The problem
You don't know your full stack
Shadow IT is everywhere. Teams spin up tools, grant OAuth access, and create accounts without IT knowing. Your actual stack is much larger than what’s managed.
Access sprawl goes unchecked
Employees accumulate app access over time. OAuth grants pile up. Offboarded users retain licenses. Nobody has a complete picture.
Security risks go unnoticed
Risky browser extensions, over-permissioned OAuth apps, and AI tools handling sensitive data create real exposure that traditional tools miss.
Renewals and spend are scattered
Contracts in email, invoices in inboxes, pricing in spreadsheets. No single source of truth for what you spend or when things renew.
What Porcia does
1
Discovers your complete stack
Connects to your email (domain-wide service account), SSO providers (Google Workspace, Microsoft Entra, Okta), and browser extension to find every app in use — including shadow IT and OAuth grants your team has authorized.
2
Governs access and security
Surfaces security posture issues as Findings, inventories OAuth grants with risk scores, tracks unapproved apps in Shadow IT, and gives you Workflows (Playbooks, Pulses, Rules) to act on everything systematically.
3
Tracks spend and usage
Dashboard → Spend shows what you’re paying, who’s actually using each tool, where licenses are going to waste, and what’s renewing soon — so you can act before auto-renewals lock you in.
4
Pia keeps things moving
Ask Pia — Porcia’s in-app AI assistant — to look up data, send pulses, manage rules, handle access requests, and surface optimization opportunities. No switching tabs.
How the app is organized
Dashboard
Dashboard
Overview metrics, Shadow apps, AI usage, Spend, Governance, Compliance, and Posture sub-pages. Your starting point for the state of the org.
Assets
Assets
Apps — complete app catalog, every discovered and manually-added app.
Accounts — per-user account view across all apps.
Browser Extension — extension enrollment and deployment.
Integrations — OAuth Grants, Risk Score, and MCP Connections.
Findings
Findings
Top-level item. Security posture checks with risk levels, filters, group-by views, and guided remediation for every issue.
Shadow IT
Shadow IT
Top-level item. Unapproved apps discovered across all sources — with actions to approve, deny, or replace each one.
Security → Browser
Security → Browser
Browser extension signals: AI usage, password strength and reuse, file uploads to AI chatbots, and shared account detection.
Workflows
Workflows
Playbooks — multi-step operational workflows.
Pulses — async employee outreach to verify app usage.
Rules — event-based automation.
Identities
Identities
Users — directory users with MFA status and extension enrollment.
Groups — directory group memberships.
Service Accounts — non-human identities.
Requests
Requests
Top-level item. App access request workflow — employees submit, admins review and act, everything logged.
Core capabilities
- Discovery
- Governance & Security
- Intelligence & Spend
Three complementary sources run automatically and feed a single unified app catalog.
How discovery works end to end
Full architecture, matching pipeline, and where results surface
Who uses Porcia
IT teams
Complete app visibility, access request management, offboarding playbooks, shadow IT review, browser extension governance
Security teams
Findings and remediation, OAuth grant auditing, browser security signals, MCP connection and extension supply chain risk
Finance teams
Spend dashboard with inactive license detection, upcoming renewals, redundant apps, and unapproved spend
Operations
Onboarding and offboarding playbooks, pulse outreach, access reviews, automated offboarding via rules
Security & privacy
Encryption
AES-256 at rest, TLS 1.3 in transit
Email privacy
Content processed in memory, never persisted — only extracted metadata is stored
Extension privacy
Sends only: domain, detection method, work email boolean — no page content or credentials
Access control
Role-based permissions with full audit logs and GDPR-compliant data handling
Pricing
Porcia is usage-based — **200/month floor).- Standard
- Enterprise
**200/mo floor)
- All discovery sources (email, SSO, browser extension)
- Full governance suite (Findings, OAuth Grants, Shadow IT, Requests, Rules, Playbooks, Pulses)
- Security → Browser signals
- Pia AI assistant
- Slack & Teams integration
- Standard support
Start your trial
14-day free trial — no credit card required
What Porcia does and doesn’t do
Discovers SaaS and Shadow AI usage
Finds every app across email, SSO, and browser — including shadow IT and OAuth grants no one explicitly approved
Governs access and security
Findings, OAuth grant revocation, shadow IT review, access requests, rules, playbooks, and employee pulse outreach
Tracks spend and renewals
Surfaces inactive licenses, redundant tools, and upcoming renewals so you can act before auto-renewal locks you in
Read-only email and IdP access
Porcia cannot send email from your mailboxes, modify your IdP, or take any write action outside of explicit OAuth grant revocation
Does not negotiate on your behalf
Porcia does not contact vendors or act as a procurement tool on your behalf
Does not send email from your accounts
Email Intelligence is strictly read-only. Pulses are sent from Porcia’s own email system, not your connected mailboxes
Quickstart guide
Up and running in under 10 minutes
How it works
Full architecture and navigation guide
Connect email
Set up email intelligence
Connect SSO
Connect your identity provider