Skip to content

Free for nonprofits, NGOs, think tanks, and institutes. Grant funded by James Scott, administered by the Embassy Row Project.

ArtOfTheHack home

KRYOS-XS Console / Service 07

Privileged-Access Governance

Understand who holds administrative authority, why it exists, whether it remains necessary and what compromise would cost.

What this service does

The problem, the evidence, and what stays with you

The problem addressed

A small number of accounts can change the organization's entire security state, and standing administrative rights usually outlive the project that justified them.

Authorized information required

Administrator roles and assignments, authentication strength, recent administrative activity, ownership and reachable systems and data.

The intelligence layer ArtOfTheHack adds

Necessity is judged against blast radius: what the account can reach, what compromise would cost and whether the authority is still being used.

The decision value you receive

A least-privilege disposition for each privileged account, with the operational consequence of removal understood before the change.

What remains under your control

The system owner and security authority approve, and emergency continuity is verified before anything is reduced.

Workflow

The six-stage governed sequence

Nothing in this sequence is skipped. Evidence precedes inference, authority precedes action, and verification precedes assurance.

  1. Stage 01

    Identify

    Accounts holding administrative authority are enumerated from connected systems.

    Output feeds stage 02: Justify

  2. Stage 02

    Justify

    The reason the authority exists is established and attached to a named owner.

    Output feeds stage 03: Test

  3. Stage 03

    Test

    Whether the authority remains necessary is checked against recent administrative activity.

    Output feeds stage 04: Model

  4. Stage 04

    Model

    The consequence of compromise for each privileged account is estimated.

    Output feeds stage 05: Approve

  5. Stage 05

    Approve

    The system owner and security authority approve any reduction or removal.

    Output feeds stage 06: Verify

  6. Stage 06

    Verify

    Privilege state and emergency continuity are confirmed after the change.

    Closes the sequence and returns evidence to the decision record

Hard boundary

Privileged accounts absent from connected administrative APIs cannot be assessed. KRYOS does not replace an IAM or PAM platform.

Evidence in

What the workflow reads

  • Administrator roles and assignments
  • Authentication strength
  • Recent administrative activity
  • Account ownership
  • Reachable systems and data

Decision out

What the workflow returns

  • Necessity determination
  • Blast radius if compromised
  • Least-privilege recommendation
  • Required approver
  • Rollback and emergency continuity

Authority and action

Who decides, who acts, how it is verified

Service posture
Advisory with approval-gated action
Acting API
Workspace admin role APIs, and IAM, PAM or PIM APIs where connected.
Approving authority
The system owner with the security authority; emergency-account changes require dual approval.
Verification
Privilege removal, emergency continuity and audit evidence are confirmed after enforcement.
Rollback and reversal
Break-glass continuity is validated before any change, so privileged access can be restored under emergency procedure.

Connection

What must be authorized

  • Workspace admin role evidence
  • IAM, PAM or PIM APIs where connected
Delivery
Authorized API integration, webhooks, or structured evidence submissions. No endpoint agent, no appliance, no product replacement.
System of record
The connected source platform remains the system of record and the point of enforcement. ArtOfTheHack proposes; the source system acts.
Cost to the grantee
KRYOS-XS is provided at no cost to eligible nonprofits under a grant funded by James Scott and administered by the Embassy Row Project.
  • Read-only advisory operation by default
  • Human approval for high-impact actions
  • Least-privilege, revocable permissions
  • Explicit blind spots instead of assumed facts
  • Reversible enforcement wherever technically available