Adaptive Access

A login is a snapshot.
Access needs a live feed.

Adaptive access weighs identity trust and access risk continuously — at sign-in, and again every time a signal says something changed. At Monokee the policy doing the weighing is a flow you can open and read, not a score returned by something nobody is allowed to look inside.

Device postureNetwork & locationBehaviourThreat signalsAdaptive decisionTRUST LEVELre-read on every signalone policy · versionedContinuenobody is interruptedNarrow the scoperead, not exportStep upone more factorEnd the sessionnow, not at renewalevery outcome becomes the next input
Why it changed

Three things stopped being true

Adaptive access exists because the assumptions underneath a single login-time decision quietly stopped holding.

The session outlived the evidence

The token was issued at nine, when the laptop was patched, the network was the office and the person had just touched a passkey. None of that is still being checked at four in the afternoon, and none of it is necessarily still true. Access keeps being granted on the strength of a fact that expired hours ago.

The signals moved out of the identity system

The thing that should change the verdict is rarely produced by the identity provider. Device posture comes from endpoint management, the fraud score from an antifraud engine, the alert from the SOC, the breached password from a threat feed. Adaptive access is only as adaptive as the signals it is allowed to hear.

Monokee treats the third as the design problem. An access decision that cannot be read is a decision nobody can defend — not to an auditor, not to a regulator, and not to the person it just interrupted.

Inputs

What the decision is allowed to know

Adaptive access is an argument about evidence. These are the categories that change a verdict — and most of them are produced by systems you already run, which is why getting them to arrive matters more than the scoring logic that consumes them.

Authentication strength and age

How the person proved who they were, and how long ago. A passkey touched two minutes ago and a password typed this morning are not the same evidence, and a policy that treats them as one is not adaptive — it is just late.

Via integration

Device posture

Managed or unmanaged, patched or drifting, attested by hardware or merely claimed by a user agent string. The device is the part of the session most likely to change while nobody is looking at it.

Via integration

Network and location

Address reputation, a corporate egress that suddenly is not one, a move between countries no journey could have made in the time available. Weak evidence on its own, useful the moment it disagrees with everything else.

Via integration

Behaviour and anomaly

What this account normally does, at what hours, from what clients, at what pace — and how far the session currently running sits from that shape.

Via integration

Threat and incident signals

A credential found in a breach dump, an alert raised by detection and response tooling, a token replayed somewhere it should not be. These systems learn first; the access layer is worth nothing here unless somebody tells it.

What is actually at stake

The same account, the same device and the same risk score justify very different answers depending on whether the request reads a directory entry or moves money. Risk without stakes is only half the input.

Outputs

The answer is rarely yes or no

A control with two settings gets configured for the worst case and then relaxed until people stop complaining. A graded response is what makes it possible to be strict about the thing that matters without being strict about everything.

  1. 01

    Continue, silently

    The overwhelming majority of the time nothing is wrong, and the correct adaptive response is to leave the person alone. Friction spent where it was not needed is friction unavailable where it is.

  2. 02

    Narrow the scope

    Keep the session and take away part of it: read but not export, view but not approve, the internal application but not the payment one. A smaller session is often the proportionate answer, and it is the one most deployments never implement because their access layer only knows how to allow or deny.

  3. 03

    Ask for more proof

    Step up to a stronger factor, and only for the action that warranted it. The user gets an interruption that visibly relates to what they just tried to do, which is the difference between a control people accept and one they route around.

  4. 04

    End it

    Revoke the session now rather than declining to renew it later. The gap between those two is the window an attacker is working in, and it is measured in the lifetime of a token nobody re-examined.

Whichever one fires, the reason is recorded: which signal moved, which branch was taken, which policy version was in force. An adaptive decision you cannot explain afterwards is a liability wearing the costume of a control.

After the login

One session, re-read continuously

Trust is not a property the session keeps until it expires. It is a reading, and the reading moves while the session is still running.

HighMediumLowSTEP-UP THRESHOLDCUT-OFFSign-inpasskey, managed devicePosture dropsdevice out of policyStep-uptrust restoredAnomalysession endedone session, from sign-in to sign-out

Continuous, event-driven trust is an area the whole industry is still building out. Which signal sources a given deployment can consume today, and how quickly they arrive, is a conversation worth having with us rather than something to infer from a diagram.

Today and next

Where the capability actually stands

Adaptive access attracts more roadmap than product. It is worth being explicit about which parts are available now and which are still arriving — for us and for everybody else selling into this market.

Today

Step-up as a step in the flow

Raising assurance is a node on the canvas, attached to the application, the API or the single transaction that needs it — not a global setting that everybody pays for.

Today

Session control from outside the application

Lifetime, scope and conditions belong to the session itself, so it can be shortened, narrowed or ended without waiting for the application to ask a question again.

Today

Phishing-resistant factors

WebAuthn and FIDO2 give the top rung of the ladder something worth climbing to: a factor that a real-time phishing proxy cannot relay, because the signature is bound to the origin.

Today

Context at the point of access

Identity, device, network and policy are evaluated together where access is granted, rather than each application keeping its own drifting copy of the rules.

Emerging

Shared signals between systems

Event-driven frameworks — CAEP for continuous access evaluation, RISC for risk and incident sharing — let one system tell another that something changed, in seconds rather than at the next login. This is where the industry is heading and where most products, ours included, are still building.

Emerging

Ephemeral, per-transaction authorization

Long-lived entitlements are giving way to decisions issued for one session, or one action, and then gone. It removes the standing privilege an attacker inherits along with the account.

On the canvas

The policy is a diagram, not a black box

The branch that decides who gets asked for a second factor is drawn on the same canvas as the rest of the identity journey. You can see the condition, follow the path a session took, change the threshold and version the change.

That is the difference between adaptive access you can operate and adaptive access you can only trust. The people who own the rule — fraud, compliance, product — are the people who can read it, without asking anyone to interpret a score on their behalf.

Device postureNetwork & locationBehaviourThreat signalsAdaptive decisionTRUST LEVELre-read on every signalone policy · versionedContinuenobody is interruptedNarrow the scoperead, not exportStep upone more factorEnd the sessionnow, not at renewalevery outcome becomes the next input

Bring us a session you would have wanted to end early

We'll draw the policy that would have caught it, and tell you honestly which signals your environment can already feed it.

Talk to an expert