Skip to main content

Wedges - Feb 2026

Last update: 2026-02-14

WedgeJob AreaCustomer PainWhat We Deliver (MVV)
W1 – LANDDiscover Autonomous ExecutionI don’t know what automations exist or which are AI-enabledDeterministic inventory of automations + execution identities in ServiceNow + Foundry
W1 – LANDUnderstand Data Reachability“So what?” — I can’t tie bots to sensitive dataRisk-first list view where each finding shows automation → identity → system → data domain; expandable mini-graph per finding
W1 – LANDClassify Egress (LLM/External/Internal/Unknown)I can’t tell which automations are sending data to LLMs or outside the enterprise boundaryDeterministic egress host/base URL extraction + category badge/filter per finding (no payload inspection)
W1 – LANDDetect Ownership DecayOwners leave; no one reviewing automationsOwnership health surfaced as badge + filter in risk list; detailed evidence panel per finding
W1 – LANDSurface High-Risk CasesToo many signals, no prioritizationDashboard “Top Risks” list (top 10) with badges for data domain, LLM/egress, ownership, drift; expandable deterministic path view
W1 – LANDCommunicate RiskHard to explain AI automation risk to ELTOne-page executive brief (generated PDF) + per-finding evidence snapshot (deterministic path + source references)
W2 – EMBEDGate AI Before ProductionSecurity is asked to approve blindlyRisk scan triggered at prod deployment event; models execution authority against current prod state
W2 – EMBEDProvide Deterministic Risk“Is it safe?” is subjectiveDeterministic execution authority report for the specific workflow being deployed (same path view + evidence model as W1)
W2 – EMBEDDetect Drift / Compare Against BaselineApproval today ≠ safe tomorrowDrift delta from last approved version, shown as structured change summary in report
W2 – EMBEDDetect Drift (Existing Estate)Risk accumulates silently over timeDrift badge + filter on the estate view; “What changed” section inside each finding detail view
W2 – EMBEDCreate Audit EvidenceNo proof of due diligenceDownloadable evidence bundle (execution path, identities, data domains, timestamps)
W2 – EMBEDEnable Clear DecisionNo formal AI governance checkpointEvidence output + per-finding disposition field (Reviewed / Accepted risk / Needs remediation / Blocked externally)
W3 – CATEGORYMaintain NHI InventoryNo clear inventory of machine identitiesCross-system non-human identity inventory: SPs, managed identities, API tokens, automation accounts
W3 – CATEGORYDetect Authority ExpansionPermissions compound silentlyPrivilege & integration drift detection
W3 – CATEGORYModel Compounding RiskAuthority compounds across systemsCross-plane authority correlation
W3 – CATEGORYMonitor Risk Over TimeNo way to show AI risk improving or worseningRisk trend dashboard
W3 – CATEGORYFeed Security OpsNo operationalization of AI identity riskSOC-ready risk signals - "risk signal" export
W3 – CATEGORYReduce ExposureNo guidance on tightening NHI riskExposure reduction guidance