Where things live in the app
Assets → Apps
Full app catalog — every discovered and manually-added app
Assets → Accounts
Per-user account view across all apps — with MFA, auth methods, last activity
Shadow IT
Unapproved apps discovered but not in your sanctioned catalog
Assets → Integrations → OAuth Grants
Third-party OAuth connections discovered via SSO sync
Identities → Users / Groups
Directory users and groups synced from your IdP
Security → Browser
Browser extension security signals — AI usage, passwords, file uploads
Discovery sources
Email intelligence
Domain-wide service account scans org mailboxes for vendor invoices, renewals, signups, and OAuth notifications
SSO & directory
Google Workspace, Microsoft Entra, and Okta sync every app accessed via SSO, user assignments, and OAuth grants
Browser extension
Chrome extension detects SaaS logins, tracks AI tool usage, and reports all installed browser extensions
Manual
Add any app directly from Assets → Apps → Add App
The Discovery page
The Discovery page (/discovery) in the sidebar is the entry point for email-based scanning specifically. When you first arrive:
- Not connected — shows an empty state with a “Connect Email” button linking to Settings → Integrations
- Scan in progress — redirects to the scanning progress view at
/discovery/scanning - Scan complete — shows total apps discovered and links to the full app catalog
The Discovery page focuses on the email scanning pipeline. The complete app catalog — combining all discovery sources — lives in Assets → Apps.
Multi-source correlation
When the same vendor is found across multiple sources, Porcia merges them into one app record:- Email finds a Salesforce invoice → creates the Salesforce record with pricing and renewal date
- SSO sync finds Salesforce in your Google Workspace → adds user count and login data
- Browser extension detects logins to salesforce.com → adds real usage frequency
Vendor matching pipeline
1
Domain matching
Sender domain, SSO app URL, or browser login domain is checked against Porcia’s global vendor database.
2
Alias resolution
Common aliases resolved —
SFDC → Salesforce, O365 → Microsoft 365, G Suite → Google Workspace.3
Fuzzy matching
Name variations and typos handled. Signals from multiple sources are deduplicated into one app record.
4
AI categorization
Unknown vendors classified by type, category, and whether they’re an AI tool.
5
Intelligence enrichment
Matched apps enriched with pricing benchmarks, compliance certifications, and AI classification.
Approval statuses
Every discovered app gets an approval status, which you can filter on in the Apps table:
Shadow IT apps start as Pending or are surfaced separately in the Shadow IT view.
Accounts view
The Assets → Accounts page shows every individual user account discovered — not just the apps. Columns include: Name of Account, User, Category, First Seen, Last Activity, MFA Status, Authentication Methods, User Status, and Organization Unit. Use this view for license utilization analysis — sorting by Last Activity to find abandoned accounts is the fastest way to identify waste.Next steps
Apps catalog
Manage your full app inventory
Shadow IT
Review unapproved apps
OAuth Grants
Audit third-party access from SSO
Connect integrations
Add more discovery sources