The AI reasons over your privileged access. It watches, it interprets, and it resolves what risk analysis gets wrong.
Augur is the AI line that runs on top of Fidwyn PAM and EPM. It scores every identity, runs SOAR playbooks over live signals, maps how far a compromised account could reach, governs non-human identities and gives administrators an assistant that performs real, audited actions. The analysis rests on Fidwyn LLM, fully owned by Fidwyn, not on a classical rule engine. At set intervals Augur returns to completed session recordings and re-scores identity risk; the score does not freeze when the session ends. The model lives in the appliance, served from your GPU; no inference call can leave your perimeter.
A SOC needs privileged access to do its job. That is exactly where security breaks.
Regulators, from banking and capital-markets authorities to defense mandates, require security operations that run around the clock, watching the estate and ready to act the moment something goes wrong. To staff it, most organizations have no choice but to hand their SOC teams privileged accounts. For anyone who has just finished a PAM and EPM programme that is a contradiction: the privilege you spent the project removing, you grant straight back to a whole team, and hardened systems start carrying exceptions again.
Augur closes the gap. It gives SOC teams standard, non-privileged access and still lets them do the real work of building detections, writing playbooks and automation, and running the whole operation without a single privileged account defined for them anywhere. When access is genuinely needed, just-in-time elevation grants it for the moment, under full audit, then takes it back, so the hardened baseline stays intact, with no standing privilege and no exceptions, and separation of duties finally holds. The engine behind it is OpenAI-compatible and self-hosted: through AirGap AI the bundled model loads onto your own GPU with no manual steps, and endpoint validation rejects any address outside loopback and RFC 1918, at configuration and at call time.
Read the data-residency postureMost security AI assistants summarize. This one acts, and it goes through the product's own controls.
Ask Augur, in plain language, to grant a contractor time-boxed SSH to one host. It resolves the user and the asset, drafts the change, and returns a preview with a signed apply token. Nothing executes until an administrator confirms. On confirmation it runs the grant through the same access resolver a human would use and writes it to the audit trail.
Illustrative. Multi-step plans substitute one step's output into the next and run only tools on a server-side allowlist.
Nine consoles, one shared AI engine.
Every capability below is a live module in the product, reading the same privileged-access signals and served by the same on-prem model.
A behavioral-risk SOC. Fused per-identity risk scores from 0 to 100, KPIs for monitored and high-risk users, a per-minute score timeline, a signal-rate breakdown and a 168-hour risk heatmap. High-risk is flagged at 75.
Every score opens a SHAP waterfall: a 50-point base rate plus the per-signal contributions that moved it, with calibrated probabilities. The analyst sees why an identity is risky, not just that it is.
Nineteen catalogued signal types, including geo change, off-hours, volume and velocity spikes, lateral attempts, beaconing, exfiltration patterns and detections read from session recordings, each mapped to MITRE ATT&CK from a locally-baked, air-gapped CTI bundle.
A visual SOAR builder. Nested boolean trigger trees (all-of, any-of, not-of) over signal type, severity, risk score, time window, role and MFA state, with wired actions: revoke tokens, force MFA re-auth, quarantine an endpoint, disable a user, notify, forward to SIEM.
Installable, cloneable templates saved as versioned YAML, grouped by standard and carrying inline compliance mappings to CIS, NIST 800-53, ISO 27001, PCI DSS, HIPAA, SOC 2 and GDPR. Test-trigger evaluates against 24 hours of real signals without touching the database.
A unified identity blast-radius graph. For each identity it computes, if compromised, how many systems are reachable and how bad that is, scored 0 to 100 by fusing Active Directory attack paths and pass-the-hash exposure, with the top path to a tier-0 sink and the trend versus the last run.
Governance for non-human and AI identities as first-class principals. Inventories agents with owner, privilege scope, 7-day action volume, MFA-bound and approval-gated state, then ranks the most-privileged and least-overseen first, putting the orphaned, over-privileged and critical at the top.
Read-only entitlement analysis across AWS, Azure and GCP, surfacing unused administrator access, long-lived keys, privilege-escalation paths and external access.
Analyst-written PDF reports per identity, with an AI narrative, confidence score and a reproducible hash, plus a multi-user summary over a chosen window, rendered server-side and downloadable for the board or the auditor.
What Augur looks like in the product.
Taken from the live product surface: behavioral risk, identity attack paths, SOAR automation and the Fidwyn LLM assistant previewing before it applies.
When the AI needs a value, it asks. It never guesses.
If your command leaves out something an action needs, Fidwyn LLM doesn’t invent it. It opens a real, typed form for exactly what’s missing, whether a text, number, select or masked password field.
Non-sensitive details like a username or hostname are lifted from the conversation and dropped into the right field automatically, in English, Turkish or French. But a secret is never parsed from prose: a credential is forced into the masked field, by policy and in code. Smart field mapping speeds the operator up; the secret never appears in the clear.
Find your most dangerous account before an attacker does.
Run Blast Radius on a copy of your environment: see which identity would do the most damage if stolen and the path an attack would take, then closes it.
