01 · Runtime authorization
When a non-human identity — service account, agent, workflow — initiates an action in production, what authorizes that action at the moment of execution?
02 · Runtime intervention
If a machine identity executes an unintended or out-of-policy action, how quickly can you halt it mid-execution?
03 · Auditability
Which best describes your audit trail for machine-initiated actions?
04 · Delegated execution
When an agent or workflow chains multiple actions, how is authority evaluated across the chain?
05 · Policy authority
Who defines the policy governing what a given machine identity is allowed to do at runtime?
06 · Intent enforcement
A valid credential is used in an unexpected way — correct authentication, wrong intent. What catches it?
07 · Forensic readiness
Could you produce, on demand, the full list of actions a specific machine identity took in the last 24 hours — with the authorization context for each?