Skip to content

Free for nonprofits, NGOs, think tanks, and institutes. Grant funded by James Scott, administered by the Embassy Row Project.

ArtOfTheHack home

Product 02 / 8 services

KRYOS-XS Console

A centralized Cyber Decision Operations Hub that converts alerts, identity risks, access questions, data exposures and response requirements into one prioritized decision queue.

KRYOS-XS protects decisions, not just systems. It detects consequential actions, determines what the evidence justifies, identifies who has authority, recommends the safest response and preserves proof of what the organization decided and why.

Across the organization

8 services

  • Unified Decision Queue

    Alerts, identity risks, access requests, data exposures and response tasks arrive in one ordered list, ranked by consequence and deadline rather than by the tool that raised them.

  • Evidence-backed Decision Workspace

    Each item opens into a workspace that shows the supporting evidence and its source, the confidence in that evidence, what is missing, the applicable policy and the recommended action.

  • Account-compromise assessment

    Sign-in anomalies, mailbox rule changes, token activity and device signals are assembled into a single judgment about whether an account is compromised and what containment is proportionate.

  • Access and entitlement review

    Standing access is compared against role, activity and policy, so reviewers can see which entitlements are justified and which should be reduced or removed.

  • Privileged-access governance

    Administrative rights are tracked with the reason they were granted, the approver who authorized them and the date they are due to be revisited.

Prioritized decisions, governance and decision history

Paired product

The other half of the same decision layer

Edge works at the moment of action. Console works across the organization. Both write to the same KRYOS Decision Ledger and are evaluated by the same Hypercube Decision Engine.

KRYOS-XS Edge

A browser-based security decision assistant that helps users evaluate suspicious messages, external data sharing, OAuth approvals and other consequential actions at the moment they occur.

Explore KRYOS-XS Edge

Positioning

What this product is

A centralized Cyber Decision Operations Hub that connects approved information from existing systems and converts fragmented security signals into one prioritized queue of governed decisions.

The problem it addresses

Traditional dashboards tell a team what happened. They do not say what the evidence means, which issue matters most, what should happen next, who owns the decision, who can approve it, what evidence is missing, or whether the response worked. For an organization without a continuous security operations center, that gap is the whole problem.

Operating model

  • Approved, narrowly scoped integrations, beginning with Google Workspace and expanding as APIs allow.
  • One prioritized decision queue covering alerts, identity risk, access, authority, exposure, response and reporting.
  • Every decision arrives with available evidence and organizational context, never as a blank prompt.
  • Guided workflows carry a team through investigation, containment, authority, approval, execution, verification and rollback.
  • The Decision Ledger accumulates into board, funder and framework reporting and into training drawn from real decisions.

Evidence and authority

The shared model across this product

  • Tenant isolation and least-privilege integrations.
  • Evidence provenance, with confidence and uncertainty stated on every decision.
  • Human authorization and separation of duties for consequential action.
  • Reversible actions and complete audit history.
  • Configurable data retention under organization-controlled policies.

Limitations

What this product does not do

  • Capabilities are available only where the relevant system provides a suitable API.
  • KRYOS does not claim evidence a connected system cannot provide, and identifies the limitation instead.
  • The Console does not detect; it organizes and adjudicates what connected systems report.
  • Escalation replaces unsupported certainty when the evidence is insufficient.
  • The Console does not replace a SIEM, an identity provider, an EDR platform or the organization's own governance.

Capabilities

What KRYOS-XS Console does

Each capability is delivered through authorized connections to systems the organization already runs.

Unified Decision Queue

Alerts, identity risks, access requests, data exposures and response tasks arrive in one ordered list, ranked by consequence and deadline rather than by the tool that raised them.

Evidence-backed Decision Workspace

Each item opens into a workspace that shows the supporting evidence and its source, the confidence in that evidence, what is missing, the applicable policy and the recommended action.

Account-compromise assessment

Sign-in anomalies, mailbox rule changes, token activity and device signals are assembled into a single judgment about whether an account is compromised and what containment is proportionate.

Access and entitlement review

Standing access is compared against role, activity and policy, so reviewers can see which entitlements are justified and which should be reduced or removed.

Privileged-access governance

Administrative rights are tracked with the reason they were granted, the approver who authorized them and the date they are due to be revisited.

External-party access governance

Contractors, partners, consultants and volunteers are reviewed on the same evidence basis as staff, including what they can reach and when their access should end.

OAuth and automation authority

Connected applications, service accounts and automations are inventoried with their scopes, so the organization can see what non-human identities are permitted to do.

Guided incident-response workflows

Response follows an ordered sequence with the required authority named at each step, and the outcome of each step recorded as it completes.

Board and funder reporting

Reports are generated from the real decision history in the KRYOS Decision Ledger rather than reconstructed at the end of a reporting period.

Framework and control evidence

Decisions are mapped to the control frameworks the organization is accountable to, so evidence requests can be answered from records that already exist.

Decision-based security training

Training is drawn from the decisions the organization actually faced, so staff practise the judgments their roles require.

Expandable integrations

Deployment begins with Google Workspace and extends to identity providers, endpoint and detection tooling, and cloud estate evidence as the organization authorizes each connection.

Governance and safeguards

Consequential actions require a named human approver, connected systems remain the point of enforcement, and every decision keeps its evidence, authority and outcome on the record.

Example decisions

Illustrative decisions, not customer records

These examples show the shape of a governed decision. They are illustrative and do not describe any specific organization.

Illustrative: suspected mailbox compromise

Priority
High
Owner
IT operations lead
Evidence
Sign-in from an unrecognized location, a new mailbox forwarding rule, and a password change within the same hour
Confidence
High on the forwarding rule, moderate on the location signal
Missing information
Whether the staff member was travelling; device posture was not reported
Recommended action
Revoke active sessions, remove the forwarding rule, and confirm the change with the account holder by a second channel
Required approver
Executive director or designated deputy
Deadline
Same business day
Outcome
Sessions revoked, rule removed, account holder confirmed the change was not theirs

Illustrative: external sharing of a sensitive dataset

Priority
Medium
Owner
Programs director
Evidence
A folder containing beneficiary records was shared with a personal email domain by link
Confidence
High on the share event, moderate on the sensitivity classification
Missing information
Whether a data-sharing agreement exists with the recipient
Recommended action
Restrict the link to named recipients and confirm the legal basis before restoring access
Required approver
Programs director with data protection sign-off
Deadline
Two business days
Outcome
Link restricted, agreement confirmed, access restored to two named recipients

Illustrative: third-party application access request

Priority
Low
Owner
Operations manager
Evidence
An unverified application requested read and write access to organizational mail and files
Confidence
High on the requested scopes, low on the publisher's track record
Missing information
No security review or vendor documentation was supplied
Recommended action
Decline the request and re-evaluate if the vendor provides documentation and a narrower scope
Required approver
Operations manager
Deadline
Five business days
Outcome
Request declined and recorded, with the narrower scope noted for reconsideration

Operating model

How every workflow in this product runs

  1. Stage 01

    Authorize

    Approved integration with the minimum scope the capability requires.

  2. Stage 02

    Detect

    A consequential security action or signal is identified for evaluation.

  3. Stage 03

    Gather

    Available evidence is retrieved from the connected systems and its source and age recorded.

  4. Stage 04

    Reason

    The Hypercube Decision Engine cross-checks facts, compares safe and dangerous explanations and applies policy.

  5. Stage 05

    Authorize action

    Required authority is confirmed and a named human approves anything consequential.

  6. Stage 06

    Verify and record

    The outcome is verified and preserved in the KRYOS Decision Ledger.

KRYOS does not claim evidence that a connected system cannot provide. When data is incomplete, the platform identifies the limitation and requests the appropriate human or technical input.