KRYOS-XS Console / Service 10
Guided Incident and Response Workflows
Guide teams through structured response without depending on anyone remembering every step during a crisis.
What this service does
The problem, the evidence, and what stays with you
The problem addressed
Complex response should not depend on someone remembering every step during a crisis, and pressure produces containment that stops services to people.
Authorized information required
The incident evidence, affected users and systems, available containment options and the authority model for each action.
The intelligence layer ArtOfTheHack adds
Containment options are compared for consequence and reversibility, the required authority is established and the sequence is ordered before anything is executed.
The decision value you receive
A structured response with authority, rollback and verification attached to every step, and the final outcome preserved.
What remains under your control
Every consequential action requires human authorization and executes in the organization's own systems.
Workflow
The six-stage governed sequence
Nothing in this sequence is skipped. Evidence precedes inference, authority precedes action, and verification precedes assurance.
Stage 01
Investigate
The evidence is reviewed and affected users and systems identified.
Output feeds stage 02: Evaluate
Stage 02
Evaluate
Containment options are compared for consequence and reversibility.
Output feeds stage 03: Confirm authority
Stage 03
Confirm authority
Required authority is established and approval requested.
Output feeds stage 04: Execute
Stage 04
Execute
The selected action is executed or recommended in the organization's own systems.
Output feeds stage 05: Verify
Stage 05
Verify
The result is verified and rolled back if necessary.
Output feeds stage 06: Record
Stage 06
Record
The final outcome and evidence are preserved for reporting and review.
Closes the sequence and returns evidence to the decision record
Hard boundary
Every consequential action requires human authorization, and action is possible only where the existing platform exposes a supported API.
Evidence in
What the workflow reads
- Suspicious account investigation
- Phishing response
- External exposure containment
- Privilege reduction
- Access revocation
- Incident escalation
- Ransomware containment planning
- Recovery sequencing
- Evidence preservation
- Leadership notification
Decision out
What the workflow returns
- Ordered response sequence
- Required authority at each step
- Rollback requirement
- Verified result
- Preserved evidence and final outcome
Authority and action
Who decides, who acts, how it is verified
- Service posture
- Advisory with approval-gated action
- Acting API
- The existing enforcement platform action APIs, identity, cloud, mail or endpoint, where they are connected.
- Approving authority
- A named human authority for each action in the sequence.
- Verification
- The result of every executed action is verified and the incident record updated with the outcome.
- Rollback and reversal
- No action enters the sequence without a rollback requirement recorded alongside it.
Connection
What must be authorized
- Google Workspace admin actions
- Connected identity, cloud, mail or endpoint action APIs where available
- Delivery
- Authorized API integration, webhooks, or structured evidence submissions. No endpoint agent, no appliance, no product replacement.
- System of record
- The connected source platform remains the system of record and the point of enforcement. ArtOfTheHack proposes; the source system acts.
- Cost to the grantee
- KRYOS-XS is provided at no cost to eligible nonprofits under a grant funded by James Scott and administered by the Embassy Row Project.
- Read-only advisory operation by default
- Human approval for high-impact actions
- Least-privilege, revocable permissions
- Explicit blind spots instead of assumed facts
- Reversible enforcement wherever technically available
Product
Where this capability sits
Product 02
KRYOS-XS Console
A centralized Cyber Decision Operations Hub that converts alerts, identity risks, access questions, data exposures and response requirements into one prioritized decision queue.
Adjacent capabilities
Other capabilities in this product
Alert Triage and Incident Adjudication
Consolidate security alerts into a prioritized decision queue and connect related events so the broader situation is evaluated.
Account-Compromise Assessment
Distinguish legitimate unusual behavior from potential account compromise using available identity evidence.
Access and Entitlement Review
Identify unnecessary, outdated or unusually powerful access and recommend what should change.
Privileged-Access Governance
Understand who holds administrative authority, why it exists, whether it remains necessary and what compromise would cost.
External-Party Access Governance
Decide which external access should be retained, restricted, reviewed or revoked.
OAuth and Automation Authority Governance
Evaluate applications, integrations and automated agents requesting organizational access, before and after the grant.
Board, Funder and Framework Reporting
Turn the accumulated Decision Ledger into clear institutional reporting generated from real decision history.
