The examiner’s evidence list arrived

Trident finds the control gap, proves it, and files the evidence the way your examiner reads it.

Report excerpt — finding detail

highCWE-269

One identity can release a payment alone

EntryOne operatorImpactNo second approver

Reproduced with a single operator account

The finding as the report presents it.

From console to cleared wire

Operations analyst signs in
Submits the wire
Choke point
Approves it as the same role
Payment released
One role submits and approves. A second party breaks it.

The finding, in control language

Segregation of duties
Tested, unmet
Privileged access
Tested, evidence filed
Core system reachability
Tested, evidence filed
Third-party access
Tested, evidence filed
Trident tests technical controls. Trident does not attest to regulatory compliance.

How the assessment runs

01

Recon

Scoped read-only access maps payment workflows and entitlements.

02

Path mapping

Entitlement edges chain into routes ending where money moves.

03

Exploit validation

Every hop is exercised. The control failure is demonstrated.

04

Draft PR + report

The severing change opens as a draft pull request.

Report and methodology, one bundle

The finding above, cross-referenced to the controls your examiner names.

  • Read-only assessment identities, scoped and expiring
  • Findings map to the control refs you file against
  • Every finding carries its reproduction and its fix
  • Methodology document ships alongside the report

Trident tests technical controls. Trident does not attest to regulatory compliance.

Controls tested against the estate, not the policy document

The gap that matters is between the control as written and the control as implemented in cloud identity.

Controls tested

Banking supervision cares less about the count of vulnerabilities than about whether the controls a bank claims to operate actually hold. Trident tests that directly. The flaw on this page is the classic failure: segregation of duties written into policy, then dissolved in cloud identity, where one role both submits a payment and approves it.

Segregation of duties
Toxic entitlement combinations — above all, any identity that can both initiate and approve a payment, directly or through an assumable role.
Privileged access
Standing administrative rights, unused break-glass accounts, wildcard policies, and whether elevation is genuinely time-bound and reviewed or only documented as such.
Core system reachability
Which identities and networks can reach core banking, ledger and payment infrastructure, including indirect routes through shared services and CI systems.
Third-party access
External roles, cross-account trust and vendor integrations holding standing access, ranked by what that access can reach rather than by contract tier.
Evidence retention
A durable record of what was tested, proven, remediated and retested — the artefact that survives examiner questions.

Questions examiners and control owners ask

Yes. Each finding carries the control references your framework uses, so the evidence files against the clause rather than arriving as a severity label an examiner has to translate.

Meet the examiner with evidence in hand.

See the gaps on your estate, each proven and mapped to a control.

Scoped access. Evidence, not attestations.