Platform / Layer 4
Layer 4
Revoking access should be one act, not a hopeful tour of six consoles.
When an account is compromised, the question is not whether you can disable it. It is whether you can be sure that everything which trusted it has stopped — and in most estates that answer is assembled by hand, product by product, while the incident is still running.
The argument
Access is decided in one place and enforced at every machine. The decision and the enforcement are deliberately separate: a central policy says who may do what, and the agent on each machine applies it locally — so enforcement keeps working when the network does not, and revoking something is a single act rather than a hope that six products all honoured it.
The second idea here is that a live session is not a standing permission. Releasing a held containment action requires proving who you are again, at that moment — so a stolen session, however valid, still cannot approve anything that changes your world.
The second idea here is that a live session is not a standing permission. Releasing a held containment action requires proving who you are again, at that moment — so a stolen session, however valid, still cannot approve anything that changes your world.
Ask the access record
authored example, not live data
Reports here answer questions in plain language, and every sentence they return carries the evidence behind it. Pick a question an auditor actually asks.
The honest limits
We can only revoke what we are the authority for
Where another identity provider issues the credential, we can tell you it exists and stop it reaching your machines — we cannot end its session inside a third party's product.
An unmapped machine cannot enforce a decision
Enforcement happens where the agent runs. Somewhere with no agent is not covered by it, and coverage is reported as a count of machines rather than a percentage that flatters us.
A permission we never read is not enforced
If a policy declares something nothing consumes, the platform says so rather than accepting it quietly. Desired state you believe is in force but isn't is worse than a gap you know about.
Some questions have no answer, and get none
Where a field was never recorded, a report says it was never measured rather than returning a zero. A confident number is worth less than a stated gap.
What this layer deliberately does not do
It does not become your identity provider. If you already have one, this layer reads from it rather than asking you to migrate — replacing a working directory is a two-year project nobody asked for in the middle of a security purchase.
It also does not let a permission be granted permanently and quietly. Access to the most sensitive material is requested, approved by a second person, and used — with all three recorded — rather than sitting on an account indefinitely because someone needed it once.
It also does not let a permission be granted permanently and quietly. Access to the most sensitive material is requested, approved by a second person, and used — with all three recorded — rather than sitting on an account indefinitely because someone needed it once.
Words this page introduced
Full glossary →Standing — whether an identity may do a particular thing right now, rather than whether it signed in successfully.
Step-up — proving who you are again at the moment of a consequential act, not at the start of the day.
Second person — someone other than the requester approving. The requester can never be their own approver.
Evidence link — the record behind a sentence in a report. No uncited claim ships.
This layer's capabilities
All 88 →
Authentication and step-up
per seat
Enterprise sign-on and provisioning
flat
Privileged access and sessions
per seat
Non-human identity inventory
included
Policy declaration and assurance
included
Reports and evidence export
per report