A privileged account is, by design, allowed to do almost anything. That makes the difference between routine privileged work and dangerous privileged work invisible to entitlement-based controls. Vedric reads the behavioral shape underneath the privilege.
THE PROBLEM
PAM and identity tooling decide what privileged users are allowed to do. Once that gate is open, the difference between routine elevation and dangerous elevation lives entirely in behavior: when it happens, on which systems, with which commands, against which data. Without a behavioral baseline on those primitives, every privileged action looks the same.
Decides who can elevate and brokers the credentials. It does not score the resulting behavior. A legitimate elevation followed by a command sequence the user has not run in six months is still an approved elevation as far as PAM is concerned.
Captures content. Generates terabytes nobody watches. Surfaces nothing in real time. By the time someone scrubs the recording, the action has been taken.
Tell you the action was approved. They do not tell you that this approval, on this user, on this day, sits outside the user historical pattern.
Block lists are brittle. Admin tooling is too varied, and the privileged commands that matter are usually built into the OS or the cloud provider, not on a list.
Vedric runs the same per-user, per-peer, and per-endpoint baselines on privileged accounts as it does on standard ones, but the storyline weighting is different. Privileged scope drift, privileged temporal drift, and privileged command drift all promote earlier, because the cost of missing is higher.
A privileged account running a command outside its six-month pattern is treated as a stronger signal than the same command from an unprivileged user. Vedric promotes privileged drift earlier in the storyline lifecycle.
Whether the command is encoded, off-hours, run on systems outside the user normal scope, or in an unusual sequence - those modifiers, not the command itself, are what matter for a privileged user.
Privileged incidents end up in front of legal, the board, or a regulator. Vedric writes detection, AI verdict, and analyst response to an append-only audit trail with database-level mutation refused, so the chain holds up later.
EXAMPLE SCENARIO · TIMELINE
A domain admin who has worked the same shift for two years runs a sequence of commands at the start of an evening that nobody on the team would have flagged in isolation.
The action that would normally take a domain admin minutes to execute is interrupted by an admin-gated response. The storyline, the verdict, and every tool call by the triage agent are written to an append-only audit trail before any action is taken.
Vedric is metadata-only by design. The collector enforces these limits at the source code of the agent.
Read the full privacy stance →Early access is for teams whose privileged accounts are well-controlled at the entitlement layer and want a behavioral signal underneath that PAM cannot give them.