Skip to content

INTYGA Intelligence

See what needs your attention.

Investigate unusual authorization activity with the evidence in front of you. Intelligence is an open-source, self-hosted application that surfaces findings and protects sensitive configuration changes with signed human approval.

Requires an INTYGA workspace. Production hardening is underway. See setup requirements →

From activity to a reason to investigate

17 refusals. One integration. What changed?

A release service starts attempting permission changes. Its requests are refused, but the pattern deserves a closer look. Intelligence compares that activity with the same subject's observed history and surfaces the difference.

Refusals in 8 minutes
17
Typical for that window
2
Permission-change attempts
12
Intelligence findings interface: a high-severity finding for 17 refused operations from release-service, with baseline metrics, action counts and source event references.
Current application interface, populated with synthetic events. The finding was generated by the implemented refusal-burst detector. Select the image to view it at full size.
Why did this become a finding?

The volume changed. Seventeen refusals exceed both the detector's minimum count and its threshold relative to this subject's baseline of two per window.

The behavior changed. Twelve attempts involve permissions.update, an action type absent from this subject's earlier observed refusal history.

The evidence is inspectable. The finding includes counts, the baseline and references to source events. No model is needed to produce this finding. It is a reason to investigate, not proof of a compromise.

How it fits with INTYGA

Evidence to investigate. Approval to change.

Intelligence surfaces findings

Review unusual activity, inspect its evidence and record whether it is expected, useful or worth investigating. You decide what needs a response.

INTYGA protects sensitive changes

Enabling connectors, turning on alert destinations, switching a detector off, issuing an administrator's enrollment link, configuring model judgment and purging data each require a passkey approval bound to the exact change, so a detector cannot be silenced from the console without one. Intelligence uses INTYGA's embedded approvals to enforce it.

Intelligence observes connected activity; it does not automatically remediate your systems. Its availability does not affect INTYGA's authorization service. If INTYGA is unreachable, privileged changes inside Intelligence cannot proceed without approval.

Explore the embedded approval model →

Start with the signals you connect.

Connectors bring operational events into a common format. Connecting a source determines what Intelligence can observe. For anything not listed, send signed events to the custom webhook without writing code, or write a connector in a single file.

Built-in connectors

  • INTYGA
  • GitHub
  • GitLab
  • Vercel
  • Netlify
  • Cloudflare Pages
  • Sentry
  • PagerDuty
  • Datadog
  • Fly.io
  • Metrics (Prometheus)
  • Opsgenie (until its April 2027 shutdown)
  • Custom webhook

Connect your own source →

Evidence comes first

Three detectors: refusal bursts and unfamiliar action types, security-sensitive code changes, and regressions after a production deploy. Each finding starts with measured evidence. A post-deploy finding reports timing, not proof of cause, and says so.

AI assistance is optional

Model judgment is off by default. If enabled, it can adjust severity or filter expected behavior after detection. It does not originate findings.

You operate the application

Run Intelligence and its database on your infrastructure. Approval requests send INTYGA a digest of the change. Optional model and alert integrations send their configured data to those destinations.

Current scope: three detectors — refusal bursts, security-sensitive code changes, and regressions after a production deploy. Connectors are reference implementations built on each vendor's documented API.

Open source · Self-hosted

Explore it on your infrastructure.

Intelligence is licensed under Apache 2.0. The early release is available to inspect and evaluate while production hardening continues; it has no support SLA.

  1. Prepare your deployment.Run the Node.js application and PostgreSQL database using the repository's setup guide.
  2. Connect an INTYGA workspace.Register the application's domain for embedded approvals and enroll an administrator's passkey from a one-time enrollment link. A workspace is required to run Intelligence.
  3. Enable a source and inspect the findings.Sign the connector configuration, then review the activity you have explicitly connected.

The application's open-source license is separate from your INTYGA workspace plan. See workspace plans →