Service accounts, API keys, OAuth grants, and AI agent credentials now outnumber your employees many times over — and most have no owner, no expiration, and too much access. I find them, rank the risk, and help you fix the worst ones in weeks, not quarters.
Non-human identities to humans in a typical cloud-native organization.
of organizations feel highly confident they can prevent an attack through an NHI.
That's all it takes. A leaked token walks right past every MFA prompt you've deployed.
You've invested in SSO, MFA, and access reviews for employees. Meanwhile, the identities doing most of the work in your environment never log in, never get reviewed, and never leave.
Can your team list every service account, API key, and integration in your tenant — and who owns each one? Most can't.
Long-lived tokens with admin-level scopes are the fastest path for lateral movement after a single leak.
Offboarding removes the person. Their OAuth grants, scripts, and automation accounts quietly keep running.
SOC 2, ISO 27001, and cyber-insurance questionnaires increasingly ask how machine access is governed. "We're not sure" isn't an answer.
Every copilot, agent, and automation your teams adopt mints new credentials. Few organizations track them at all.
Users click "Allow" on third-party apps every day, granting mail, file, and directory access to vendors nobody vetted.
Start with an assessment. Every engagement ends with something you can act on — not a slide deck of generic best practices.
A complete inventory of your non-human identities, ranked by real risk.
Work through the roadmap and close the highest-risk gaps.
Keep the gains from eroding as new integrations and AI agents appear.
Founding client pricing: I'm taking on a small number of first assessments at a reduced rate in exchange for a testimonial and an anonymized case study. Ask about it on our call.
20 minutes. We talk through your stack, your audit timeline, and what's worrying you.
Read-only API access to agreed systems, under NDA. Nothing changes in your environment.
Automated discovery plus manual review. Every finding is verified by a person, not just a script.
A walkthrough with your team: what we found, what it means, and what to fix first.
I'm Michael Yee. For the last four years I've worked hands-on in enterprise identity and IT at a cybersecurity company — administering Okta, Microsoft Entra ID, Active Directory, and Google Workspace, alongside device management and network infrastructure. Identity is the layer every other system trusts, so that's where I've chosen to specialize.
Working inside identity platforms every day, I kept seeing the same blind spot: organizations govern their people carefully, while the service accounts, tokens, and integrations behind the scenes pile up quietly — unowned and over-privileged. So I built nhi-scanner, a Python tool for discovering and risk-ranking non-human identities, and started BuildWithYee to help companies close that gap.
You'll work with me directly — no hand-off to a junior team. My approach is practical: verify every finding, explain it in plain language, and leave you with a process your team can run without me.
Any identity that isn't a person: service accounts, API keys and tokens, OAuth app grants, workload identities, certificates, bots, and AI agents. They authenticate and hold permissions just like employees do — but usually without MFA, reviews, or an offboarding process.
Companies of roughly 100–1,000 employees running Okta or Microsoft Entra ID — especially those preparing for SOC 2 or ISO 27001, renewing cyber insurance, adopting AI tools quickly, or operating without a dedicated identity team.
No. Assessments use read-only API access, scoped to the systems we agree on, under a mutual NDA. Nothing in your environment is modified during an assessment.
Tools are great at surfacing findings; the hard part is deciding what matters, assigning ownership, and actually remediating. I can work alongside the platform you already have and help you operationalize it.
Usually within one to two weeks of a discovery call. Assessments take one to two weeks from the time access is granted.
If that question makes anyone on your team wince, let's talk. A 20-minute call, no pitch deck — just an honest look at where your machine identity risk probably sits.