Abstract
This use case examines the role of KRYOS-XS during the first hour of a suspected account incident. The principal contribution is disciplined sequencing: evidence is preserved, authority is confirmed and containment is matched to consequence before irreversible action is taken.
Decision problem
Incident response frequently fails through omission, premature action or unclear ownership. Suspending an account may reduce risk but disrupt essential work. Delaying containment may permit further access. The organization must decide what to do first, who can authorize it and what evidence must be retained.
Evidence and Hypercube reasoning
Console assembles approved identity, login, application, file and alert evidence. Hypercube evaluates the likely cost of action and inaction under competing incident hypotheses. Organizational policies define the actions available to each role. Evidence age, completeness and provenance remain attached to the decision.
Governed workflow
Console guides the team through investigation, affected-asset identification, containment analysis, authority confirmation, approval, action, verification and rollback if necessary. Each stage produces a traceable decision record. The process does not assume that the first hypothesis will survive later review.
Evaluation design
The pilot should measure time to containment, evidence preserved, required steps completed, approval latency, inappropriate account suspensions, actions successfully verified and completeness of the final incident record.
Boundary condition
KRYOS-XS provides governed decision support. It should not execute high-impact containment unless bounded automation has been expressly approved.
Reading time 2 minutes. Every decision described here is recorded in the KRYOS Decision Ledger with its evidence, authority and verified outcome.




