Configuration evidence
Collect registered control observations without arbitrary attribute maps.
2AYE records typed posture observations, evaluates the versioned enterprise identity baseline, assigns findings to owners, enforces expiring exceptions, and refuses remediation unless a newer compliant observation proves the exact control changed.
Collect registered control observations without arbitrary attribute maps.
Evaluate seven named identity controls against VERID_ENTERPRISE_BASELINE version 1.
Require optimistic concurrency, an accountable actor, and expiration within 90 days.
Close only from newer compliant evidence matching the exact tenant, control, and resource.
Each consequential action moves through the same six control points. See where 2AYE evaluates authority, requests human review, and preserves the outcome.
Document the environment, threat model, and integration boundary.
Select protocols, signals, policies, and failure behavior.
Test vendor-specific APIs, tenant isolation, and abuse paths.
Mark available only after deployed end-to-end verification.