KRYOS-XS Console / Service 07
Privileged-Access Governance
Understand who holds administrative authority, why it exists, whether it remains necessary and what compromise would cost.
What this service does
The problem, the evidence, and what stays with you
The problem addressed
A small number of accounts can change the organization's entire security state, and standing administrative rights usually outlive the project that justified them.
Authorized information required
Administrator roles and assignments, authentication strength, recent administrative activity, ownership and reachable systems and data.
The intelligence layer ArtOfTheHack adds
Necessity is judged against blast radius: what the account can reach, what compromise would cost and whether the authority is still being used.
The decision value you receive
A least-privilege disposition for each privileged account, with the operational consequence of removal understood before the change.
What remains under your control
The system owner and security authority approve, and emergency continuity is verified before anything is reduced.
Workflow
The six-stage governed sequence
Nothing in this sequence is skipped. Evidence precedes inference, authority precedes action, and verification precedes assurance.
Stage 01
Identify
Accounts holding administrative authority are enumerated from connected systems.
Output feeds stage 02: Justify
Stage 02
Justify
The reason the authority exists is established and attached to a named owner.
Output feeds stage 03: Test
Stage 03
Test
Whether the authority remains necessary is checked against recent administrative activity.
Output feeds stage 04: Model
Stage 04
Model
The consequence of compromise for each privileged account is estimated.
Output feeds stage 05: Approve
Stage 05
Approve
The system owner and security authority approve any reduction or removal.
Output feeds stage 06: Verify
Stage 06
Verify
Privilege state and emergency continuity are confirmed after the change.
Closes the sequence and returns evidence to the decision record
Hard boundary
Privileged accounts absent from connected administrative APIs cannot be assessed. KRYOS does not replace an IAM or PAM platform.
Evidence in
What the workflow reads
- Administrator roles and assignments
- Authentication strength
- Recent administrative activity
- Account ownership
- Reachable systems and data
Decision out
What the workflow returns
- Necessity determination
- Blast radius if compromised
- Least-privilege recommendation
- Required approver
- Rollback and emergency continuity
Authority and action
Who decides, who acts, how it is verified
- Service posture
- Advisory with approval-gated action
- Acting API
- Workspace admin role APIs, and IAM, PAM or PIM APIs where connected.
- Approving authority
- The system owner with the security authority; emergency-account changes require dual approval.
- Verification
- Privilege removal, emergency continuity and audit evidence are confirmed after enforcement.
- Rollback and reversal
- Break-glass continuity is validated before any change, so privileged access can be restored under emergency procedure.
Connection
What must be authorized
- Workspace admin role evidence
- IAM, PAM or PIM APIs where connected
- Delivery
- Authorized API integration, webhooks, or structured evidence submissions. No endpoint agent, no appliance, no product replacement.
- System of record
- The connected source platform remains the system of record and the point of enforcement. ArtOfTheHack proposes; the source system acts.
- Cost to the grantee
- KRYOS-XS is provided at no cost to eligible nonprofits under a grant funded by James Scott and administered by the Embassy Row Project.
- Read-only advisory operation by default
- Human approval for high-impact actions
- Least-privilege, revocable permissions
- Explicit blind spots instead of assumed facts
- Reversible enforcement wherever technically available
Product
Where this capability sits
Product 02
KRYOS-XS Console
A centralized Cyber Decision Operations Hub that converts alerts, identity risks, access questions, data exposures and response requirements into one prioritized decision queue.
Adjacent capabilities
Other capabilities in this product
Alert Triage and Incident Adjudication
Consolidate security alerts into a prioritized decision queue and connect related events so the broader situation is evaluated.
Account-Compromise Assessment
Distinguish legitimate unusual behavior from potential account compromise using available identity evidence.
Access and Entitlement Review
Identify unnecessary, outdated or unusually powerful access and recommend what should change.
External-Party Access Governance
Decide which external access should be retained, restricted, reviewed or revoked.
OAuth and Automation Authority Governance
Evaluate applications, integrations and automated agents requesting organizational access, before and after the grant.
Guided Incident and Response Workflows
Guide teams through structured response without depending on anyone remembering every step during a crisis.
Board, Funder and Framework Reporting
Turn the accumulated Decision Ledger into clear institutional reporting generated from real decision history.
