Are identity security posture management tools actually useful beyond finding misconfigurations?
finding problems was never the hard part for us. deciding what to fix first with a small team is.
what's changed things for us is having full discovery and mapping feed directly into prioritization, so the tool tells you which of the hundred findings actually raises your risk instead of handing you a flat list. has anyone gotten real prioritization value out of a platform like that, or are you still triaging manually after the scan runs?