# Acaspoint

*/Startups/Acaspoint*

## Startup Overview

This platform autonomously maps and revokes orphaned SaaS permissions across the enterprise digital footprint. By connecting directly to cloud application APIs, the system identifies dormant accounts, over-provisioned access, and former employee credentials, executing immediate revocation protocols without manual intervention.

IT and security teams deploy the service to eliminate the hidden attack surface generated by decentralized software adoption. Instead of relying on manual access reviews or waiting for IT tickets to be processed, administrators secure their environments through continuous, automated access remediation.

Unlike SailPoint IdentityNow or Vanta, which operate as diagnostic dashboards that flag vulnerabilities for human resolution, this solution actively neutralizes the exposure. Replacing the traditional Jira IT ticketing workflow for access management, it functions as an outcome-priced remediation service. Organizations pay directly for the successful revocation of orphaned access rather than purchasing seat-licensed analytics.

## Startup Founding Hypothesis

**Approach**: that autonomously maps and revokes orphaned SaaS permissions
**Competitors**:
- [SailPoint IdentityNow](/Competitors/SailPoint_IdentityNow)
- [Vanta](/Competitors/Vanta)
- [Jira IT ticketing](/Competitors/Jira_IT_ticketing)
**Differentiator2x2**: an outcome-priced remediation service rather than a purely diagnostic, seat-licensed dashboard

## Startup Solution Coordinate

**Solution**: [Acaspoint Access Sweep](/Services/Acaspoint_Access_Sweep)

## Startup Position2x2

```mermaid
quadrantChart
x-axis Purely Diagnostic --> Autonomous Remediation
y-axis Seat-Licensed Dashboard --> Outcome-Priced Service
SailPoint IdentityNow: [0.3, 0.2]
Vanta: [0.1, 0.3]
Jira IT ticketing: [0.2, 0.1]
Acaspoint: [0.9, 0.8]
```

## Startup Brand

**Voice**: Authoritative and exact, communicating zero-tolerance for security access gaps
**Tagline**: Eliminate orphaned SaaS access and close unauthorized entry points
**Icon Concept**: badge
**Palette Intent**: institutional-cool
**Visual Identity**: Deep slate and icy blue tones anchor a clinical, high-contrast interface that highlights exposed permissions and access revocation events with stark typographic precision.
**Archetype Reference**: the-ruler

## Startup Customer Journey

```mermaid
flowchart LR; A[Okta Directory] --> C[Diagnostic API]; B[Entra App Gallery] --> C; C --> D[Workspace Integration]; D --> E[Remediation Engine]; E --> F[Volume Revocation Tier]; F --> G[SIEM Audit Log];
```

## Startup Proof Points

_Illustrative — target and order-of-magnitude estimate figures, not an achieved track record (this Thing is concept-stage)._

**Pilot Goals**:
- 14-day ad-hoc security audit pilot: Deploy alongside an existing IdP to discover and safely revoke 50 orphaned contractor accounts, proving the zero-risk, pay-per-revocation billing model.
- 30-day volume remediation pilot: Connect to 10 core SaaS integrations to automatically execute and log 200 account offboardings, validating the 48-hour programmatic remediation target.
**Target Metrics**:
- Target: 95% reduction in manual offboarding tickets for core SaaS applications
- Aim: 10 hours saved per week previously spent by IT chasing application owners
- Target: 48-hour time-to-remediation for discovered orphaned accounts post-deployment
- Aim: 100% automated logging of API revocation payloads directly to SIEM or Jira systems
**Target Case Studies**:
- Mid-market technology company (500+ employees): Target demonstrating the transition from manual Jira offboarding tickets to automated API-driven revocation, specifically highlighting the safe removal of 300+ legacy contractor accounts across 50 core integrations without interrupting active service accounts.
- Healthcare SaaS provider: Target validating the compliance audit trail capability, showing how the automated SIEM and Vanta logging satisfies SOC2 requirements while eliminating the need for IT to manually track down application owners for access removal.
- Financial services firm: Target proving the usage-metered value proposition by showing zero upfront software costs and payment only for the 1,200 successfully quarantined orphaned identities discovered during an ad-hoc security audit.
**Testimonial Targets**:
- Director of IT: Needs to express relief that the tool actually executes the API payload to remove the accounts rather than just adding alerts to an IGA dashboard.
- VP of Information Security: Should validate the dual-match HRIS and IdP validation, confirming that automated revocation did not cause any false-positive lockouts of active contractors.
- Compliance Manager: Needs to highlight the completeness of the timestamped audit logs sent to Vanta, verifying it satisfies their strict auditor requirements.

## Startup Top Risks

**Risks**:
- Severity: existential · Description: Major SaaS providers like Google Workspace or Salesforce restrict or deprecate the third-party APIs required for automated permission revocation. · Mitigation Status: unmitigated
- Severity: high · Description: The autonomous engine incorrectly revokes access for an active service account or executive, causing severe operational outages and immediate customer churn. · Mitigation Status: in-progress
- Severity: high · Description: Established compliance competitors like Vanta or SailPoint release native automated remediation features and bundle them at no extra cost. · Mitigation Status: unmitigated
- Severity: moderate · Description: Security buyers resist the outcome-based pricing model because their procurement processes require fixed predictable budgets rather than dynamic performance expenditures. · Mitigation Status: in-progress

## Startup Competitors

- [SailPoint IdentityNow](/Competitors/SailPoint_IdentityNow) — Incumbent IGA
- [Vanta](/Competitors/Vanta) — Compliance Dashboard
- [Jira IT Ticketing](/Competitors/Jira_IT_Ticketing) — Status Quo
- [Okta Identity Governance](/Competitors/Okta_Identity_Governance) — Incumbent Suite
- [Opal Security](/Competitors/Opal_Security) — Access Management

## Startup Token Hero

**Genre**: founding-hypothesis
**Rendered**: Every week, IT Security Managers battle account sprawl. Acaspoint revokes orphaned SaaS permissions autonomously so you can eliminate your hidden attack surface.
**Mechanism**: spine-derived-v1
**Template Id**: spine-founding-hypothesis
**Vocab Fingerprint**: 9ab4af3d287084ee

## Startup Token Positioning

**Genre**: moore-positioning
**Rendered**: Automated SaaS Access Remediation for IT and Security teams at mid-market enterprises. Unlike SailPoint IdentityNow or Vanta dashboards — actually revoke orphaned permissions instead of just flagging them.
**Mechanism**: spine-derived-v1
**Template Id**: spine-moore-positioning
**Vocab Fingerprint**: 225b0d9a1a85b442

## Startup Token Pitch Deck

**Genre**: pitch-deck
**Rendered**: Problem: Stale employee credentials and over-provisioned apps clutter Vanta dashboards while manual revocation workflows stall in Jira ticketing queues
Solution: Every week, IT Security Managers battle account sprawl. Acaspoint revokes orphaned SaaS permissions autonomously so you can eliminate your hidden attack surface.
Customer: IT and Security teams at mid-market enterprises
Unlike: SailPoint IdentityNow or Vanta dashboards
**Mechanism**: spine-derived-v1
**Template Id**: spine-pitch-deck
**Vocab Fingerprint**: 651cc8551dea0fb2

## Startup Token M E D D P I C C

**Pain**: Stale employee credentials and over-provisioned apps clutter Vanta dashboards while manual revocation workflows stall in Jira ticketing queues
**Metrics**: Target: Your environment stays hardened as the system automatically purges orphaned accounts the moment they appear.
**Rendered**: Pain: Stale employee credentials and over-provisioned apps clutter Vanta dashboards while manual revocation workflows stall in Jira ticketing queues
Economic buyer: Enterprise IT Security Administrator
Metrics: Target: Your environment stays hardened as the system automatically purges orphaned accounts the moment they appear.
Competition: SailPoint IdentityNow or Vanta dashboards
**Mechanism**: spine-derived-v1
**Competition**: SailPoint IdentityNow or Vanta dashboards
**Economic Buyer**: Enterprise IT Security Administrator
**Vocab Fingerprint**: d954591e58807431

## Startup Token Cold Email

**Genre**: cold-email
**Rendered**: Subject: Automated SaaS Access Remediation for IT and Security teams at mid-market enterprises

IT and Security teams at mid-market enterprises — Stale employee credentials and over-provisioned apps clutter Vanta dashboards while manual revocation workflows stall in Jira ticketing queues Every week, IT Security Managers battle account sprawl. Acaspoint revokes orphaned SaaS permissions autonomously so you can eliminate your hidden attack surface.
**Mechanism**: spine-derived-v1
**Template Id**: spine-cold-email
**Vocab Fingerprint**: 68f5a4c6df42ac5f

## Startup Token Agent Spec

**Genre**: ai-agent-spec
**Rendered**: Automated SaaS Access Remediation. Every week, IT Security Managers battle account sprawl. Acaspoint revokes orphaned SaaS permissions autonomously so you can eliminate your hidden attack surface. Serves IT and Security teams at mid-market enterprises.
**Mechanism**: spine-derived-v1
**Template Id**: spine-ai-agent-spec
**Vocab Fingerprint**: 3bfafa7f0ff096c5

## Neighborhood

### Candidate solutions

- [Source Tech-Savvy Advisory Staff](/Problems/Source_Tech-Savvy_Advisory_Staff) — candidate solution for · Problems

### Competitors

- [Vanta](/Competitors/Vanta) — competes with · Competitors
- [SailPoint IdentityNow](/Competitors/SailPoint_IdentityNow) — competes with · Competitors
- [Jira IT Ticketing](/Competitors/Jira_IT_Ticketing) — competes with · Competitors
- [Okta Identity Governance](/Competitors/Okta_Identity_Governance) — competes with · Competitors
- [Opal Security](/Competitors/Opal_Security) — competes with · Competitors

### What it offers

- [Acaspoint Access Sweep](/Services/Acaspoint_Access_Sweep) — offers · Services

### Embodies

- [Service-as-Software](/Theses/Service-as-Software) — embodies · Theses

### Composed of

- [Account Discovery Agent](/Agents/Account_Discovery_Agent) — composes · Agents
- [Permission Revocation Worker](/Agents/Permission_Revocation_Worker) — composes · Agents
- [Identity Mapping Engine](/Agents/Identity_Mapping_Engine) — composes · Agents
- [SaaS Connector API](/Agents/SaaS_Connector_API) — composes · Agents
- [Access Remediation Service](/Services/Access_Remediation_Service) — composes · Services

### Similar Startups

- [Coordinatorfield](/Startups/Coordinatorfield) — similar · Startups
- [Hororus](/Startups/Hororus) — similar · Startups
- [Novia](/Startups/Novia) — similar · Startups
- [Symon](/Startups/Symon) — similar · Startups
- [Prilum](/Startups/Prilum) — similar · Startups
- [Corelamp](/Startups/Corelamp) — similar · Startups
- [Accaze](/Startups/Accaze) — similar · Startups
- [Permoster](/Startups/Permoster) — similar · Startups
- [Acceam](/Startups/Acceam) — similar · Startups
- [Spaceintractable](/Startups/Spaceintractable) — similar · Startups
- [Departuredepot](/Startups/Departuredepot) — similar · Startups
- [Turnift](/Startups/Turnift) — similar · Startups
- [Duoreduction](/Startups/Duoreduction) — similar · Startups
- [Spruanager](/Startups/Spruanager) — similar · Startups
- [Venturenexus](/Startups/Venturenexus) — similar · Startups
- [Atomnon](/Startups/Atomnon) — similar · Startups
- [Accirm](/Startups/Accirm) — similar · Startups
- [Atonyx](/Startups/Atonyx) — similar · Startups
- [Cessum](/Startups/Cessum) — similar · Startups
- [Verow](/Startups/Verow) — similar · Startups
