Path
Identity and permission edges keep provenance
Each accepted path retains its source and confidence so a reviewer can inspect how the principal reaches the resource.
Capability
Follow an identity and permission path to the reachable assets and data, compute the blast radius, identify the smallest access-edge cut set, and attach the remediation to the existing FAIR financial-impact spine.
Cloud findings, IaC and Kubernetes posture, identity and permission paths, CIEM blast radius, minimal cut sets, remediation proof, and cloud-to-dollar risk. Valty turns this domain's signals into priced, proof-backed risk you can act on.
Design-partner engine. Incomplete identity or permission data is degraded, never assumed safe; native enforcement remains customer-owned.
Best next step for Cloud security, CISO: choose “See how this attaches to CRQ” to review the workflow, evidence boundary, and fit for your environment.

CIEM blast radius
Valty carries identity and permission paths across the unified evidence graph, identifies the reachable assets and data, and ties the smallest remediation cut set to the FAIR impact already on the graph.
Path
Each accepted path retains its source and confidence so a reviewer can inspect how the principal reaches the resource.
Radius
The impact set stays machine-checkable rather than collapsing into a generic criticality label.
Cut set
Valty ranks the access edges whose removal severs the origin from the financially anchored assets.
Impact
The graph attaches to recorded financial exposure and does not invent a second, disconnected risk score.
Identity path
Valty complements the cloud and graph tools already in place. Incomplete identity or permission paths degrade confidence; they never count as safe.
Proof matrix
Every claim shows its source, confidence, and limits, so you can trust the number before you act on it.