Skip to main content
Porcia builds a continuously-updated inventory of your SaaS estate from three sources: email intelligence, SSO & directory sync, and the browser extension. Once discovered, all apps land in Assets → Apps.

Where things live in the app

Assets → Apps

Full app catalog — every discovered and manually-added app

Assets → Accounts

Per-user account view across all apps — with MFA, auth methods, last activity

Shadow IT

Unapproved apps discovered but not in your sanctioned catalog

Assets → Integrations → OAuth Grants

Third-party OAuth connections discovered via SSO sync

Identities → Users / Groups

Directory users and groups synced from your IdP

Security → Browser

Browser extension security signals — AI usage, passwords, file uploads

Discovery sources

Email intelligence

Domain-wide service account scans org mailboxes for vendor invoices, renewals, signups, and OAuth notifications

SSO & directory

Google Workspace, Microsoft Entra, and Okta sync every app accessed via SSO, user assignments, and OAuth grants

Browser extension

Chrome extension detects SaaS logins, tracks AI tool usage, and reports all installed browser extensions

Manual

Add any app directly from Assets → Apps → Add App

The Discovery page

The Discovery page (/discovery) in the sidebar is the entry point for email-based scanning specifically. When you first arrive:
  • Not connected — shows an empty state with a “Connect Email” button linking to Settings → Integrations
  • Scan in progress — redirects to the scanning progress view at /discovery/scanning
  • Scan complete — shows total apps discovered and links to the full app catalog
The Discovery page focuses on the email scanning pipeline. The complete app catalog — combining all discovery sources — lives in Assets → Apps.

Multi-source correlation

When the same vendor is found across multiple sources, Porcia merges them into one app record:
  • Email finds a Salesforce invoice → creates the Salesforce record with pricing and renewal date
  • SSO sync finds Salesforce in your Google Workspace → adds user count and login data
  • Browser extension detects logins to salesforce.com → adds real usage frequency
The result is one record in Assets → Apps with all three data layers combined.

Vendor matching pipeline

1

Domain matching

Sender domain, SSO app URL, or browser login domain is checked against Porcia’s global vendor database.
2

Alias resolution

Common aliases resolved — SFDC → Salesforce, O365 → Microsoft 365, G Suite → Google Workspace.
3

Fuzzy matching

Name variations and typos handled. Signals from multiple sources are deduplicated into one app record.
4

AI categorization

Unknown vendors classified by type, category, and whether they’re an AI tool.
5

Intelligence enrichment

Matched apps enriched with pricing benchmarks, compliance certifications, and AI classification.

Approval statuses

Every discovered app gets an approval status, which you can filter on in the Apps table: Shadow IT apps start as Pending or are surfaced separately in the Shadow IT view.

Accounts view

The Assets → Accounts page shows every individual user account discovered — not just the apps. Columns include: Name of Account, User, Category, First Seen, Last Activity, MFA Status, Authentication Methods, User Status, and Organization Unit. Use this view for license utilization analysis — sorting by Last Activity to find abandoned accounts is the fastest way to identify waste.

Next steps

Apps catalog

Manage your full app inventory

Shadow IT

Review unapproved apps

OAuth Grants

Audit third-party access from SSO

Connect integrations

Add more discovery sources