Beta — Powered by Teleport

How Atlas works

Connect what you already run, and Atlas assembles a live map of every path between an identity and a resource. Read-only from the first day and every day after.

The Short Version — A map, not another gateway.

What Atlas reads, and what it will not touch.

Atlas watches the systems you already run and builds a live map of who can reach what. There is no agent to install and nothing to migrate — it reads from the identity providers, cloud accounts and clusters you have already connected, and it reads only.

What it reads

The graph is assembled from four kinds of source, refreshed continuously rather than on a nightly job:

  • Identity providers — users, groups, and the memberships that grant inherited access.
  • Cloud IAM — roles, policies, and the trust relationships between accounts.
  • Infrastructure — Kubernetes clusters, databases, and the service accounts that reach them.
  • Machine identities — CI runners, AI agents, and MCP tools acting on their own credentials.

What it does not do

Atlas does not hold your secrets, proxy your traffic, or sit in the path of a request. It is read-only by construction, which is what makes the five-step rollout possible on day one. The common questions below cover what that means in practice.

We had the map in under an hour. What took longer was accepting how much of it we had never seen before.

Teleport publishes the full source list in its documentation, opens in new window.

The Rollout — Five steps, no migration.

Numbering follows array order, so this section runs 01 to 05 with nothing hardcoded.

  • CONNECT

    Point Atlas at what you already run

    Add your identity provider and cloud accounts with read-only credentials. No agent to install, no network changes, nothing in the request path.

  • DISCOVER

    Watch the graph assemble itself

    Atlas walks identities, roles, groups and resources, resolving inherited access the way an attacker would. The first complete map usually lands within the hour.

  • REAL-TIME

    See changes as they happen

    New credentials, changed policies and fresh service accounts appear as they are created. The map is never a snapshot you have to remember to refresh.

  • INVESTIGATE

    Ask what an identity can actually reach

    Pick any identity and Atlas returns the full effective reach, including the paths granted indirectly through group membership and role chaining.

  • PROVE

    Answer the auditor in one query

    Export effective access for any system or person at any point in time. Evidence stops being a week of log correlation across six tools.

The Graph — Every path, not every permission.

A permissions list tells you what a policy says. The graph tells you where an identity can actually arrive, which is rarely the same thing once group membership and role chaining are resolved.

Paths are what matter during an incident. Atlas keeps them live so the blast radius is a query rather than an afternoon.

The Atlas access graph linking identities to the resources they can reach

The Console — Ask a question, get a path.

Pick an identity and Atlas returns its full effective reach, including everything granted indirectly. Pick a resource and it works the other direction.

Answers are exportable, so audit evidence stops being a week of correlation work.

The Atlas console showing effective access for a single identity

What It Answers — The questions that used to take a week.

Four cards on a rotating carousel, which is the display option doing its job.

Common questions

Does Atlas need write access? No. Every connector is granted read-only scopes, and the product has no code path that mutates a policy, a role, or a credential.

How long does the first graph take? Most teams see a complete map within an hour of connecting their identity provider and first cloud account. Coverage grows as you connect more.

What happens to the data? Atlas stores relationships, not contents. It records that a service account can reach a database, never what is in it.

Can we export it? Yes. The graph is queryable and exportable, so audit evidence is a query rather than a project.

Trusted by teams building critical infrastructure

Get Started — Ready to see your access graph?

Request early access today. Free during beta. No credit card required.