KRYOS-XS Edge / Service 03
Cloud Exposure and Configuration Decisioning
Identify configuration changes that may create unnecessary exposure, while the change is still being made.
What this service does
The problem, the evidence, and what stays with you
The problem addressed
A single configuration change can expose storage, widen an identity policy or open a security group, and the consequence is usually discovered in an audit months later.
Authorized information required
The action context visible in the management console plus authoritative security state read from connected APIs.
The intelligence layer ArtOfTheHack adds
The proposed change is compared against the current state to establish the exposure it would create, its reversibility and whether the user holds the authority to make it.
The decision value you receive
An inline verdict on a configuration change, with the safer configuration and the rollback requirement stated.
What remains under your control
The cloud platform remains the point of enforcement, and where an API cannot evidence the state the limitation is stated rather than inferred.
Workflow
The six-stage governed sequence
Nothing in this sequence is skipped. Evidence precedes inference, authority precedes action, and verification precedes assurance.
Stage 01
Detect
An authorized user views or changes an important cloud configuration on an approved management console.
Output feeds stage 02: Gather
Stage 02
Gather
The visible interface supplies the action context; connected systems supply the authoritative security state through APIs.
Output feeds stage 03: Cross-check
Stage 03
Cross-check
Public storage permissions, broad identity policies, open security-group rules and external access settings are compared against the current state.
Output feeds stage 04: Evaluate
Stage 04
Evaluate
Unnecessary administrator access, risky authentication changes and misconfigured sharing controls are weighed for consequence and reversibility.
Output feeds stage 05: Recommend
Stage 05
Recommend
A verdict is returned inline, with approval required where the change exceeds the user's authority.
Output feeds stage 06: Record
Stage 06
Record
The configuration decision, its evidence and its outcome are preserved in the Decision Ledger.
Closes the sequence and returns evidence to the decision record
Hard boundary
Edge combines the action a user is taking with authoritative API evidence when available. Where a connected system cannot evidence the configuration, the limitation is stated rather than inferred.
Evidence in
What the workflow reads
- Public storage permissions
- Excessively broad identity policies
- Open security-group rules
- Unnecessary administrator access
- External access settings
- Risky authentication changes
- Misconfigured sharing controls
Decision out
What the workflow returns
- Exposure created by the proposed change
- Inline verdict with required authority
- Recommended safer configuration
- Rollback requirement
- Escalation where evidence is insufficient
Authority and action
Who decides, who acts, how it is verified
- Service posture
- Advisory with approval-gated action
- Acting API
- The cloud or Workspace configuration API of the platform being changed.
- Approving authority
- The resource owner, with additional review where the change affects critical services.
- Verification
- Configuration is re-read after the change and absence of service disruption is confirmed.
- Rollback and reversal
- The prior configuration is captured before the change so the resource can be returned to its previous state.
Connection
What must be authorized
- Approved cloud management surface
- Cloud or Workspace configuration API for authoritative state
- Delivery
- Authorized API integration, webhooks, or structured evidence submissions. No endpoint agent, no appliance, no product replacement.
- System of record
- The connected source platform remains the system of record and the point of enforcement. ArtOfTheHack proposes; the source system acts.
- Cost to the grantee
- KRYOS-XS is provided at no cost to eligible nonprofits under a grant funded by James Scott and administered by the Embassy Row Project.
- Read-only advisory operation by default
- Human approval for high-impact actions
- Least-privilege, revocable permissions
- Explicit blind spots instead of assumed facts
- Reversible enforcement wherever technically available
Product
Where this capability sits
Product 01
KRYOS-XS Edge
A browser-based security decision assistant that helps users evaluate suspicious messages, external data sharing, OAuth approvals and other consequential actions at the moment they occur.
Adjacent capabilities
Other capabilities in this product
Suspicious Message Adjudication
Determine whether a message appears legitimate, unwanted or malicious, and present the recommendation beside the message.
External Sharing and Data-Movement Governance
Evaluate a sharing decision before sensitive information leaves the organization, and offer a safer method.
