14-Day Runtime Assessment
Understand your approval gaps before you enforce.
Route selected requests from your agents, pipelines, and services through INTYGA in Discovery Mode. Over 14 days, review the recorded requests and the human-approval requirements they would face under enforcement. The report covers those integrations, not your entire estate.
Observe first, with an explicit integration.
Discovery Mode records eligible authorization requests without waiting for a human signature. Authentication, input validation, rate limits and other security boundaries still apply. INTYGA does not discover arbitrary activity or execute your operations; a recorded request is not proof that the downstream action ran.
This is not a trial that quietly starts enforcing on day 15. Human-approval enforcement stays off for the whole window, and turning it on afterwards is a decision an administrator makes explicitly, in the console, with a signature. Nothing in the product will make it for you.
Connect one workflow first
- Create a workspace, then explicitly enable Discovery Mode under Governance with your passkey.
- Instrument the requests you want to assess using the REST API or MCP integration. Keep existing controls in place.
- Start the assessment window under Governance and confirm the expected requests appear before expanding coverage.
Read the integration guide. Signing up alone does not connect systems or start the assessment.
What it watches
The same request-level observation works across these integrations. Anything you do not route through INTYGA is outside the report's coverage.
Authorization requests made through INTYGA's MCP tools or connected wrappers. Unconnected tools are not observed.
Anything calling /authorize with a human API key: deploy pipelines, migration runners, ad-hoc operator scripts.
Authorization requests your services explicitly send to INTYGA before a privileged operation.
What you get: the Security Risk Report
A printable document covering the assessment window — the dates it actually ran, not month-to-date — describing the separation-of-duties and control gaps found in it.
- Which identities approved their own requests, and how often.
- Which recorded requests had no human approval in the INTYGA path.
- Where a single person holds both the requesting and approving role.
- Which recorded action types are frequent enough to warrant a closer review before enforcement.
How it ends
After 14 days, the report's data window closes and a one-time notification is scheduled for workspace admins. Delivery is best-effort; the report is available under Governance even if that message does not arrive.
Discovery Mode does not expire on its own, and no scheduled job flips your workspace to enforcement. A product that started blocking production on a timer the customer never set would be a worse version of the problem this one exists to solve. Read the report, decide what is worth gating, and turn enforcement on for those actions when you are ready — or leave it observing for another month.
Start with an honest baseline.
Free to start, with browser passkey enrollment and no approver app to install. Connect one workflow and confirm it is being observed before drawing conclusions from the report.
Start your 14-day assessment →