Lojycally speaking, IT security.
Shadow IT discovery, AI threat detection, dual-control response and signed evidence — one governed posture, not five dashboards arguing with each other.
One finding. One owner. One audited response.
Why IT security breaks
Shadow IT inventories live in one tool, threat detections in another, incident response in a third, and the evidence binder in a fourth. By the time the auditor asks "who saw this and what did you do?", the answer depends on which tool you trust today.
Lojycal collapses discovery, detection, response and proof into one governed posture. The finding, the responder, the approval, the action and the evidence are the same record — read once, written once, signed once.
The three labs that move as one
Shadow IT Lab, AI Threat Lab and the Trust Center share the same ledger. Findings flow forward; evidence flows back.
Shadow IT Lab
Discover every SaaS, browser extension and OAuth grant your people are actually using — pulled from IdP sign-ins, the managed-browser cookie jar and finance signals. Then sanction, owner-attest or block from one inventory.
- Discovery sources reconcile against one app row, not three exports.
- Per-app owners, scopes and spend visible alongside the finding.
- Sanction / request-owner / block with a single approval path.
- Per-app cost flows straight into the Financial Impact ledger.
AI Threat Lab
Anomaly detection over MDM dispatches, IdP sign-ins, cookie-jar posture and break-glass usage. Verdicts come with the underlying events, not a black-box score, and every response is dual-controlled and time-boxed.
- Hourly anomaly checks across device, identity and browser telemetry.
- Break-glass requires reason, expiry and a second admin's review.
- Unclosed break-glass sessions auto-expire — no quiet escalation.
- Incidents land in a WORM archive and prefill the Policy Lab report.
Governance & evidence
The Trust Center turns posture into evidence. KMS, scope, dual-control, anomaly, SIEM, webhook, compliance, review, pentest, pgAudit and hardening each have a live pillar — and the evidence pack is HMAC-signed before it leaves the building.
- SIEM egress is HMAC-SHA256 signed per endpoint, replay-protected.
- Access reviews auto-populate from privileged membership — keep / reduce / revoke.
- Evidence packs are signed and every export logged to the audit_log.
- Idempotent ingestion: webhook events are deduped on (provider, external_id).
One governed loop — discover → detect → respond → prove
The same row that surfaces a rogue SaaS becomes the incident the security team works, the dual-controlled response the platform admin executes, and the signed artefact the auditor receives.
- Step 1Discover
Shadow IT Lab surfaces an unsanctioned SaaS, OAuth grant or browser extension from IdP + cookie-jar + finance signals.
- Step 2Detect
AI Threat Lab cross-references that finding against device posture, sign-in anomalies and break-glass activity.
- Step 3Respond
Policy Lab opens an incident (WORM). Break-glass is dual-controlled, time-boxed and reviewable by a second admin.
- Step 4Prove
Trust Center signs the evidence pack; the audit_log records who saw what, when, and on which assurance level (AAL2).
What changes when IT security makes Lojycal sense
- Shadow IT findings carry an owner and a cost, not just a name.
- Break-glass is reasoned, time-boxed and second-admin reviewed.
- Incidents flow into a WORM archive that prefills the report.
- Evidence packs ship signed — verifiable outside the app.
- SIEM egress is HMAC-signed per endpoint, replay-protected.
- Platform-admin actions require AAL2 — password-only sessions can't.
Questions auditors and security leaders actually ask
- How does Shadow IT discovery work without a network agent?
- Lojycal blends IdP sign-in events, the managed-browser cookie jar and finance signals (vendor charges, SaaS subscriptions). Each app row reconciles across all three sources, so a rogue app appears once with owner, scopes and spend attached.
- Who can trigger break-glass, and what stops abuse?
- Only platform admins on an AAL2 session. Every break-glass requires a reason (≥10 chars), an expiry (≤240 min) and review by a different admin. Unclosed sessions auto-expire and every step is written to the audit_log.
- Where do incident reports live?
- Policy Lab → Incident Reports. The incident archive is WORM — a database trigger blocks UPDATE/DELETE for everyone. Generating a PDF report logs an incident_reports row alongside the WORM archive.
- How is exported evidence trustworthy outside the app?
- Evidence packs are generated by a SECURITY DEFINER function and signed with a per-org HMAC key. Every signed export is logged to evidence_pack_signatures and the audit_log so an auditor can verify the artefact without trusting the UI.
- How is MFA enforced for security actions?
- Privileged tables (user_roles, app_auth_settings, security_events, kms_master_keys, pentest_*) require AAL2 — a password-only session cannot read or write them even if the admin row exists. Root shell and key entrypoints all re-check live AAL.
IT security should make Lojycal sense.
One posture for shadow IT, threats, response and evidence. No black-box scores, no unilateral admin actions, no last-minute audit scrambles. Just the security truth, signed and queryable on demand.
