saascode

KeyHorizon

A non-human credential lifecycle actuator that inventories metadata without secrets, builds an evidence-backed dependency graph, stages expiry or revocation plans, and executes only approved provider-supported actions with health readback and recovery.

Genesis score5.75/10
Make KeyHorizon real.0/500
500 more votes and KeyHorizon is authorized for build.
0%500 to authorize
Backing is the vote. When an idea crosses 500, we pull it into the build pipeline and ship it for real — the votes decide what gets built next, not an editor.
The opportunity
1Confirmed adjacent lifecycle incumbents
1Confirmed broad connector substrates
0Guaranteed reversible revocation providers
The case

Enterprise authorization grants, service accounts and agent keys can outlive their owners and intended purpose. The research confirms an enterprise lifecycle incumbent and a broad connector substrate, but no reviewed product combining blast-radius evidence with a mid-market revocation actuator. Connector availability does not prove that required lifecycle actions or rollback exist.

KeyHorizon should separate credential identity and metadata from secret value, issuer and provider, owner and purpose, creation and last verified use, expiry and rotation support, permissions and reachable resources, dependency observation and uncertainty, blast-radius evidence, stale candidate, owner attestation, canary and maintenance window, revocation or rotation plan, security approval, exact command, provider acknowledgment, service health readback, incident, replacement or restore plan, reconciliation and outcome.

Many revocations are irreversible. The product must never promise un-revocation, expose or copy secret material, revoke from absence of observed use alone, infer ownership, execute automatically in production, bypass provider controls or present a blast-radius score as proof of compromise, misuse or safe removal.

Who pays — and why

Enterprise identity, platform-security and service-ownership teams responsible for non-human credentials and stale authorization grants.

What it unlocks
A credential metadata registry with tenant, provider, credential type and identifier, issuer, owner, purpose, environment, creation, expiry, rotation support, status and last validation without storing the secret value
A dependency graph linking granted permissions, resources, observed callers and workloads, last verified use, evidence source and time, coverage gaps, uncertainty, business owner and criticality
A retirement case separating stale candidate, reason, owner attestation, alternative credential, canary, maintenance window, impact preview, security approval, revocation or rotation plan and recovery plan
An actuation ledger separating exact provider-supported command, idempotency, acknowledgment, service health readback, replacement distribution through approved systems, incident, restore or reissue, reconciliation and outcome
How Genesis scored it
5.75across seven criteria
tension 6temporal 5blindspot 5buyer 6leverage 8convergence 5why-not 5
8
Asymmetric leverage

A reusable evidence and provider-action layer can scale across supported credentials.

6
Productive tension

Fast credential retirement must coexist with incomplete dependency evidence, irreversible provider semantics and production availability.

5
Why nobody did it

The record does not prove which actuation or trust barrier recently changed.

Why it scored well

A clear non-human identity problem, confirmed enterprise lifecycle tooling and an actuation gap make a staged retirement workflow testable.

What's holding it back

Required providers, action and rollback semantics, dependency coverage, enterprise trust, buyer budget, liability and differentiation need validation.

Signals detected3 sources crossed
SignalGenesis research

SignalGenesis research

SignalGenesis research

Direction briefkeyhorizon.md
keyhorizon.md
Want this pointed at your vertical?Point Genesis at your own market and constraints — it invents adjacent, fork-ready ideas, private to you before they hit the public feed.

Discussion

?

No comments yet — be the first to weigh in.