KRYOS-XS Console / Service 06
Access and Entitlement Review
Identify unnecessary, outdated or unusually powerful access and recommend what should change.
What this service does
The problem, the evidence, and what stays with you
The problem addressed
Access accumulates through groups, roles, shared drives and departed staff until nobody can say what a single account can actually reach.
Authorized information required
Group memberships, organizational roles, administrator privileges, third-party and partner access and dormant entitlements.
The intelligence layer ArtOfTheHack adds
Inherited and nested access is traced to the effective entitlement, then compared with current responsibilities and last use.
The decision value you receive
Retain, reduce, time-bound, transfer or revoke recommendations carrying the evidence of need and the impact of removal.
What remains under your control
The named manager or data owner certifies every decision, and effective access is re-read after the approved change.
Workflow
The six-stage governed sequence
Nothing in this sequence is skipped. Evidence precedes inference, authority precedes action, and verification precedes assurance.
Stage 01
Inventory
Group memberships, organizational roles and administrator privileges are collected.
Output feeds stage 02: Trace
Stage 02
Trace
Third-party and partner access is resolved to the effective entitlement it grants.
Output feeds stage 03: Compare
Stage 03
Compare
Dormant entitlements and access inconsistent with current responsibilities are identified.
Output feeds stage 04: Evaluate
Stage 04
Evaluate
Potential impact of retaining or removing each entitlement is estimated.
Output feeds stage 05: Certify
Stage 05
Certify
The named manager or data owner reviews and approves each recommendation.
Output feeds stage 06: Verify
Stage 06
Verify
Effective access is re-read after the approved change and the review recorded.
Closes the sequence and returns evidence to the decision record
Hard boundary
Only access exposed by a connected system can be reviewed. Access held on platforms without a supported API is stated as a coverage gap.
Evidence in
What the workflow reads
- Group memberships
- Organizational roles
- Administrator privileges
- Third-party access
- Partner access
- Dormant entitlements
- Access inconsistent with current responsibilities
Decision out
What the workflow returns
- Retain, reduce, time-bound, transfer or revoke
- Evidence of need
- Potential impact
- Required approver
- Verified outcome
Authority and action
Who decides, who acts, how it is verified
- Service posture
- Advisory with approval-gated action
- Acting API
- Directory, Workspace group and connected SaaS entitlement APIs.
- Approving authority
- The named manager, data owner or application owner who certifies the review.
- Verification
- Effective access is re-read after the change and the review is scheduled to recur.
- Rollback and reversal
- The prior entitlement state and the reviewer rationale are retained, so a removal can be reinstated.
Connection
What must be authorized
- Google Workspace directory and group evidence
- Identity provider or SaaS entitlement APIs where connected
- Delivery
- Authorized API integration, webhooks, or structured evidence submissions. No endpoint agent, no appliance, no product replacement.
- System of record
- The connected source platform remains the system of record and the point of enforcement. ArtOfTheHack proposes; the source system acts.
- Cost to the grantee
- KRYOS-XS is provided at no cost to eligible nonprofits under a grant funded by James Scott and administered by the Embassy Row Project.
- Read-only advisory operation by default
- Human approval for high-impact actions
- Least-privilege, revocable permissions
- Explicit blind spots instead of assumed facts
- Reversible enforcement wherever technically available
Product
Where this capability sits
Product 02
KRYOS-XS Console
A centralized Cyber Decision Operations Hub that converts alerts, identity risks, access questions, data exposures and response requirements into one prioritized decision queue.
Adjacent capabilities
Other capabilities in this product
Alert Triage and Incident Adjudication
Consolidate security alerts into a prioritized decision queue and connect related events so the broader situation is evaluated.
Account-Compromise Assessment
Distinguish legitimate unusual behavior from potential account compromise using available identity evidence.
Privileged-Access Governance
Understand who holds administrative authority, why it exists, whether it remains necessary and what compromise would cost.
External-Party Access Governance
Decide which external access should be retained, restricted, reviewed or revoked.
OAuth and Automation Authority Governance
Evaluate applications, integrations and automated agents requesting organizational access, before and after the grant.
Guided Incident and Response Workflows
Guide teams through structured response without depending on anyone remembering every step during a crisis.
Board, Funder and Framework Reporting
Turn the accumulated Decision Ledger into clear institutional reporting generated from real decision history.
