Which identities touched your stores last night?
Retail's hardest year proved the pattern: attackers did not break in. They logged in. CINQUE learns what normal looks like for every identity across stores, DCs, and digital.
Inventory, cash, and shrink get reconciled nightly.
Access does not.
Entitlement is asserted in your access model; behavior is the only proof. CINQUE reads all five control points together and shows where the two disagree.
| Persona | Entitled, per RBAC | Observed, per CINQUE | Variance |
|---|---|---|---|
| Seasonal associate | POS sales, own store | Gift cards issued off-shift | SHRINK PATTERN |
| Store-systems vendor | Maintenance telemetry | Hop toward payment network | SCOPE DRIFT |
| Reset employee | Help-desk password reset | MFA re-enrolled, new geo | TAKEOVER PATTERN |
| DC automation | Replenishment, overnight | Replenishment, overnight | RECONCILED |
Detection tells you what happened. Context tells you whether it was supposed to happen.
Four places retailers point it first.
Seasonal identity churn
Day-one hires measured against the role's baseline, not a history they do not have.
Payment-path exposure
Which identities are behaving like they are moving toward cardholder data.
Third-party and store vendors
What contracted identities actually touched, on the store network and beyond it.
Agents in retail workflows
Loyalty, pricing, and supply-chain agents baselined as personas of their own.
PCI DSS v4.x now runs against the full standard.
Show how the payment path is actually used.
PCI DSS v4.x future-dated requirements became enforceable March 31, 2025; every assessment now runs against the full standard.
CINQUE for Retail security leaders
Which identities touched your stores last night? Seasonal churn, store-systems vendors, and the payment path, reconciled across stores, DCs, and digital.
- Seasonal identity churn: day-one hires measured against the role's baseline
- Payment-path exposure: which identities are behaving like they are moving toward cardholder data
- Third-party and store vendors: what they actually touched on the store network and beyond
- Evidence for PCI DSS v4.x 7.2.4 / 7.2.5, your acquirer and QSA, your insurer and board
Your data, handled like we mean it. You choose the export: limited, point-in-time, analyzed in an isolated environment, and deleted after your readout. Ask us for the data-handling summary; we are a security company and we expect the question.