IT & Security

Give agents access, and keep the proof of every touch

Security teams distrust AI agents because most can't prove what they touched. Kentron runs each job in isolation, stops at a policy gate before every write, and records each call in an immutable, hash-chained receipt. The audit artifact is a by-product of the work, not a project after it.

What this replaces

Screenshot-based evidence collection two weeks before the audit.

Rachel Adler4:50 PM

@Receipt J. Okoye finished today. Show me everything they still have access to.

ReceiptApp4:52 PM

14 systems. Nine are SSO-governed and revoke when the account is suspended. Five are not: a GitHub token, an AWS access key used two days ago, Datadog, Figma, and a shared Notion. Revocation is queued for your approval.

Receiptrcp_9e27

Three jobs IT & Security stops doing by hand

Each one is a single run across the systems you already use, with a policy gate before anything changes and a receipt for every call.

  1. 01

    Find the access SSO doesn't cover

    You ask

    @Receipt this person is leaving. What do they have that suspending SSO won't kill?

    • Okta
    • Google Workspace
    • GitHub
    • AWS
    • 1Password

    What Kentron does

    1. Lists identity-provider groups and app assignments
    2. Goes past SSO to personal access tokens, API keys, and standing cloud credentials
    3. Sorts by last use and privilege, so the risky ones come first
    4. Revokes on approval, then reads each one back to confirm it is gone

    What it leaves behind

    The receipt holds the revoke call and the read that confirmed it. That is evidence the access is gone, not just that a request was sent.

  2. 02

    Run the quarterly access review as a run, not a project

    You ask

    @Receipt who has production database access, and did anyone approve it?

    • Okta
    • AWS
    • Jira
    • Vanta

    What Kentron does

    1. Pulls current entitlements from every governed system in scope
    2. Reconciles each one against the approval ticket that granted it
    3. Flags standing access with no approval, no recent use, or no current manager
    4. Exports the reviewed evidence pack in the format your auditor expects

    What it leaves behind

    The whole review is one replayable chain. Next quarter you re-run it and diff, instead of starting a new spreadsheet.

  3. 03

    Triage the vulnerability queue by real exposure

    You ask

    @Receipt of this week's CVEs, which ones reach our production surface?

    • GitHub
    • AWS
    • Datadog
    • Jira

    What Kentron does

    1. Maps each advisory to the services that actually import the package
    2. Checks whether the vulnerable path is reachable from an internet-facing route
    3. Ranks by real exposure instead of CVSS alone
    4. Opens tickets only for the ones that matter, with the upgrade path attached

    What it leaves behind

    The reasoning for every deprioritised CVE is kept, which is exactly what an auditor asks about six months later.

For IT & Security, the receipt is the evidence

Every privileged call is recorded before it counts: what was read, what was changed, who approved it, and a hash that proves the record hasn't been edited since.

  • Each run gets its own sandbox, so no access is ambient
  • Every write waits at a policy gate for a named approver
  • Evidence arrives with its source, timestamp, and hash attached

Receipt

Offboarding, contractor access

rcp_9e27
  1. Read: Okta

    6f2b…d914

    Read J. Okoye's groups and app assignments

  2. Read: GitHub

    a8d3…10ec

    Read personal access tokens and their scopes

  3. Read: AWS

    35c9…f7a6

    Read access keys and last-used dates

  4. Held for approval: Policy gate

    de07…4b58

    Revocation of five non-SSO credentials held for approval

  5. Wrote: Slack

    20e4…8c19

    Sent the access list to Rachel for review

5 calls, chain verified

The tools IT & Security usually connects

Any tool you use can be connected. These are where this team tends to start.

  • Okta
  • Google Workspace
  • GitHub
  • AWS
  • Jira
  • Vanta
  • 1Password
  • Datadog

Put Kentron on the IT & Security backlog

Connect one system, then read the receipts it writes before you connect the next.

Book Demo