HomeOur Blog
Blog Posts

The whole soup: cloud AI infrastructure for insider-risk investigations

Amir Boldo

Amir Boldo

Aviv Nahum

Aviv Nahum

Table of contents
Amir Boldo

Amir Boldo

Aviv Nahum

Aviv Nahum

Insider risk behaves like a soup. The more ingredients our AI can taste at once, the better its judgment. Getting there means reasoning at scale over both human and agent behavior, which is mostly a question of infrastructure.

An employee downloads 4 GB of files just before midnight, then signs in an hour later from a city they’ve never worked from. On most security tools that is two alerts and a tense morning for your team.

At Above it is usually nothing, and we can tell you why before anyone loses sleep over it. The person was promoted on Friday, the files belong to a project they now own, and the unfamiliar city is where their manager’s offsite is being held this week.

The signal looked alarming. The context made it ordinary. That gap is the whole problem with insider risk, and closing it is what we built Above to do.

Insider risk is a soup

Brent Predovich, a Gartner analyst who covers insider risk, frames it with an analogy we keep coming back to. Insider risk is a soup, and no single ingredient tells you much on its own.

A large download. A login from a new place. A copy to a USB stick. An email forwarded to a personal address. A calendar invite to a domain nobody recognizes. A message to a colleague who left months ago. A quiet resignation rumor. A sudden interest in a repository someone never usually opens.

Taste any one of them alone and you can’t say whether the soup is fine or spoiled. Simmer them together with everything you know about the person and their role, and the flavor comes through. The dish either makes sense or it doesn’t.

The more ingredients an investigator can draw on, the better its judgment gets. The harder question is how to get all of them into the same pot.

Any single vantage point tastes only one ingredient

A laptop agent sees what happens on that laptop, and what it sees is real and useful. A file leaves. A device is plugged in. Those are genuine ingredients, and we want them.

What a single vantage point can’t do is judge them. The endpoint has no way of knowing the person was promoted last week, or that half their team did the same thing this morning because a project shipped, or that this exact pattern shows up every quarter close and has never once been trouble.

Ask any one source to render a verdict on its own and you get the same two outcomes. It reacts to everything that looks vaguely off and floods your analysts with false positives, or it stays quiet and lets the real thing slip past. Both come from the same place: a verdict reached somewhere that can only see a sliver of the picture.

So we don’t ask any single point to be the judge. We gather the endpoint’s signals along with everything else and move the reasoning to where all of it can sit together.

Reasoning at scale is the hard part

Pulling every ingredient into one pot and reasoning over it, continuously, for an entire workforce, is a genuinely difficult engineering problem. It is also the whole point, so we built the infrastructure for it before anything else.

Start with the signals themselves. They arrive from identity systems, SaaS apps, endpoints, data stores, and collaboration tools, each in its own format, on its own clock, with its own quirks. Correlating all of it into a coherent picture of one person’s behavior, as it happens, is harder than any single connector makes it look.

Then there is memory. A good judgment depends on knowing what normal looks like for this person, this team, this role, and normal keeps moving. The system has to hold a living model of behavior for every identity and update it constantly, because a baseline from three months ago will quietly lie to you.

On top of that sits a fleet of investigative agents that reason around the clock instead of on a schedule. The work they generate is bursty by nature. A quiet week asks little of the system; a reorg, a layoff, or a sensitive project can light up thousands of identities at once. The infrastructure has to expand to meet that and settle back down afterward, without anyone sizing hardware in advance.

The reasoning itself also keeps improving. Because the platform runs on cloud AI infrastructure, we can adopt stronger models as they arrive and run different ones for different stages of an investigation, so the quality of judgment rises over time rather than freezing on the day a box was installed.

None of this bolts onto a tool designed to make local decisions. Reasoning at scale is a good thing and a hard thing, and it only works when the infrastructure was built for it from the start.

More ingredients, sharper judgment

This is also why we keep adding sources rather than paring them back. Identity, SaaS activity, endpoint telemetry, access patterns, email, calendars, chat and collaboration tools, file shares, the org chart, and now the behavior of the AI agents that increasingly act inside companies on people’s behalf.

Each new source is another ingredient to weigh. For a tool making isolated decisions, more signal just means more noise. For a system built to reason over all of it at once, more signal means better calls.

So the same download that would trip a local agent gets read against forty other facts, and most of the time those facts explain it. The few cases they don’t explain are the ones worth a person’s attention.

Investigations, not alerts

This is the part we’re proud of, and it comes straight from where the reasoning happens.

An alert is what a tool produces when it notices one ingredient and reacts. An investigation is what a system produces when it has weighed all of them and can explain itself: what the person did, the context around it, why it does or doesn’t add up, and what to do next.

Because every conclusion comes out of the full picture, we sit close to zero false positives. We wait until the ingredients together actually warrant a conclusion, and then we show our work.

Your analyst doesn’t have to reassemble the story to find out whether it’s real. It shows up already built. The correlation work that used to swallow an insider-risk program, the hours someone spends stitching logs from five systems together to learn whether a flag means anything, is the part the platform now handles on its own.

What a quiet queue is worth

A program drowning in false positives is just a queue nobody trusts. After enough false alarms, people stop looking, and the one alert that mattered sits there unread.

Getting close to zero false positives saves hours, but the hours are the smaller win. The bigger one is that the alerts which do land get believed and acted on. You can walk into a room with HR and legal carrying a real account of what happened instead of a suspicion you still have to prove.

That confidence only comes from weighing everything at once, which only works on infrastructure built for it. We put the reasoning where every ingredient can reach it, so the investigator decides from the whole picture rather than from whatever one source happened to see.

The soup is always better than the spoonful. We built Above to taste the whole pot.

Share

Contact us

You've made a great move.
We'll be in touch shortly

Close
Watch Now