Every cloud app needs a visa
Your identity provider already knows which cloud apps hold privilege in the tenant. The problem is not that the data is missing — it is that nobody operationalizes it.
An permitted user opts the entire organization into a third-party SaaS app. A custom App Registration lands with mail, files, or role-management scopes. A cross-tenant partner relationship opens with inbound trust and auto-consent posture buried in admin portals. Consent is not authorization — but without a control loop, it becomes standing access anyway.
Dual-Strike XISEM Visa is the cloud app, OAuth, and cross-tenant trust surface in XISEM. Visa inventories what the identity provider authorizes, escalates when posture changes, supports analyst and certification review, and finishes with SOAR playbooks that revoke grants, disable apps, or remove them from the tenant.
Every cloud app needs a visa to operate in your tenant. Issue them deliberately. Revoke the rest.
Explore: dual-strike.com/visa · dual-strike.com
The gap in plain language
Most organizations discover cloud app risk in one of three painful ways:
• A user with consent rights grants org-wide access to a SaaS tool nobody in security has reviewed.
• An attacker or insider registers a custom application that holds secrets, certificates, or high-privilege Graph permissions.
• A guest-join or B2B cross-tenant path opens a trust relationship that analysts only find after an incident.
Microsoft Entra and Google Workspace Admin Console hold the truth. What they do not provide, by themselves, is a continuous control loop — readable inventory, deduplicated alerts, certification review, and evidence-backed response in the same platform where your analysts already work.
Visa closes that loop. It does not replace Entra or Google Admin. XISEM extends and operationalizes the evidence those systems produce — the same STAP posture we take with EDR, DNS, and identity: enrich, correlate, act.
Available now: what Visa inventories
Visa mirrors identity-provider truth — not browser discovery. Operators filter by provider, app kind, and permission mode. Trust & Guests isolates cross-org relationships that are easy to miss in native admin UIs.
• App Registrations — Custom Entra app registrations that can hold secrets, certificates, and Graph permissions — inventoried with publisher, permission mode, and first / last seen.
• Enterprise Apps — Service principals and enterprise applications in the directory — including app-only (application) permissions that never touch a human identity.
• Scopes & permission modes — Delegated scopes and application roles side by side. Filter by application vs delegated; high-risk scopes (mail, files, role management) are called out for triage.
• Consent users — User consent footprint and admin-consent flags — who granted what, whether the org is opted in, and how wide the blast radius is.
• Cross-tenant partners (XT Partners) — Entra cross-tenant partner orgs — default domain, inbound and outbound trust, auto-consent posture — so guest-join and B2B relationships are visible, not buried in portal JSON.
• Trust & Guests / cross-domain — Dedicated view for cross-org trust and Google domain-wide delegation. Correlate with guest invite / redeem and cross-tenant sign-in events.
Evidence arrives through Microsoft Entra and Google Workspace Gateways — read-only connectors that harvest OAuth app catalogs, consent posture, and trust relationships into durable Visa rows.
Consent is not authorization
Visa exists because the most common cloud-app failures are authorization failures dressed up as convenience:
• App Regs & Enterprise Apps — Custom registrations and enterprise apps that gain directory, mail, or Azure function without a security review.
• Org-wide SaaS consent — A permitted user opts the entire organization into a third-party SaaS app — Visa sees the grant, scores the scopes, and escalates.
• High-privilege scopes — Mail.ReadWrite, Files.ReadWrite.All, RoleManagement — alerted with labeled evidence for analysts, not a raw API dump.
• XT partners & guest-join — Cross-tenant partners with inbound / outbound trust and auto-consent — the path a rogue invite → accept → guest join can exploit.
• Consent requested & attempted — Admin consent requests and attempted grants surface before they become standing access.
• SOAR revoke & disable — Kill the OAuth grant, disable the service principal, or remove the app — with approval gates for destructive actions.
Readable evidence is the default story. Raw JSON remains available as an audit appendix — not the primary analyst view.
Inventory → Detect → Review → Act
Visa runs one control loop for the entire cloud app estate:
1. Inventory — App Registrations, Enterprise Apps, OAuth clients, scopes, consent users, XT partners, and cross-domain trust — durable rows in Visa from Entra and Google Workspace Gateways.
2. Detect — Posture-deduped alerts when a new app appears, high-privilege scopes land, or consent is requested or attempted — escalated through Alerts, Lookout, and COBRA².
3. Review — Analyst and certification review of publisher trust, application vs delegated permissions, partner inbound/outbound trust, and risk tier.
4. Act — SOAR playbooks revoke OAuth grants, disable the app, or remove it from the tenant — human-gated when destructive, evidence-backed when complete.
That loop is the difference between knowing apps exist in a portal and governing them as a security program.
Authority, attribution, and MFA coverage
Visa answers what is authorized in the identity provider. Sibling XISEM surfaces answer adjacent questions — without merging product names or confusing discovery with permission.
• SaaS App Attribution (Anti-Venom Secure Access) — What is used — browser-observed SaaS domains users actually open, including shadow and sanctioned apps from session telemetry, not only what the IdP lists.
• Visa — What is authorized — whether that app (or a parallel Graph or Workspace grant) holds consented privilege, and whether an XT partner or cross-domain trust path exists.
• SaaS / Cloud MFA Coverage — Was it stepped up — browser-attested login events show whether SaaS and cloud sign-ins challenged MFA, with gap analysis by app and by user.
• SSPM — Tenant posture — identity hygiene, mail flow, sharing, and admin sprawl across the broader SaaS control plane. Visa owns the app estate and cross-tenant trust; SSPM owns tenant-wide configuration drift.
• Shadow AI — AI sprawl — unsanctioned AI tools in browser, local CLI, and Copilot surfaces. When an AI product also holds Graph or Workspace grants, Visa is the revoke path.
One verdict, three lenses: Used ≠ authorized ≠ MFA-safe. When any lens fails, SOAR and certification campaigns close the loop.
Part of the XISEM family — not Anti-Venom
Product names should tell operators where to look:
• Scout watches endpoints.
• Sonar watches networks.
• Visa watches cloud apps and cross-tenant trust.
• Anti-Venom protects the browse path — Secure Access, Secure Resolve, Secure Elevate, Secure Control.
Lookout notifies technicians. COBRA² correlates. ASPIRE scores Access when OAuth and MFA posture move. One platform — clear product names.
What we do not claim
Public buyers deserve precision:
• Visa does not replace Microsoft Entra, Google Workspace Admin, or your identity provider's native app governance. XISEM extends and operationalizes that evidence.
• Visa does not enforce Conditional Access by itself. Inventory presence is not a policy engine.
• Visa does not substitute browser discovery for IdP authority — and vice versa. Both lenses matter.
• Visa does not ask you to rip out your CASB or SSPM vendor. Keep them. XISEM correlates what they cannot see alone when Gateways and sibling surfaces are connected.
Who this is for
• MSP and MSSP security leads managing multi-tenant M365 and Google Workspace portfolios
• vCISO and identity teams tired of Graph JSON archaeology for OAuth reviews
• Compliance and audit stakeholders who need readable evidence chains for app consent and cross-tenant trust
• Organizations closing Shadow AI and SaaS sprawl — where browser attribution finds usage and Visa confirms grants
Next step
If your cloud app estate lives in admin portals nobody reviews until something breaks, start here:
dual-strike.com/visa · dual-strike.com · Connect your Entra or Google Workspace Gateway · Request a demo
Issue visas deliberately. Revoke the rest.
— The Dual-Strike team


