Browse documentation

Understand access with the Trust Graph

The Trust Graph shows relationships your organization has explicitly recorded between owners, projects, agents, tools, and data sources. Use it to investigate intended access and possible impact without treating observed activity as proof of permission.

What the graph means

Each node represents a governed identity or resource. Each edge represents an authored relationship, such as an agent being allowed to call a tool or access a data source.

The graph does not infer permission from network traffic, discovery results, recent syncs, or naming similarity. Inventory and observations remain separate until an authorized administrator records a relationship.

Review a node

  1. Open Enterprise → Trust Graph.
  2. Search by display name, stable ID, or governed scope.
  3. Narrow the view by identity type, risk tier, or lifecycle state.
  4. Select a node to inspect incoming and outgoing relationships.
  5. Review the node's trust ceiling, scopes, lifecycle, and affected resources.
  6. Follow up in the relevant inventory, policy, or destination system before changing access.

The filters apply to the graph currently rendered on screen. If Sernixa reports a large graph window, use the totals to understand the complete inventory and treat the visual subset accordingly.

Read lifecycle states correctly

StateHow to interpret it
ActiveThe authored record is eligible for access evaluation.
SuspendedThe record is administratively paused and should not be treated as current permission.
RevokedThe record no longer grants governed access.
ExpiredThe record passed its configured validity window.

Inactive, expired, malformed, or dangling relationships do not count as effective access. A missing graph record is unknown—not automatically active and not automatically revoked.

Use governed blast radius

Select a node to see which authored nodes, tools, and data sources are reachable within the displayed analysis depth. Use this view when reviewing a risky change, revocation, delegation path, or incident.

If Sernixa marks the result as truncated, additional authored paths exist beyond the returned analysis window. Treat the displayed impact as a lower bound and investigate further before making a high-impact decision.

Blast radius is a governance view. Pair it with Flight Recorder and destination-system evidence when you need to understand what actually happened.

Keep graph data safe

  • Use stable identifiers and approved scope labels; never place passwords, tokens, private keys, or connection strings in graph metadata.
  • Record only relationships your organization intends to govern.
  • Revoke or expire obsolete relationships instead of relying on visual absence.
  • Confirm the active organization before reviewing or administering access.

Next step

Improve ownership in the Agent inventory, set decision behavior in Policies and controls, or investigate runtime evidence in Flight Recorder.