Typed telemetry
Accept registered identity event and source enums with timestamp, network, device, approval, and directory bindings.
2AYE ingests a closed set of tenant-bound identity events, detects repeated sign-in failure, MFA denial bursts, and unapproved privilege assignment deterministically, opens versioned evidence-linked cases, and executes bounded step-up, session revocation, or directory suspension responses.
Accept registered identity event and source enums with timestamp, network, device, approval, and directory bindings.
Preserve the rule identifier and every contributing event identifier.
Record step-up, revoke active sessions, or suspend the exact linked directory identity.
Audit ingestion, detection, analyst state changes, and response execution.
Each consequential action moves through the same six control points. See where 2AYE evaluates authority, requests human review, and preserves the outcome.
Document the environment, threat model, and integration boundary.
Select protocols, signals, policies, and failure behavior.
Test vendor-specific APIs, tenant isolation, and abuse paths.
Mark available only after deployed end-to-end verification.