KRYOS-XS Console / Service 08
External-Party Access Governance
Decide which external access should be retained, restricted, reviewed or revoked.
What this service does
The problem, the evidence, and what stays with you
The problem addressed
Vendors, consultants, coalition partners, volunteers and former employees keep access that was granted for a project nobody remembers.
Authorized information required
Access records for external parties, their sponsor and purpose, current engagement status and the data each can reach.
The intelligence layer ArtOfTheHack adds
Each external identity is matched to an accountable sponsor and tested against current engagement status and the risk of persistent access.
The decision value you receive
A governed register of external access with a retain, restrict, review or revoke position for every entry.
What remains under your control
The sponsor and system authority decide, and dependency impact is checked after the approved change.
Workflow
The six-stage governed sequence
Nothing in this sequence is skipped. Evidence precedes inference, authority precedes action, and verification precedes assurance.
Stage 01
Enumerate
Access granted to vendors, consultants, coalition members and partner organizations is collected.
Output feeds stage 02: Attribute
Stage 02
Attribute
Volunteers, former employees and temporary personnel are matched to a sponsor and purpose.
Output feeds stage 03: Cross-check
Stage 03
Cross-check
Current employment or engagement status is compared against the access still held.
Output feeds stage 04: Evaluate
Stage 04
Evaluate
The data each external party can reach and the risk of persistence are assessed.
Output feeds stage 05: Decide
Stage 05
Decide
Retain, restrict, review or revoke is routed to the sponsor and system authority.
Output feeds stage 06: Verify
Stage 06
Verify
The change is confirmed and continued service or dependency impact is checked.
Closes the sequence and returns evidence to the decision record
Hard boundary
External access on systems that expose no API is out of scope and is reported as a gap rather than assumed to be absent.
Evidence in
What the workflow reads
- Vendors
- Consultants
- Coalition members
- Partner organizations
- Volunteers
- Former employees
- Temporary personnel
Decision out
What the workflow returns
- Retain
- Restrict
- Review
- Revoke
- Named sponsor and required approver
Authority and action
Who decides, who acts, how it is verified
- Service posture
- Advisory with approval-gated action
- Acting API
- Workspace directory and sharing APIs, and connected SaaS or identity APIs.
- Approving authority
- The identity sponsor together with the system authority.
- Verification
- Service health and dependency impact are confirmed after the scope change.
- Rollback and reversal
- The prior scope is retained so a dependency break can be undone.
Connection
What must be authorized
- Workspace external sharing and directory evidence
- Connected SaaS or identity APIs where available
- Delivery
- Authorized API integration, webhooks, or structured evidence submissions. No endpoint agent, no appliance, no product replacement.
- System of record
- The connected source platform remains the system of record and the point of enforcement. ArtOfTheHack proposes; the source system acts.
- Cost to the grantee
- KRYOS-XS is provided at no cost to eligible nonprofits under a grant funded by James Scott and administered by the Embassy Row Project.
- Read-only advisory operation by default
- Human approval for high-impact actions
- Least-privilege, revocable permissions
- Explicit blind spots instead of assumed facts
- Reversible enforcement wherever technically available
Product
Where this capability sits
Product 02
KRYOS-XS Console
A centralized Cyber Decision Operations Hub that converts alerts, identity risks, access questions, data exposures and response requirements into one prioritized decision queue.
Adjacent capabilities
Other capabilities in this product
Alert Triage and Incident Adjudication
Consolidate security alerts into a prioritized decision queue and connect related events so the broader situation is evaluated.
Account-Compromise Assessment
Distinguish legitimate unusual behavior from potential account compromise using available identity evidence.
Access and Entitlement Review
Identify unnecessary, outdated or unusually powerful access and recommend what should change.
Privileged-Access Governance
Understand who holds administrative authority, why it exists, whether it remains necessary and what compromise would cost.
OAuth and Automation Authority Governance
Evaluate applications, integrations and automated agents requesting organizational access, before and after the grant.
Guided Incident and Response Workflows
Guide teams through structured response without depending on anyone remembering every step during a crisis.
Board, Funder and Framework Reporting
Turn the accumulated Decision Ledger into clear institutional reporting generated from real decision history.
