Skip to the content.

AITIR 2.0 Use Cases

Version: 2.0.0 Status: Illustrative scenarios, not deployment claims

Every use case follows the same boundary: telemetry becomes evidence; policy and named authority decide; connectors execute only a bounded decision; assurance verifies the outcome.

1. Privileged session anomaly

Scenario: A privileged identity authenticates from a new device and network context, then accesses a sensitive administrative resource outside its normal window.

AITIR flow:

Caution: New context is not proof of compromise; emergency or approved work can be unusual.

2. Service-account and workload identity

Scenario: A non-human identity begins using new credentials or resources.

AITIR flow:

3. MFA fatigue or suspicious authentication sequence

Scenario: Repeated prompts, failures, and a later successful session appear across one identity.

AITIR flow:

4. Identity attack-path remediation

Scenario: A subject graph shows several routes from ordinary identities to high-value administrative targets, but relationships have unequal confidence and disruption cost.

AITIR flow:

Caution: Synthetic graph-study results do not establish a production confidence model or optimal action cost.

5. Insider-threat triage with abstention

Scenario: A behavior model ranks user-day activity, but several cases are close to the decision boundary.

AITIR flow:

Caution: The submitted CERT study used synthetic data and assumed correct review in its cost model.

6. Cross-agency or partner risk signal

Scenario: A trusted partner sends an identity-risk event through CAEP/RISC or threat intelligence through STIX/TAXII.

AITIR flow:

7. Public-service continuity

Scenario: Identity controls protect a public-facing benefit, emergency, justice, health, or safety service.

AITIR flow:

8. Generative-AI-assisted investigation

Scenario: An LLM summarizes identity evidence or drafts an analyst timeline.

AITIR flow:

9. Research and training

AITIR can support tabletop exercises, schema mapping, policy testing, synthetic replay, academic evaluation, and procurement requirements. Researchers must disclose synthetic data, protocol changes, code and environment, negative findings, and limits to external validity.

Use-case acceptance checklist