Skip to main content
Porcia connects to your existing infrastructure — email, identity providers, and browsers — and builds a continuously-updated picture of your SaaS estate. Here’s what happens under the hood and where everything surfaces in the app.

App structure at a glance

The sidebar is organized into these main sections:

Discovery sources

1. Email Intelligence (domain-wide)

Porcia connects using a service account (Google Workspace) or app-only auth (Microsoft Entra) to run targeted search queries across your org’s mailboxes — server-side, without reading personal email. What it finds: vendor invoices, renewal notices, signup confirmations, OAuth grant notifications, pricing change emails. How content is handled: Email content is processed in memory and immediately discarded. Only extracted structured metadata (vendor name, amount, date, renewal flag) is retained. Nothing from inside the email body is persisted. Where results appear: Assets → Apps, Dashboard → Spend

2. SSO & Directory Discovery

Connects to your identity provider to discover every application accessed via SSO and sync your directory structure. Supported providers: Google Workspace, Microsoft Entra ID (Azure AD), Okta What it discovers:
  • Every SSO-enabled application (SAML, OIDC, OAuth)
  • User-to-app assignments and group memberships
  • Login events and access frequency
  • OAuth grants (third-party apps with delegated access)
  • Directory users and groups (org structure, department, MFA status)
Where results appear: Assets → Apps, Assets → Accounts, Assets → Integrations → OAuth Grants, Identities → Users/Groups
Okta full per-user directory attribute sync is partially supported. Google Workspace and Microsoft Entra have complete directory sync including department, org unit, and MFA status.

3. Browser Extension

A lightweight Chrome extension deployed to employee devices. What it tracks:
  • Domains where a login event is detected (form submit, OAuth click, SSO redirect)
  • Detection method (login_form, oauth_google, oauth_microsoft, saml_sso)
  • Whether a work email was used (boolean only — the address itself is never stored)
  • All browser extensions installed on the device (name, version, permissions, deployment method)
  • AI tool usage, password signals, and file upload events
Where results appear: Security → Browser, Assets → Apps (usage signals), Dashboard → AI, Assets → Accounts

Vendor matching pipeline

Every signal from every source goes through matching before appearing in Assets → Apps:
1

Domain matching

Sender domain, SSO app URL, or browser login domain checked against Porcia’s global vendor database.
2

Alias resolution

Common aliases resolved — SFDC → Salesforce, O365 → Microsoft 365, G Suite → Google Workspace.
3

Fuzzy matching

Name variations handled. Signals from multiple sources deduplicated into one app record.
4

AI categorization

Unknown vendors classified by category and AI classification (LLM assistant, AI coding tool, etc.).
5

Intelligence enrichment

Matched apps enriched with pricing benchmarks, compliance certifications, breach history, and AI data handling details from Porcia’s global vendor database.

Governance engine

Once apps are in your inventory, the governance layer runs continuously on top of them. Findings — security posture checks run on a schedule. When a check fails (risky OAuth grant, app accessed outside SSO, sideloaded extension), a finding is created in Findings with severity, evidence, and remediation steps. Rules — evaluate every incoming event against admin-defined conditions and fire actions (notifications, finding creation, assignments) in real time. Live under Workflows → Rules. Playbooks — multi-step workflows triggered manually or by a rule. Each step is assigned, timestamped, and auditable. Live under Workflows → Playbooks. Pulses — async outreach to employees delivered via Slack, Teams, or email. Structured responses (Yes/No/Not Sure) feed back into your app inventory automatically. Live under Workflows → Pulses. Access Requests — employees request app access through a structured form. Admins review with full context and act — everything logged. Lives at Requests in the top-level nav.

Pia — AI assistant

Pia is Porcia’s in-app AI assistant accessible from the chat icon in the bottom-right corner. She has full knowledge of your workspace data and can take real actions — not just answer questions. She can look up data from any section of the app, explain how features work, send pulses, create rules, deny access requests, and surface optimization opportunities. See Pia for a full capabilities reference.

Data security

Next steps

Connect Email

Set up domain-wide email intelligence

Connect SSO

Discover apps via your identity provider

Governance overview

Explore findings, workflows, and identity management

Meet Pia

Your AI assistant inside Porcia