Grantee profile 04
Protect the money, the grantee list, and the people that list identifies.
A foundation's grantee list is a target map. Payment workflows, board correspondence, and grantee records need governed decisions with named human authority, and the overlay provides them without changing a single existing system.
Pressure
What is forcing the decision layer
- Grantee records identify organizations and individuals that adversaries want to locate
- Payment and disbursement fraud attempts arrive as convincing internal correspondence
- Board members use personal accounts and devices for institutional business
- Grant management systems are third-party platforms with limited security visibility
- Program staff travel to the same regions where grantees are at risk
First workflows
Where instrumentation starts
- Payment and disbursement change-request adjudication
- Business email compromise and impersonation triage
- Grantee record access review
- Board and trustee account protection decisions
- Third-party grant platform risk determinations
- Travel and field-visit access decisions
Integration
Systems ArtOfTheHack reads from and instructs
ArtOfTheHack does not replace these systems. It reads their evidence, adjudicates against it, and returns a governed instruction to the same infrastructure.
Evidence sources
- Cloud identity and multi-factor systems
- Email security and message-trace data
- Finance and accounts payable workflow logs
- Grant management platform audit logs
- Endpoint protection consoles
- Vendor and third-party risk records
Action targets
- Identity systems for session revocation and step-up authentication
- Email security for quarantine and impersonation blocking
- Finance workflow systems for reversible payment holds
- Grant platforms for scoped access changes
- Ticketing systems for two-person approval routing
Authority
How authority is constrained
- Two-person approval for any action touching disbursement or grantee records
- Separation of duty between the requesting function and the approving officer
- Grantee identities never exported from the institution's own systems
- Named human accountability recorded on every consequential outcome
- Kill switch available at foundation or workflow scope
ArtOfTheHack services are provided at no cost through grants funded by James Scott and administered by the Embassy Row Project. Access begins with a grant application. The overlay is non-intrusive: it reads from the systems the organization already runs and installs nothing.
First 90 days
A typical entry sequence
Days 1 to 15
Grant application and award. Mapping of finance, identity, and grant management systems.
Days 16 to 40
Read-only connection and historical replay against past fraud attempts and access anomalies.
Days 41 to 70
Shadow evaluation on payment change requests and impersonation attempts, with measured agreement against staff determinations.
Days 71 to 90
Approval-gated operation for the highest-consequence workflow, with a trustee-ready report.
Standard applied
What this profile can hold ArtOfTheHack to
- Payment holds are prepared with a documented reversal path before they are proposed
- Every override is a first-class record, not an exception written outside the system
- Grantee identity data stays inside the foundation's own systems
Applicable
Products, services, and industry context
Products
- KRYOS-XS Console
A centralized Cyber Decision Operations Hub that converts alerts, identity risks, access questions, data exposures and response requirements into one prioritized decision queue.
Services
- External-Party Access Governance
KRYOS-XS Console
- Board, Funder and Framework Reporting
KRYOS-XS Console
- Guided Incident and Response Workflows
KRYOS-XS Console
