A trusted software build and release path distributed compromised updates to downstream customers who accepted vendor-supplied software into their environments. Detection and prevention of supplier compromise remain responsibilities of the wider security and assurance environment.
Within a customer environment, a customer might Permit approved monitoring, Defer production changes, require independent authority for authentication or logging changes, and Block privileged identity creation or selected external data movement, where those actions pass through integrated authority checks. When the supplier or product is under investigation, the customer can apply tighter conditions to selected connected actions where Authority Control is integrated.