HomeCybersecurityToxic Access Combination Detector

Toxic Access Combination Detector

Interactive 2D entitlement-graph simulator that flags 'toxic combinations' — accounts holding both read access to sensitive data and destructive rights like delete or export — scores their blast-radius risk, and lets you enforce least-privilege remediation live.

Cybersecurity2DModerate60 FPS📱 Mobile-adapted⇄ 3D version
2d-cybersec-topic-38 ↗ Open standalone

Data Security Posture Management lives or dies on one question: which accounts can both see sensitive data and destroy or move it out? This simulator renders a live 2D account × permission matrix and runs a real set-containment detection pass across it on every edit, flagging every "toxic combination" where an account's full permission set contains a complete predefined rule — read access plus destructive rights, or a create/approve pair that lets one person originate and rubber-stamp their own fraud. Toggle any cell to grant or revoke a permission and watch rows flip red the instant a toxic rule set is completed, and clear the instant it is broken.

⚙ Under the hood

Interactive 3D entitlement-graph simulator that flags 'toxic combinations' — accounts holding both read access to sensitive data and destructive rights like delete or export — scores their blast-radius risk, and lets you enforce least-privilege remediation live.

cybersecurityDSPMIAMaccess controlrisk scoringThree.js

2D · HTML5 Canvas 2D · 60 FPS target · runs fully client-side, no install

What did you find?

Add reproduction steps (optional)