MAITS identity and security observability

See identity risk.
Act with context.

Specialist monitoring, detection and response for identity systems, delegated access, digital credentials and the applications they protect.

The leadership issue

Most organisations have logs.
Fewer have operational assurance.

01

Signals are fragmented

Identity, access, application and credential events sit in different systems and schemas.

02

Alerts lack context

Teams receive technical conditions without the authority, resource or business impact needed to act.

03

Blind spots persist

Custom applications and delegated administration may sit outside standard SOC integrations.

04

Response varies

Ownership, escalation, containment and evidence can be reconstructed differently every time.

Operating model

From source signal to governed response—and measurable learning.

Vigilance connects collection, context and action. It does not equate more telemetry with better control, or an alert with an owned incident.

From signal to responseSignals are ingested, normalised and correlated before detections create alerts. Actionable alerts become owned incidents, responses and learning. Alert and incident are distinct stages.01SIGNALSIdentity · access · trust02INGESTGoverned collection03NORMALISEConsistent entities04CORRELATERelated activity05DETECTTested analytics06ALERTCondition to assess07INCIDENTOwner + severity08RESPONDContain + remediate09LEARNTune + assureFrom signal to responseSignals are ingested, normalised and correlated before detections create alerts. Actionable alerts become owned incidents, responses and learning. Alert and incident are distinct stages.01SIGNALSIdentity · access · trust02INGESTGoverned collection03NORMALISEConsistent entities04CORRELATERelated activity05DETECTTested analytics06ALERTCondition to assess07INCIDENTOwner + severity08RESPONDContain + remediate09LEARNTune + assure
An alert describes a condition requiring assessment. An incident is an owned investigation with severity and a response path.
Explore monitoring coverage →

What changes

Shorten the path from change to accountable action.

VISIBILITYKnow what changed

Correlate identity, privilege, authority and application events across control boundaries.

CONTEXTKnow why it matters

Enrich signals with identity, resource, delegation and business ownership.

RESPONSEKnow who acts next

Assign severity, ownership, investigation and proportionate containment.

ASSURANCEKnow what improved

Report coverage, recurring patterns, response evidence and unresolved control gaps.

Microsoft Sentinel

A major platform for identity-centred monitoring.

MAITS can bring Microsoft Entra signals, directory events, access changes, application telemetry, custom systems and credential lifecycle events into Sentinel.

Normalisation and identity context make correlation possible; analytics, incidents and runbooks create an operational path. Sentinel is a key implementation platform—not a mandatory choice for every engagement.

Explore the Sentinel model →
How identity signals become operational monitoringSignals from identity systems, applications, digital credentials, Delegance and custom systems move through supported collection and normalisation into Microsoft Sentinel or another selected monitoring platform, analytics, alerts and incidents.01SIGNAL SOURCESIdentity · apps · trust02CONNECTORS / INGESTSupported collection03NORMALISEEntity + event context04MONITORING PLATFORMSentinel or selected tool05ANALYTICSDetection hypotheses06ALERTS / INCIDENTSAssessment + ownershipHow identity signals become operational monitoringSignals from identity systems, applications, digital credentials, Delegance and custom systems move through supported collection and normalisation into Microsoft Sentinel or another selected monitoring platform, analytics, alerts and incidents.01SIGNAL SOURCESIdentity · apps · trust02CONNECTORS / INGESTSupported collection03NORMALISEEntity + event context04MONITORING PLATFORMSentinel or selected tool05ANALYTICSDetection hypotheses06ALERTS / INCIDENTSAssessment + ownership
Microsoft Sentinel is a major supported implementation platform, not a mandatory dependency for every Vigilance engagement.

Custom connectors

Observe the systems standard integrations miss.

How custom signals enter monitoringSupported REST APIs, webhooks, Event Hub, Log Analytics, syslog or polling patterns can produce a normalised security signal for monitoring and detection.SOURCES / PATTERNSCONTROLOUTCOMESREST APIWEBHOOKEVENT HUBLOG ANALYTICSSYSLOGPOLLINGVIGILANCENormalised signalSchema · entity · timeMONITORINGDETECTIONHow custom signals enter monitoringSupported REST APIs, webhooks, Event Hub, Log Analytics, syslog or polling patterns can produce a normalised security signal for monitoring and detection.SOURCES / PATTERNSREST APIWEBHOOKEVENT HUBLOG ANALYTICSSYSLOGPOLLINGVIGILANCENormalised signalSchema · entity · timeOUTCOMESMONITORINGDETECTION
These are integration patterns selected and engineered for the source—not a claim of prebuilt connectors.

These are implementation patterns, not a claim that each connector already exists. MAITS confirms the source interface, security model and operational requirements before building an integration.

Understand connector engineering →

Potential detection patterns

Detect changes that alter trust or authority.

PRIVILEGE

Unexpected administrator assignment

RECOVERY

Unusual identity recovery

DELEGATION

Authority outside expected scope

CREDENTIALS

Issuance or revocation anomaly

APPLICATION

Abnormal administration activity

ENTITLEMENT

Excessive access change

Examples are candidate analytics, not prebuilt or guaranteed detections.

Explore detection design →

Alert ≠ incident

An alert describes a condition. An incident owns the response.

How an alert becomes an owned incidentA signal matches a detection and creates an alert. Assessment branches to close and tune when it is not actionable, or to an owned incident, response and learning when it is actionable.SIGNALDETECTIONALERTASSESSMENTNOT ACTIONABLECLOSE / TUNERetain evidenceACTIONABLEINCIDENTOwner · severity · contextRESPOND + LEARNAlert and incident decision pathSignal, detection, alert and assessment are stacked. Assessment branches to close and tune or to an owned incident and response.SIGNALDETECTIONALERTASSESSMENTCLOSE+ TUNEINCIDENTOwnedRESPOND + LEARNContain · remediate · improve
Alerts require assessment. Incidents require ownership, severity, an accountable response and closure evidence.

Runbooks can enrich, notify, ticket or act automatically. High-impact response can retain human approval.

Explore incident operations →

Managed service

Maintain observability as the environment changes.

ONBOARD

Signals and connectors

Assess sources, implement ingestion and maintain monitoring coverage.

DETECT

Analytics and tuning

Map detections to risk, test them and refine with operational evidence.

RESPOND

Incidents and runbooks

Structure ownership, investigation, escalation and proportionate action.

REPORT

Executive assurance

Explain high-risk events, control gaps, recurring patterns and unresolved exceptions.

MAITS product family

Evidence. Authority. Assurance.

DILIGENCEIDTrusted evidence

What evidence can this person or organisation prove?

DELEGANCEControlled authority

Who is authorised to act, where and for how long?

VIGILANCEContinuous assurance

How do we know when trust or access is at risk?

Frequently asked questions

Monitoring claims, kept precise.

Is Vigilance a generic SOC service?

No. Vigilance is specialist monitoring and operational assurance for identity, access, applications and digital trust. No 24x7 SOC capability or fixed SLA is implied.

Is Microsoft Sentinel required?

No. Sentinel is a major MAITS implementation platform, but the monitoring platform is selected for the organisation and engagement.

Are the listed detections prebuilt?

No. They are candidate detection patterns. Each requires available telemetry, implementation, testing, tuning and an owned response.

Does credential monitoring require credential contents?

Not necessarily. Useful operational signals can cover issuance, verification, status, revocation, configuration and service health without collecting complete credential contents.

Next step

Start with the risks you cannot currently see.

Bring the identity systems, critical actions, current telemetry and response ownership. MAITS can map the observability gaps.

Discuss Vigilance →