Plain-language guidance about meaningful signals, privacy boundaries and safe next steps.
Explore for individuals →Continuous assurance · For people and organisations
Shine light on change.
Know what needs attention.
Help people understand relevant trust and security changes. Help organisations turn identity, access and application signals into owned action and assurance.
→ DECIDE
→ RESPOND
Two clear experiences
Awareness for people. Assurance for organisations.
Specialist monitoring, detection engineering, incident operations and assurance across authorised systems.
Explore for organisations →Use Vigilance independently or connect DiligenceID and Delegance signals around a broader trust journey.
Use authorised operational signals for a defined purpose and avoid collecting unrelated personal or credential information.
The leadership issue
Most organisations have logs.
Fewer have operational assurance.
Signals are fragmented
Identity, access, application and credential events sit in different systems and schemas.
Alerts lack context
Teams receive technical conditions without the authority, resource or business impact needed to act.
Blind spots persist
Custom applications and delegated administration may sit outside standard SOC integrations.
Response varies
Ownership, escalation, containment and evidence can be reconstructed differently every time.
Operating model
From source signal to governed response—and measurable learning.
Vigilance connects collection, context and action. It does not equate more telemetry with better control, or an alert with an owned incident.
What changes
Shorten the path from change to accountable action.
Correlate identity, privilege, authority and application events across control boundaries.
Enrich signals with identity, resource, delegation and business ownership so detection has something to reason about.
Assign severity, ownership, investigation and proportionate containment once a detection is confirmed.
Report coverage, recurring patterns, response evidence and unresolved control gaps to drive ongoing improvement.
Microsoft Sentinel
A major platform for identity-centred monitoring.
MAITS can bring Microsoft Entra signals, directory events, access changes, application telemetry, custom systems and credential lifecycle events into Sentinel.
Normalisation and identity context make correlation possible; analytics, incidents and runbooks create an operational path. Vigilance can also use the monitoring platform that fits the organisation’s sources and operating model.
Explore the Sentinel model →Custom connectors
Observe the systems standard integrations miss.
MAITS confirms the source interface, security model and operational requirements, then engineers the ingestion and support path around that system.
Understand connector engineering →Identity and trust detection patterns
Detect changes that alter trust or authority.
Unexpected administrator assignment
Unusual identity recovery
Authority outside expected scope
Issuance or revocation anomaly
Abnormal administration activity
Excessive access change
Each detection is mapped to available telemetry, a tested baseline, an accountable owner and a proportionate response.
Explore detection design →Alert ≠ incident
An alert describes a condition. An incident owns the response.
Runbooks can enrich, notify, ticket or act automatically. High-impact response can retain human approval.
Explore incident operations →Managed service
Maintain observability as the environment changes.
Signals and connectors
Assess sources, implement ingestion and maintain monitoring coverage.
Analytics and tuning
Map detections to risk, test them and refine with operational evidence.
Incidents and runbooks
Structure ownership, investigation, escalation and proportionate action.
Executive assurance
Explain high-risk events, control gaps, recurring patterns and unresolved exceptions.
MAITS product family
Evidence. Authority. Assurance.
What evidence can this person or organisation prove?
Explore DiligenceID →Who is authorised to act, where and for how long?
Explore Delegance →How do we know when trust or access is at risk?
Frequently asked questions
Monitoring claims, kept precise.
What service model does Vigilance use?
Vigilance provides specialist monitoring and operational assurance for identity, access, applications and digital trust. Support hours, response ownership and service levels are agreed for each engagement.
Is Microsoft Sentinel required?
No. Sentinel is a major MAITS implementation platform, but the monitoring platform is selected for the organisation and engagement.
Are the listed detections prebuilt?
No. They are candidate detection patterns. Each requires available telemetry, implementation, testing, tuning and an owned response.
Does credential monitoring require complete credential contents?
No. Operational signals can cover issuance, verification, status, revocation, configuration and service health without collecting complete credential contents.
Next step
Start with the risks you cannot currently see.
Bring the identity systems, critical actions, current telemetry and response ownership. MAITS can map the observability gaps.
Discuss Vigilance →