EDR secures the device, but modern attacks target SaaS. Discover how frontier AI weaponizes integrations and how Obsidian secures your identity estate.

Ten years ago, if someone got onto a laptop in your fleet, you found out when the ransom note showed up. Antivirus checked hashes against a list and called it a day. EDR changed that completely. You got process trees, memory inspection, behavioral detections that catch a PowerShell one-liner doing something it shouldn't even though nothing about it matches a signature. You got the ability to actually hunt, and a whole generation of analysts learned the craft on that telemetry. MITRE ATT&CK became a shared vocabulary in large part because endpoint data gave it something to map onto.
Payroll is in Workday. Sales pipeline and customer records are in Salesforce. Code is in GitHub. The rest is in M365, Google, and Snowflake. None of it runs on hardware you own, and none of those vendors will let you install a driver on theirs.
Attackers know this. The intrusions that hurt now don't drop a binary; somebody logs in. A session token lifted off a phishing proxy that passed MFA. An OAuth grant to a "productivity" app nobody has patched since 2023. A service account password from 2019. To the endpoint, none of that is an event. A browser opened a tab, which it does four hundred times a day. The EDR reported nothing because nothing happened on the endpoint.
For years, that was survivable. Finding those weaknesses required someone to understand each application's permission model well enough to know what a stolen credential actually unlocked, and that expertise didn't scale. So attackers triaged too. A dormant token here, a local admin without MFA there, a departed contractor's grant still live: each one a low-severity finding, individually not worth anyone's time.
Frontier AI changed that. A frontier model reads an unfamiliar application's permission structure with the fluency of a specialist, at machine cost, on every target at once. One operator can point many agents at your identities, APIs, and integrations in parallel. They don't need any single finding to be severe. They need a few of them to connect, and they can now afford to look for every combination. A public portal leaks an OAuth client ID; a dormant token surfaces in a repository; that token's service account can read a runbook that names a local admin outside the IdP; that admin can authorize a new integration with org-wide read. Five "lows" become one working path, and the step that used to take a skilled human weeks, learning what a foothold can reach, now takes an agent hours.
Meanwhile the surface they're working on keeps growing. Copilot, ChatGPT Enterprise, Claude, and Gemini are wired directly into those same SaaS tenants. Each one authenticates as a user or a service identity, reads whatever that identity can reach, and acts on it. Employees connect them further with plugins, connectors, MCP servers, and marketplace agents, each of which is a third-party OAuth grant with its own scopes and its own vendor behind it. Every consent screen is a standing grant that outlives the enthusiasm that created it, doesn't appear in the IdP, and doesn't disappear when the employee leaves. The average enterprise now has hundreds of these integrations and can name maybe a dozen. Your own agents authenticate once and act ten thousand times, on delegated permissions, steerable by a paragraph of text in a shared doc.
None of this touches a process on a managed device. EDR answers "what ran on this machine?" Frontier AI forces a different question: "what can this identity reach, what did it do inside this app, and how fast can I revoke it?" Pretending the first tool answers the second is how you get a green dashboard and a breach.
A recruiting coordinator installs an AI scheduling assistant. It asks for Workday access to "read candidate and employee data." She approves; she has eleven interviews to book. The scope is coarse, so the token can read the directory, comp bands, and performance ratings.
Nine months later the vendor is acquired, the acquirer gets popped, and someone enumerates every Workday tenant the token reaches. Your data leaves through a legitimate API, on a legitimate grant, from a legitimate company's IP space. Total endpoint evidence: one browser tab, opened on install day.
Closing this gap comes down to three requirements, none of which can be met from an endpoint. Obsidian was built for exactly that layer: the identities, entitlements, and integrations inside the applications where the work happens. It connects to your SaaS and AI estate by API, no agent required.
Discovery: Know what exists and how it's permissioned. Not a point-in-time list of findings, but a live model of every identity, entitlement, integration, and agent across hundreds of applications. Obsidian builds that model normalized across systems that share no schema, covering human and non-human identities, in the IdP and outside it. It's time-aware, so it shows what each identity actually used versus what it was merely granted, and it's relationship-aware, so it traces the multi-hop chains a frontier-capable adversary would follow instead of listing findings one at a time. Shadow AI and unsanctioned integrations surface through browser telemetry alongside everything sanctioned.
Governance: Shrink the blast radius before anyone tests it. Obsidian drives the estate toward least privilege continuously: flagging risky integrations by vendor, scope, and usage, retiring dormant grants and orphaned credentials, tightening what's over-scoped, and putting controls on who can authorize new access in the first place, so the long tail stops regenerating as fast as it gets cleaned up. Remove one link and the chain is dead.
Enforcement: Detect and contain as it happens. Obsidian's streaming detections watch identity behavior across every connected application, baselined per identity, so anomalous activity is caught at the moment an adversary is learning what a foothold can reach. High-confidence detections trigger containment inside the application: revoke the grant, terminate the session, strip the scope, automatically and narrowly. And every detection built in one customer's environment becomes protection across all of them, which is the only mechanism that scales defense the way compute scales offense.
Anthropic secures the model. CrowdStrike secures where it runs. Obsidian secures the long tail where the work actually happens, which just became the front line.