Data Security Posture Management doesn't stop at discovering and classifying sensitive data — the harder question is who can actually reach it. This simulator renders a live entitlement graph on two concentric rings: an outer ring of data stores classified Public through Restricted, an inner ring of identities holding either scoped-read or over-privileged wildcard grants, and a line for every access relationship between them. Drag the graph to rotate it and inspect the rings from any angle. A store only turns into a flagged "toxic combination" when high sensitivity, internet exposure and an over-privileged grant converge on the same store at once — the same convergence real DSPM and CSPM tools hunt for across cloud estates. Widen the entitlement-breadth slider to watch sprawl accumulate, turn on auto-remediation to watch least-privilege pruning collapse the aggregate risk score back down (traced live in the strip below the graph), or run a fresh entitlement scan to audit an entirely new access matrix.