Skip to content
Black Atlas — Powered by KRYOS V6

Domain 3 · Identity and Privilege Intelligence

Privilege Escalation Path Discovery


Map effective privilege across human, machine, service and agent identities, and find where delegation bridges trust domains.

Classification

NATIVE

Maturity

OPERATIONAL, REQUIRES QUALIFIED HUMAN REVIEW

Authorization

Level 0 to Level 2

Decision it answers

Which single identity creates the largest privilege amplification?

Inputs it needs

  • Identity provider configuration and group structure
  • Role, policy and delegation records
  • Service accounts, machine identities and agent identities
  • Contractor and temporary access records

Methods applied

  • Effective-privilege computation rather than assigned-role reading
  • Escalation-chain discovery across domains
  • Trust-exposure thresholds per identity
  • Least-privilege counterfactuals with operational cost stated

Outputs produced

  • Escalation chains with preconditions
  • Privilege concentration findings
  • Cross-domain trust bridges
  • Least-privilege proposals and their operational impact

Must remain human-owned

Authorization, acceptance of residual risk, containment decisions, disclosure and notification, and any communication to a board or regulator. No analytical capability creates operational authority.