Why Lattuss
Permissions built for people, inherited by agents.
The rules across your estate assumed a person on the other end: one system at a time, one context, human speed. An agent inherits those rules and uses all of them at once.
A large estate is what a working company looks like.
Data spread across a collaboration suite, a CRM, a warehouse and a service desk is normal, and so is the way the access was built: a system at a time, for people who opened what they needed.
An admin in the directory maps to a role in the CRM, another in the warehouse, another in the service desk. Each drawn by a different team, on a different day.
That held while a person was doing the opening.
- Identity providerWho authenticated, from where, with what factor.
- Collaboration suiteIts own permissions, down to the item, correctly.
- CRMIts sharing rules, exactly as configured.
- WarehouseIts grants, for the identity that presented.
- Data posture and DLPWhere sensitive data lives, at rest.
An agent uses the whole of a permission, not the part a person walks to.
Access control was designed around a person: one context, human speed, and a fraction of the permission actually used. An agent works differently on all three.
Reach is exercised, not navigated
Permissions describe what someone can reach. People reach what they navigate to, so an entitlement to four hundred sites has meant four of them for years. Asked one question, an agent reads what all four hundred will give it. The entitlement did not change. The use of it did.
A person navigates. An agent searches.
One question crosses systems
A single request becomes eleven calls across six systems in under two seconds. Each system sees its own share of the question and answers for its own share of the estate.
That is the agent working correctly.
The join is a permission nobody granted
A name, a billing record and a ticket history are each allowed on their own. Together they are a level of access no one signed off, because no system in the chain was asked about the combination.
Each check can be correct and the result still be wrong.
The date does not move while the question stays open.
Security cannot approve what it has no instrument to measure, and the business has a date. Two ways out of that, and both are paid for.
- Hold the rolloutThe programme sits in review while the question of what an agent could reach stays open. Everyone in the room is behaving correctly.The cost is the rollout, and the advantage it was meant to buy.
- Re-permission the estate firstEvery system, owned by a different team, re-reviewed against a standard that did not exist when the access was granted.The cost is in years, in budget and in the people who leave before it lands.
Lattuss lets security say yes.
An agent acts for a person, and inherits what that person can reach. Across every system at once, that number has never been calculated. Only assumed.
- Calculate the reachRead-only across the systems an agent can call. Permissions, never content.
- Decide in the pathEach call checked against the person behind the agent, and what comes back scoped to them.
- Keep the recordWhat was asked, what was in scope, what was allowed - and where the record has gaps, it says so.
Your ceiling stops being an assertion and becomes a number.
How the answer gets built