How Atlas works
Connect what you already run, and Atlas assembles a live map of every path between an identity and a resource. Read-only from the first day and every day after.
The Short Version — A map, not another gateway.
What Atlas reads, and what it will not touch.
Atlas watches the systems you already run and builds a live map of who can reach what. There is no agent to install and nothing to migrate — it reads from the identity providers, cloud accounts and clusters you have already connected, and it reads only.
What it reads
The graph is assembled from four kinds of source, refreshed continuously rather than on a nightly job:
- Identity providers — users, groups, and the memberships that grant inherited access.
- Cloud IAM — roles, policies, and the trust relationships between accounts.
- Infrastructure — Kubernetes clusters, databases, and the service accounts that reach them.
- Machine identities — CI runners, AI agents, and MCP tools acting on their own credentials.
What it does not do
Atlas does not hold your secrets, proxy your traffic, or sit in the path of a request. It is read-only by construction, which is what makes the five-step rollout possible on day one. The common questions below cover what that means in practice.
We had the map in under an hour. What took longer was accepting how much of it we had never seen before.
Teleport publishes the full source list in its documentation, opens in new window.
The Rollout — Five steps, no migration.
Numbering follows array order, so this section runs 01 to 05 with nothing hardcoded.
- CONNECT
Point Atlas at what you already run
Add your identity provider and cloud accounts with read-only credentials. No agent to install, no network changes, nothing in the request path.
- DISCOVER
Watch the graph assemble itself
Atlas walks identities, roles, groups and resources, resolving inherited access the way an attacker would. The first complete map usually lands within the hour.
- REAL-TIME
See changes as they happen
New credentials, changed policies and fresh service accounts appear as they are created. The map is never a snapshot you have to remember to refresh.
- INVESTIGATE
Ask what an identity can actually reach
Pick any identity and Atlas returns the full effective reach, including the paths granted indirectly through group membership and role chaining.
- PROVE
Answer the auditor in one query
Export effective access for any system or person at any point in time. Evidence stops being a week of log correlation across six tools.
The Graph — Every path, not every permission.
A permissions list tells you what a policy says. The graph tells you where an identity can actually arrive, which is rarely the same thing once group membership and role chaining are resolved.
Paths are what matter during an incident. Atlas keeps them live so the blast radius is a query rather than an afternoon.

The Console — Ask a question, get a path.
Pick an identity and Atlas returns its full effective reach, including everything granted indirectly. Pick a resource and it works the other direction.
Answers are exportable, so audit evidence stops being a week of correlation work.

What It Answers — The questions that used to take a week.
Four cards on a rotating carousel, which is the display option doing its job.
Who can reach production?
Not who is in the production group — who can arrive there by any path, including the ones granted through three layers of inherited role.
What did this agent touch?
AI agents and MCP tools act continuously at machine speed. Atlas records the reach of each one as an identity like any other.
What survives offboarding?
The account is disabled the same day. Atlas shows the tokens it minted and the runners it configured, which usually are not.
Where is the blast radius?
One compromised identity is rarely the end of it. The graph answers how far it reaches before an incident review has to.
Common questions
Does Atlas need write access? No. Every connector is granted read-only scopes, and the product has no code path that mutates a policy, a role, or a credential.
How long does the first graph take? Most teams see a complete map within an hour of connecting their identity provider and first cloud account. Coverage grows as you connect more.
What happens to the data? Atlas stores relationships, not contents. It records that a service account can reach a database, never what is in it.
Can we export it? Yes. The graph is queryable and exportable, so audit evidence is a query rather than a project.
Trusted by teams building critical infrastructure
Get Started — Ready to see your access graph?
Request early access today. Free during beta. No credit card required.