Which identities moved money last night?
Your IGA knows who was entitled. Your DLP knows a file moved. Your fraud platform knows a payment cleared. None of them can tell you whether that behavior was normal for that identity. The gap between entitled and actual is where the risk lives.
Every other balance gets reconciled.
Access does not.
Entitlement is asserted in your role model; behavior is the only proof. CINQUE reads all five control points together and shows where the two disagree.
| Persona | Entitled, per RBAC | Observed, per CINQUE | Variance |
|---|---|---|---|
| Treasury analyst | Initiate payments | Initiate and approve | FOUR-EYES BREAK |
| Payment service account | 3 systems, batch window | 7 systems, off-window | SCOPE DRIFT |
| AML review agent | Read case files | Read and bulk export | NEW EXPORT PATH |
| Fintech partner integration | Sandbox API only | Production ledger read | BOUNDARY CROSSED |
| Branch operations | Teller applications | Teller applications | RECONCILED |
Detection tells you what happened. Context tells you whether it was supposed to happen.
Four places the variance shows up first.
Segregation of duties, verified
Asserted in your entitlement model, proven only in behavior. CINQUE shows where one persona sits on both sides of a control.
Payment-path exposure
Not just who can reach money movement, but which identities are behaving like they are moving toward it.
Third-party and fintech access
Your vendor register records who you contracted with, not what those identities actually touched.
Agents in regulated workflows
KYC, AML, and fraud agents run on borrowed human authority. CINQUE baselines them as personas of their own.
Evidence you can stand behind
at exam, in the register, and to the board.
Framework references reflect published requirements as of July 2026; the FFIEC retired its Cybersecurity Assessment Tool in August 2025 without endorsing a successor. Requirements vary by charter and jurisdiction; the direction toward continuous inventory, data-flow evidence, and accounting for the AI you run does not.
CINQUE for Financial Services security leaders
Which identities moved money last night? The reconciliation nobody runs: entitled versus observed, for payment rails, fintech partners, contractors, and the agents in KYC, AML, and fraud workflows.
- Segregation of duties, verified in behavior
- Payment-path exposure by observed movement, not entitlement
- Third-party and fintech access, what those identities actually touched
- Evidence mapped to NYDFS Part 500, DORA, CRI Profile, PCI DSS v4.x
Your data, handled like we mean it. You choose the export: limited, point-in-time, analyzed in an isolated environment, and deleted after your readout. Ask us for the data-handling summary; we are a security company and we expect the question.