Identity visibility and hygiene tools compared
SHORT ANSWER
Editorial assessment · Desk research from public vendor material · Reviewed 2026-09-29
Ranking
| Rank | Product | Total | Best for |
|---|---|---|---|
| 1 | Veza | 7.6 / 10 | The widest inventory of who can access what, across clouds, data and SaaS |
| 2 | Silverfort | 7.3 / 10 | Turning identity findings into inline enforcement |
| 3 | NewCore | 6.8 / 10 | One live graph of people and AI agents, with fixes such as revoking stale grants |
| 4 | Push Security | 6.6 / 10 | Seeing the SaaS logins and MFA gaps that happen in the browser |
| 5 | Semperis | 6.5 / 10 | A free, detailed hygiene report for Active Directory, Entra ID and Okta |
How the scores are weighted
- c1 Breadth of sources 25%
- c2 People, machines and agents in one view 20%
- c3 Hygiene findings 20%
- c4 Acting on findings 15%
- c5 Effort to start 10%
- c6 Maturity and buying clarity 10%
Totals are the weighted average of the criterion scores, computed from the weights shown. Nothing is adjusted by hand.
Scorecard
| Criterion | Veza7.6 / 10 | Silverfort7.3 / 10 | NewCore6.8 / 10 | Push Security6.6 / 10 | Semperis6.5 / 10 |
|---|---|---|---|---|---|
| c1Breadth of sources25%How many systems feed the inventory. | 9Highest in set325+ integrations across clouds, identity platforms, data systems and SaaS. Source: Veza | 7Identity graph and inventory across on-prem, cloud and hybrid environments. Source: Silverfort platform · Silverfort: ITDR | 6Sources named are Okta, AWS, Microsoft, BambooHR, Salesforce and Google; no integration count is published. Source: NewCore: Identity Discovery | 6Sees the apps and logins employees actually use, through the browser. Source: Push Security | 5Lowest in setCovers Active Directory, Entra ID and Okta. Source: Semperis Purple Knight |
| c2People, machines and agents in one view20%Whether human, machine and AI agent identities sit in the same graph. | 8The Access Graph unifies people, machines and third parties; AI agent visibility is listed as new. Source: Veza | 8Human, service account and AI agent identities are all covered. Source: Silverfort: non-human identity security · Silverfort: AI agent security | 9Highest in setOne live graph of every human, AI agent, system, app and access path. Source: NewCore: Identity Discovery | 5Tracks employee and agent activity in the browser; machine accounts outside the browser are out of scope. Source: Push Security | 4Gap in public materialLowest in setFocused on directory objects; a combined view of agents is not described. Source: Semperis Purple Knight |
| c3Hygiene findings20%Stale access, excess privilege, weak or missing MFA, and similar findings. | 8Detects dormant accounts and excessive privileges. Source: Veza | 7Lowest in setAccess intelligence and behavioral baselines for service accounts. Source: Silverfort platform · Silverfort: non-human identity security | 7Lowest in setShows stale grants and over-broad agent reach, and scores every authenticator from 1 to 10. Source: NewCore: Identity Discovery · NewCore: Identity Security | 8Finds login paths that bypass SSO, unmanaged identities and missing MFA. Source: Push Security | 9Highest in setPurple Knight checks 218+ indicators of exposure and compromise and grades the results. Source: Semperis Purple Knight |
| c4Acting on findings15%Can a finding be fixed or enforced from the product? | 5Gap in public materialLowest in setRemediation from the product is not described on the page reviewed. Source: Veza | 8Highest in setFindings can be enforced inline with policies and MFA. Source: Silverfort: ITDR · Silverfort: non-human identity security | 8Highest in setFindings carry actions such as revoking a stale grant or notifying the owner. Source: NewCore: Identity Discovery | 7In-browser guardrails push users toward MFA and stronger credentials. Source: Push Security | 6Remediation guidance in the report; automated rollback is a separate paid product. Source: Semperis Purple Knight · Semperis Directory Services Protector |
| c5Effort to start10%What has to be deployed before the first result. | 6Gap in public materialIntegration-based; deployment effort is not stated. Source: Veza | 7States no app or code changes are needed. Source: Silverfort platform | 5Gap in public materialLowest in setDeployment steps are not published. Source: NewCore home page | 8Highest in setA browser extension, with no endpoint agent; works on unmanaged devices. Source: Push Security | 8Highest in setFree downloadable assessment. Source: Semperis Purple Knight |
| c6Maturity and buying clarity10%Time in market, free options, named customers, pricing. | 8Gap in public materialNames customers including Workday, Snowflake and Blackstone; pricing not published. Source: Veza | 6Gap in public materialPricing not published. Source: Silverfort platform | 4Lowest in setLaunched June 2026; no pricing or named customers. | 6Gap in public materialPricing not published. Source: Push Security | 9Highest in setPurple Knight is free; long-running AD security vendor. Source: Semperis Purple Knight |
Veza
7.6 / 10
c1 · 25%
Breadth of sources
9Highest in set
325+ integrations across clouds, identity platforms, data systems and SaaS.
Source: Veza
c2 · 20%
People, machines and agents in one view
8
The Access Graph unifies people, machines and third parties; AI agent visibility is listed as new.
Source: Veza
c4 · 15%
Acting on findings
5Gap in public materialLowest in set
Remediation from the product is not described on the page reviewed.
Source: Veza
c5 · 10%
Effort to start
6Gap in public material
Integration-based; deployment effort is not stated.
Source: Veza
c6 · 10%
Maturity and buying clarity
8Gap in public material
Names customers including Workday, Snowflake and Blackstone; pricing not published.
Source: Veza
Silverfort
7.3 / 10
c1 · 25%
Breadth of sources
7
Identity graph and inventory across on-prem, cloud and hybrid environments.
Source: Silverfort platform · Silverfort: ITDR
c2 · 20%
People, machines and agents in one view
8
Human, service account and AI agent identities are all covered.
Source: Silverfort: non-human identity security · Silverfort: AI agent security
c3 · 20%
Hygiene findings
7Lowest in set
Access intelligence and behavioral baselines for service accounts.
Source: Silverfort platform · Silverfort: non-human identity security
c4 · 15%
Acting on findings
8Highest in set
Findings can be enforced inline with policies and MFA.
Source: Silverfort: ITDR · Silverfort: non-human identity security
c6 · 10%
Maturity and buying clarity
6Gap in public material
Pricing not published.
Source: Silverfort platform
NewCore
6.8 / 10
c1 · 25%
Breadth of sources
6
Sources named are Okta, AWS, Microsoft, BambooHR, Salesforce and Google; no integration count is published.
Source: NewCore: Identity Discovery
c2 · 20%
People, machines and agents in one view
9Highest in set
One live graph of every human, AI agent, system, app and access path.
Source: NewCore: Identity Discovery
c3 · 20%
Hygiene findings
7Lowest in set
Shows stale grants and over-broad agent reach, and scores every authenticator from 1 to 10.
Source: NewCore: Identity Discovery · NewCore: Identity Security
c4 · 15%
Acting on findings
8Highest in set
Findings carry actions such as revoking a stale grant or notifying the owner.
Source: NewCore: Identity Discovery
c5 · 10%
Effort to start
5Gap in public materialLowest in set
Deployment steps are not published.
Source: NewCore home page
c6 · 10%
Maturity and buying clarity
4Lowest in set
Launched June 2026; no pricing or named customers.
Push Security
6.6 / 10
c1 · 25%
Breadth of sources
6
Sees the apps and logins employees actually use, through the browser.
Source: Push Security
c2 · 20%
People, machines and agents in one view
5
Tracks employee and agent activity in the browser; machine accounts outside the browser are out of scope.
Source: Push Security
c3 · 20%
Hygiene findings
8
Finds login paths that bypass SSO, unmanaged identities and missing MFA.
Source: Push Security
c4 · 15%
Acting on findings
7
In-browser guardrails push users toward MFA and stronger credentials.
Source: Push Security
c5 · 10%
Effort to start
8Highest in set
A browser extension, with no endpoint agent; works on unmanaged devices.
Source: Push Security
c6 · 10%
Maturity and buying clarity
6Gap in public material
Pricing not published.
Source: Push Security
Semperis
6.5 / 10
c1 · 25%
Breadth of sources
5Lowest in set
Covers Active Directory, Entra ID and Okta.
Source: Semperis Purple Knight
c2 · 20%
People, machines and agents in one view
4Gap in public materialLowest in set
Focused on directory objects; a combined view of agents is not described.
Source: Semperis Purple Knight
c3 · 20%
Hygiene findings
9Highest in set
Purple Knight checks 218+ indicators of exposure and compromise and grades the results.
Source: Semperis Purple Knight
c4 · 15%
Acting on findings
6
Remediation guidance in the report; automated rollback is a separate paid product.
Source: Semperis Purple Knight · Semperis Directory Services Protector
c6 · 10%
Maturity and buying clarity
9Highest in set
Purple Knight is free; long-running AD security vendor.
Source: Semperis Purple Knight
What is identity visibility?
Identity visibility is knowing every identity in the organization, human, machine and AI agent, and what each one can reach. Cloud identity visibility tools extend that to cloud IAM roles, SaaS accounts and the permissions attached to them. Without it, the other controls on this site have nothing to act on.
What is identity observability?
Identity observability is a newer term for watching how identities are actually used, not only how they are configured: which accounts sign in, from where, and which permissions are exercised. The difference matters because an account can be correctly configured and still unused, or used in a way nobody intended.
What is identity hygiene?
Identity hygiene is the routine work of removing what should not be there: accounts nobody owns, access that is no longer needed, privileges broader than the job, sign-ins without MFA, logins that bypass single sign-on, and long-lived secrets. The findings column of the scorecard measures how much of that each tool surfaces.
Guide: an identity hygiene checklist for people, machines and agents
Visibility tools and ITDR: how do they differ?
Visibility and hygiene tools find the weaknesses an attacker would use. ITDR tools look for the attacker using them. Several vendors do both, Silverfort and Semperis among them, but the buying question is different: a visibility tool is judged on coverage and findings, an ITDR tool on detections and response.
The five tools, one by one
Veza
Access graph and identity security posture
Best for: The widest inventory of who can access what, across clouds, data and SaaS
LEADS ON
Silverfort
Inline identity protection across on-prem, cloud and agents
Best for: Turning identity findings into inline enforcement
LEADS ON
c2 People, machines and agents in one view 8
Human, service account and AI agent identities are all covered.
Source: Silverfort: non-human identity security · Silverfort: AI agent security
c4 Acting on findings 8
Findings can be enforced inline with policies and MFA.
Source: Silverfort: ITDR · Silverfort: non-human identity security
TRAILS ON
c6 Maturity and buying clarity 6
Pricing not published.
Source: Silverfort platform
c1 Breadth of sources 7
Identity graph and inventory across on-prem, cloud and hybrid environments.
Source: Silverfort platform · Silverfort: ITDR
NewCore
Identity provider for people and AI agents, launched June 2026
Best for: One live graph of people and AI agents, with fixes such as revoking stale grants
LEADS ON
c2 People, machines and agents in one view 9
One live graph of every human, AI agent, system, app and access path.
Source: NewCore: Identity Discovery
c4 Acting on findings 8
Findings carry actions such as revoking a stale grant or notifying the owner.
Source: NewCore: Identity Discovery
TRAILS ON
c6 Maturity and buying clarity 4
Launched June 2026; no pricing or named customers.
c5 Effort to start 5
Deployment steps are not published.
Source: NewCore home page
Push Security
Browser-based identity security
Best for: Seeing the SaaS logins and MFA gaps that happen in the browser
LEADS ON
c3 Hygiene findings 8
Finds login paths that bypass SSO, unmanaged identities and missing MFA.
Source: Push Security
c5 Effort to start 8
A browser extension, with no endpoint agent; works on unmanaged devices.
Source: Push Security
TRAILS ON
c2 People, machines and agents in one view 5
Tracks employee and agent activity in the browser; machine accounts outside the browser are out of scope.
Source: Push Security
c1 Breadth of sources 6
Sees the apps and logins employees actually use, through the browser.
Source: Push Security
Push Security alternatives · Compare Push Security head to head
Semperis
Active Directory and Entra ID protection and recovery
Best for: A free, detailed hygiene report for Active Directory, Entra ID and Okta
LEADS ON
c3 Hygiene findings 9
Purple Knight checks 218+ indicators of exposure and compromise and grades the results.
Source: Semperis Purple Knight
c6 Maturity and buying clarity 9
Purple Knight is free; long-running AD security vendor.
Source: Semperis Purple Knight
TRAILS ON
c2 People, machines and agents in one view 4
Focused on directory objects; a combined view of agents is not described.
Source: Semperis Purple Knight
c1 Breadth of sources 5
Covers Active Directory, Entra ID and Okta.
Source: Semperis Purple Knight
Questions
What is identity hygiene?
Removing identity risk that should not exist: unowned accounts, unused or excessive access, missing MFA, logins that bypass SSO and long-lived secrets.
Is there a free identity hygiene assessment?
Semperis offers Purple Knight free. It checks 218+ indicators of exposure and compromise across Active Directory, Entra ID and Okta.
Which identity visibility tool scores highest?
Veza on the weights used here. NewCore scores highest on a single view of people, machines and agents, and Semperis on hygiene findings.
Related topics
Sources
- Veza: https://veza.com/
- NewCore: Identity Discovery: https://newcore.com/platform/identity-discovery
- NewCore: Identity Security: https://newcore.com/platform/identity-security
- NewCore home page: https://newcore.com/
- NewCore launch release (PR Newswire): https://www.prnewswire.com/news-releases/newcore-emerges-from-stealth-with-66m-to-rebuild-workforce-identity-for-the-agentic-era-302799643.html
- Semperis Purple Knight: https://www.semperis.com/purple-knight/
- Semperis Directory Services Protector: https://www.semperis.com/active-directory-security/
- Silverfort platform: https://www.silverfort.com/
- Silverfort: ITDR: https://www.silverfort.com/platform/identity-threat-detection-and-response/
- Silverfort: non-human identity security: https://www.silverfort.com/platform/non-human-identity-security/
- Silverfort: AI agent security: https://www.silverfort.com/platform/ai-agent-security
- Push Security: https://pushsecurity.com/
- OWASP Non-Human Identities Top 10 (2025): https://owasp.org/www-project-non-human-identities-top-10/