Operate · Third-party access

Every outside app, token and role with access to your code and cloud.

Heeler finds the apps, tokens, webhooks, deploy keys and cloud roles that outside vendors hold, shows what each could do if that vendor were compromised, and tells you what to cut back.

Inventory

Find every vendor with a way in.

Heeler reads app installations, tokens, webhooks, deploy keys and cloud trust policies, and matches each one to the vendor behind it.

appsGitHub Apps, fine-grained tokens and webhooks
keyGitLab tokens, deploy keys, bot users and integrations
cloudAWS roles trusted from outside, Google Cloud outside bindings and federation
Vendors31 vendors · 112 connections
VendorViaHighest accessReposAccountsStatus
unknownAWS roleAdmin01Unverified
CircleCIGitHub AppWrite2140Verified
DatadogAWS roleRead012Verified
SentryWebhookEvents560Unused
HCP TerraformOIDC roleWrite34Verified
Matched against Heeler's vendor catalog95 vendorsby app, role, OIDC host, webhook host or domain660+ AWS accountsknown to belong to vendors, each with a public source
Blast radius

See what each vendor could do if it were compromised.

Every connection is rolled up to Read, Write or Admin across code, pull requests, workflows, secrets, org settings, compute, data, IAM and account admin.

grid_viewNine access areas across source control and cloud
crisis_alertBlast radius in plain sentences, per vendor
scheduleLast used, for every connection
If CircleCI were compromisedAdmin
appsGitHub AppcloudOIDC rolescheduleLast used 2 hours ago
WritePush code to all 214 repositories in acme
AdminRead and change Actions secrets
WriteDeploy to 3 AWS accountsprod-payments · prod-us · prod-eu
ReadRead pull requests and issues
grid_viewAccess matrix · 9 areas across source control and cloud · granted and used in 90 daysAdmin
Right-size

Cut each vendor back to the access it uses.

Heeler recommends a specific change for every over-scoped connection, with the policy or binding as evidence and a link to fix it at the provider.

tuneLimit apps to the repositories they serve
key_offRevoke tokens whose owner left
shield_lockRequire External ID and restrict OIDC subjects
Right-size · 6 recommendationsacme
apps
Limit deploy-helper to the 12 repositories it usesGitHub App installed on all 214 repositories
Write
key
Revoke the token owned by j.ruizOwner left the organization in July
Write
cloud
Require sts:ExternalId on audit-accessRole trusted by an outside account without it
Admin
ruleRestrict the OIDC subject on terraform-deployany repo can assume it
person_offRemove personal Google account from prod-dataOwner
open_in_newEvidence: the trust policy or binding, with a link to revoke it at the providerAWS
Unused and unknown

Find access no one uses and accounts no one can name.

Connections idle for 90 days are flagged. Outside accounts that match no known vendor stay Unverified until you confirm them.

historyUnused after 90 days
helpUnverified outside accounts, domains and personal accounts
verifiedMark your own accounts as trusted
Needs reviewacme
help
AWS account no vendor ownsCan assume audit-access · AdministratorAccess
Unverified
person
Personal Google account on prod-dataOwner role on a production project
Personal
keyGitLab deploy token · ci-runner-oldunused 211 days
webhookWebhook to hooks.oldvendor.iofailing since August
verifiedAWS account 2210 · acme-securitymarked trusted
14Unused 90+ days
3Unverified
2Marked trusted
For security and audit

Answer the vendor access questions in minutes.

The same inventory answers an incident, a quarterly access review and a cleanup sprint.

Vendor incidentA vendor reports a breach. What can they reach?214 repos, Actions secretsand 3 production AWS accounts, with the last time each was used
Access reviewWho outside the company can change production?4 vendors with Adminacross GitHub, GitLab, AWS and Google Cloud, in one list
CleanupWhat can we remove today?14 unused connectionsplus 6 right-size changes, each with the evidence

How it works

ConnectUses your existing connectionsThe GitHub, GitLab, AWS and Google Cloud connections Heeler already has. Nothing new to install.
MatchEvery connection to a vendorApps, roles, OIDC hosts, webhook hosts and domains, matched against 95 known vendors.
ReviewVendors, matrix and evidenceA vendor list, an access matrix and the raw policy behind every finding.

Purpose-built for the AI SDLC

Know which vendors can reach your code and cloud, and cut what they do not need.