An account with a valid key can still start behaving like something else.

Nothing it does will fail a permission check. The only way to catch it is to know what it normally does, which means knowing the estate it acts on — so the register that says what you have is the same system that says what is behaving strangely.

Frequently asked questions

What can AEROSS actually stop when an account starts behaving strangely?

An agent is frozen at the gate it acts through, everywhere it acts. A person, a schedule or a device key is denied at the junction, on devices enrolled in enforce. An integration or a collector is raised to an owner and nothing is stopped — those levers are not built, and the product refuses to pretend otherwise rather than showing an actor as held while it keeps working.

How quickly does it react?

It catches a campaign over an hour rather than a single action in the instant. Detection runs on a sweep every ten minutes across the preceding hour, so a finding reaches the gate on the next sweep. It also watches writes and dispatches only — reads are not recorded in the streams it is built on.

Is it on by default?

No. It ships disarmed and you arm it one kind of account at a time. On a disarmed organisation a finding records what would have happened rather than doing it, and a kind of account with no containment lever behind it cannot be armed at all — the server refuses, not just the screen.