Each timeline below is a composite of behavioral shapes Vedric reads in the days leading up to an incident. None of these are the loud event. All four are the quiet rehearsal that precedes it. Identifying details removed. Specific thresholds stay inside the product.
This is the most common insider scenario by far. No credential abuse, no malware, no unauthorized access - just a legitimate user whose patterns quietly change in the run-up to a departure they have not yet announced. The egress is the confirmation, not the trigger.
The login is legitimate. The credentials are valid. Multi-factor was satisfied. Everything the perimeter is built to check, passed. What changes is the behavior on the other side of the door - and that behavior looks nothing like the human who owns the account.
The contractor was scoped narrowly for a specific project. Access works exactly as designed for ninety days. In the final week, the shape of how the access is used changes - not the access itself. The contract is ending; the behavior is preparing for after the contract ends.
Executives have the broadest access and the least peer-cohort signal - there are only a handful of peers, and their patterns are inherently irregular. Vedric leans on the executive’s own long-term baseline. When that baseline starts disagreeing with the present, the pattern shows even when the peer view is thin.
Early access is offered to security teams, IT leaders, and MSPs who want behavioral visibility without invasive monitoring. We review every request manually.