The examiner’s evidence list arrived
Trident finds the control gap, proves it, and files the evidence the way your examiner reads it.
Report excerpt — finding detail
One identity can release a payment alone
EntryOne operatorImpactNo second approver
Reproduced with a single operator account
From console to cleared wire
The finding, in control language
- Segregation of duties
- Tested, unmet
- Privileged access
- Tested, evidence filed
- Core system reachability
- Tested, evidence filed
- Third-party access
- Tested, evidence filed
How the assessment runs
Recon
Scoped read-only access maps payment workflows and entitlements.
Path mapping
Entitlement edges chain into routes ending where money moves.
Exploit validation
Every hop is exercised. The control failure is demonstrated.
Draft PR + report
The severing change opens as a draft pull request.
Report and methodology, one bundle
The finding above, cross-referenced to the controls your examiner names.
- Read-only assessment identities, scoped and expiring
- Findings map to the control refs you file against
- Every finding carries its reproduction and its fix
- Methodology document ships alongside the report
Trident tests technical controls. Trident does not attest to regulatory compliance.
Controls tested against the estate, not the policy document
The gap that matters is between the control as written and the control as implemented in cloud identity.
Controls tested
Banking supervision cares less about the count of vulnerabilities than about whether the controls a bank claims to operate actually hold. Trident tests that directly. The flaw on this page is the classic failure: segregation of duties written into policy, then dissolved in cloud identity, where one role both submits a payment and approves it.
- Segregation of duties
- Toxic entitlement combinations — above all, any identity that can both initiate and approve a payment, directly or through an assumable role.
- Privileged access
- Standing administrative rights, unused break-glass accounts, wildcard policies, and whether elevation is genuinely time-bound and reviewed or only documented as such.
- Core system reachability
- Which identities and networks can reach core banking, ledger and payment infrastructure, including indirect routes through shared services and CI systems.
- Third-party access
- External roles, cross-account trust and vendor integrations holding standing access, ranked by what that access can reach rather than by contract tier.
- Evidence retention
- A durable record of what was tested, proven, remediated and retested — the artefact that survives examiner questions.
Questions examiners and control owners ask
Meet the examiner with evidence in hand.
See the gaps on your estate, each proven and mapped to a control.
Scoped access. Evidence, not attestations.