Platform component
ShieldCRS
Detection of insider activity: who touched which file, when, and whether that pattern is consistent with the work they do.
Where workforce visibility is separately justified and disclosed, this page describes a related monitoring use case; it should not be treated as proof of intent.
For an independent reference point, see Cloud Security Alliance Cloud Controls Matrix.
What it is
Who touched which file, and whether that is normal
Detection built on file-level activity: the access, the copy, the rename, the volume, and the pattern against what that person's role usually looks like.
What it will not do
Two things we will not build and will not advise on
Covert monitoring. Watching people without telling them is unlawful in many jurisdictions, it destroys the trust an organisation runs on when discovered, and it is discovered. We do not supply it.
Judgement about intent. A tool can establish that a file was copied at an unusual hour. It cannot establish why, and a system presented as identifying malicious insiders is overstating what any detection can do.
What it produces is a signal for a person to look at, and the entry on false positives is about what happens when that person is given too many.
Elsewhere
The other components
ACE
Alchemi Compliance Enclave
A governed environment for controlled unclassified information, built on infrastructure that inherits a documented set of controls rather than reimplementing them.
AXE
Alchemi Execution Environment
Control over what runs, where, and against which files, applied at the machine on the shop floor rather than at the network edge.