Insider Threat Matrix™Insider Threat Matrix™
HumanSynthetic
  • Sponsors
  • About Us
  • Contributors
  • Sponsors
  • About Us
  • Contributors
HumanSynthetic

Waiting/typing...

Detections
Preventions
Github

Configuration

Access Through Human Identity

  • Authenticated User Session Access
  • Delegated Mailbox and Calendar Access
  • Delegated User Account Access
  • Developer Account Tool Access
  • Local User Credential Access
  • Privileged User Access

Access Through Non-Human Identity

  • Excessive Agency
  • Hard-Coded Agent Secret
  • Long-Lived Agent Credential
  • Orphaned Agent Identity
  • Over-Scoped Agent Access
  • Shared Agent Identity
  • Uninventoried Agent Identity

Autonomous Action Control

Connected Tools and Functions

  • Changed Tool Definition
  • Impersonating Tool Package
  • Over-Permissive Tool Runtime
  • Poisoned Tool Description
  • Unapproved Connected Tool
  • Unattributed Tool Call
  • Unrestricted Tool Egress

Enterprise Retrieval Access

External Communication Access

  • Sandbox Egress Exposure

Model and Build Provenance

Model Objective Alignment

Orchestrated AI System

  • Cross-Boundary Agent Collaboration
  • Inter-Agent Context Propagation
  • Orchestrator and Worker Agents
  • Shared Agent Memory

Persistent Memory Access

Standing Instruction Stack

Vendor-Embedded AI

  • SaaS-Embedded Vendor Assistant
  • Shared-Tenant AI Service
  • Third-Party Tool Agent Platform
  • Synthetic Insider Threat Matrix™
  • -SAR2
  • ID: SAR2
  • Created: 26th August 2026
  • Updated: 26th August 2026

Configuration

The access and settings that define what a synthetic subject can do.

Sections (12)

  • About us
  • Contributors
  • Sponsors
  • Privacy Policy
  • Terms of use
  • Manage Cookies

The Insider Threat Matrix™ is an open framework for computer-enabled insider threat investigations.


© 2026 Forscie Limited. All rights reserved. Insider Threat Matrix™ is a trademark of Forscie Limited.

  • GitHub
  • X
  • Reddit
  • LinkedIn