Most organisations have logs. Fewer have operational assurance.
01
Signals are fragmented
Identity, access, application and credential events sit in different systems and schemas.
02
Alerts lack context
Teams receive technical conditions without the authority, resource or business impact needed to act.
03
Blind spots persist
Custom applications and delegated administration may sit outside standard SOC integrations.
04
Response varies
Ownership, escalation, containment and evidence can be reconstructed differently every time.
Operating model
From source signal to governed response—and measurable learning.
Vigilance connects collection, context and action. It does not equate more telemetry with better control, or an alert with an owned incident.
An alert describes a condition requiring assessment. An incident is an owned investigation with severity and a response path.Explore monitoring coverage →
What changes
Shorten the path from change to accountable action.
VISIBILITYKnow what changed
Correlate identity, privilege, authority and application events across control boundaries.
CONTEXTKnow why it matters
Enrich signals with identity, resource, delegation and business ownership.
RESPONSEKnow who acts next
Assign severity, ownership, investigation and proportionate containment.
ASSURANCEKnow what improved
Report coverage, recurring patterns, response evidence and unresolved control gaps.
Microsoft Sentinel
A major platform for identity-centred monitoring.
MAITS can bring Microsoft Entra signals, directory events, access changes, application telemetry, custom systems and credential lifecycle events into Sentinel.
Normalisation and identity context make correlation possible; analytics, incidents and runbooks create an operational path. Sentinel is a key implementation platform—not a mandatory choice for every engagement.
Microsoft Sentinel is a major supported implementation platform, not a mandatory dependency for every Vigilance engagement.
Custom connectors
Observe the systems standard integrations miss.
These are integration patterns selected and engineered for the source—not a claim of prebuilt connectors.
These are implementation patterns, not a claim that each connector already exists. MAITS confirms the source interface, security model and operational requirements before building an integration.
What evidence can this person or organisation prove?
DELEGANCEControlled authority
Who is authorised to act, where and for how long?
VIGILANCEContinuous assurance
How do we know when trust or access is at risk?
Frequently asked questions
Monitoring claims, kept precise.
Is Vigilance a generic SOC service?
No. Vigilance is specialist monitoring and operational assurance for identity, access, applications and digital trust. No 24x7 SOC capability or fixed SLA is implied.
Is Microsoft Sentinel required?
No. Sentinel is a major MAITS implementation platform, but the monitoring platform is selected for the organisation and engagement.
Are the listed detections prebuilt?
No. They are candidate detection patterns. Each requires available telemetry, implementation, testing, tuning and an owned response.
Does credential monitoring require credential contents?
Not necessarily. Useful operational signals can cover issuance, verification, status, revocation, configuration and service health without collecting complete credential contents.
Next step
Start with the risks you cannot currently see.
Bring the identity systems, critical actions, current telemetry and response ownership. MAITS can map the observability gaps.