Atomburst Console · GitHub posture

Know your GitHub org. Prove it.

Access Review & Evidence is Atomburst's own self-serve product: it discovers what your GitHub organization actually looks like — who has access, what's stale, what's over-scoped — and turns your decisions into an evidence report an auditor accepts.

The Atomburst console mid access-review: report metadata, summary counts, and a findings table with decisions and justifications
Observed: a review in progress — synthetic specimen data · full sample →
Discovery

One scan, the whole posture.

Connect an org through our read-only GitHub App and one scan inventories the access surface — metadata only, never your code. This is what it reads:

01

Members & privileges

Every member and their privilege level — owners, admins, and the machine accounts quietly holding org-admin.

02

Two-factor gaps

Accounts with 2FA disabled, including legacy machine users still on password auth.

03

Outside collaborators

External accounts with repository access — and whether the engagement that justified them is still alive.

04

Apps & OAuth grants

Installed apps and OAuth authorizations with their permission scopes — the integrations nobody has looked at since they were approved.

05

Dormant accounts

Accounts with no activity past your threshold — offboarding that never finished, internships that ended, vendors long gone.

06

Point-in-time snapshot

Every scan is a dated snapshot, so your review states what was true, when — the property auditors actually check.

Review & evidence

Decisions with names attached.

Discovery is only half the product. Every finding gets a decision — KEEP, FLAG, or REVOKE — with a justification, a named reviewer, and a timestamp. A second reviewer can formally object. The review then renders as an evidence report: your access-review record for the cycle.

The evidence report: finding counts and a decisions table with KEEP, FLAG, and REVOKE chips, justifications, and reviewers
The evidence report — synthetic specimen · see the full sample →
$15per month · 3 scans included

Start now, self-serve.

Sign in with GitHub, connect an org, and run your first review today. Month-to-month, cancel anytime. MSPs: run it per client tenant — see the MSP program.

Questions

Access Review, answered.

Is this part of ITDR? +
No — they're separate products. ITDR is NSCA's identity-defense platform (Microsoft Graph-powered signals, risk scoring, incident response). Access Review & Evidence is Atomburst's own GitHub posture product, run from the Atomburst console. They're complementary: one watches identity threats live, the other proves your standing access is right.
What permissions does the GitHub App need? +
Read-only, least privilege. The App inventories access metadata — members, 2FA status, outside collaborators, app grants — and can never read or write your repository contents.
Where does the data live, and how long is it kept? +
Review data is metadata only, encrypted in transit and at rest, and kept as your evidence of record until you delete the tenant. See Security & Compliance for specifics.
Will my auditor actually accept the report? +
The report is built as evidence: dated snapshot, full population examined, per-finding decisions with justifications and named reviewers, formal objections, and logged exceptions. That's the structure access-review controls ask for — judge the sample yourself.
How often should I run it? +
Most teams review quarterly — one scan per cycle plus re-checks. The $15 tier includes 3 scans a month, which covers a quarterly cadence with room to verify fixes.

Your first review, today.

No sales call, no rollout project. Sign in with GitHub, connect the org, scan — and make the access decisions you've been meaning to make.

$15/month · 3 scans included · Cancel anytime