfiguration, and Improper Inventory Management. It also maps AI-specific interpretation to MITRE ATLAS-style paths such as AI-enabled system discovery, credential misuse, excessive agency, and public agent/API exposure.

Kavryl Security

Want this report for your AI agents, cloud, and SaaS permissions?

Book a 30-minute risk review