Skip to content

Free for nonprofits, NGOs, think tanks, and institutes. Grant funded by James Scott, administered by the Embassy Row Project.

ArtOfTheHack home

KRYOS-XS Console / Service 08

External-Party Access Governance

Decide which external access should be retained, restricted, reviewed or revoked.

What this service does

The problem, the evidence, and what stays with you

The problem addressed

Vendors, consultants, coalition partners, volunteers and former employees keep access that was granted for a project nobody remembers.

Authorized information required

Access records for external parties, their sponsor and purpose, current engagement status and the data each can reach.

The intelligence layer ArtOfTheHack adds

Each external identity is matched to an accountable sponsor and tested against current engagement status and the risk of persistent access.

The decision value you receive

A governed register of external access with a retain, restrict, review or revoke position for every entry.

What remains under your control

The sponsor and system authority decide, and dependency impact is checked after the approved change.

Workflow

The six-stage governed sequence

Nothing in this sequence is skipped. Evidence precedes inference, authority precedes action, and verification precedes assurance.

  1. Stage 01

    Enumerate

    Access granted to vendors, consultants, coalition members and partner organizations is collected.

    Output feeds stage 02: Attribute

  2. Stage 02

    Attribute

    Volunteers, former employees and temporary personnel are matched to a sponsor and purpose.

    Output feeds stage 03: Cross-check

  3. Stage 03

    Cross-check

    Current employment or engagement status is compared against the access still held.

    Output feeds stage 04: Evaluate

  4. Stage 04

    Evaluate

    The data each external party can reach and the risk of persistence are assessed.

    Output feeds stage 05: Decide

  5. Stage 05

    Decide

    Retain, restrict, review or revoke is routed to the sponsor and system authority.

    Output feeds stage 06: Verify

  6. Stage 06

    Verify

    The change is confirmed and continued service or dependency impact is checked.

    Closes the sequence and returns evidence to the decision record

Hard boundary

External access on systems that expose no API is out of scope and is reported as a gap rather than assumed to be absent.

Evidence in

What the workflow reads

  • Vendors
  • Consultants
  • Coalition members
  • Partner organizations
  • Volunteers
  • Former employees
  • Temporary personnel

Decision out

What the workflow returns

  • Retain
  • Restrict
  • Review
  • Revoke
  • Named sponsor and required approver

Authority and action

Who decides, who acts, how it is verified

Service posture
Advisory with approval-gated action
Acting API
Workspace directory and sharing APIs, and connected SaaS or identity APIs.
Approving authority
The identity sponsor together with the system authority.
Verification
Service health and dependency impact are confirmed after the scope change.
Rollback and reversal
The prior scope is retained so a dependency break can be undone.

Connection

What must be authorized

  • Workspace external sharing and directory evidence
  • Connected SaaS or identity APIs where available
Delivery
Authorized API integration, webhooks, or structured evidence submissions. No endpoint agent, no appliance, no product replacement.
System of record
The connected source platform remains the system of record and the point of enforcement. ArtOfTheHack proposes; the source system acts.
Cost to the grantee
KRYOS-XS is provided at no cost to eligible nonprofits under a grant funded by James Scott and administered by the Embassy Row Project.
  • Read-only advisory operation by default
  • Human approval for high-impact actions
  • Least-privilege, revocable permissions
  • Explicit blind spots instead of assumed facts
  • Reversible enforcement wherever technically available