Eight IO domains. One operating picture.
These are not products with separate logins. They are the eight domains IO correlates across, each with its own signals, its own playbook library, and its own verification measures.
Pick the one that is on fire this quarter.
Human Risk
Are people making safer decisions, and is the culture and training supporting it?
Observed behaviour, reported culture and completed learning held as one position, and re-measured on the behaviour, not the completion record.
Cohort click rate on unseen lures
Threat Detection
Would we actually see it?
Detections that arrive from tooling rather than a colleague's message, and where the identity pressure is actually landing.
Share of detections that were tool-led rather than person-led
AI Governance
What AI is in use, sanctioned or not, and what is it exposed to?
Which AI tools are really in use, what data reaches them, and whether the written guardrails are the ones in force.
Share of AI usage running through sanctioned paths
Policy & Governance
Is policy current, known, and actually enforced?
Each policy statement tied to evidence that it holds in practice, not to the date it was last approved.
Policies past review date
Resiliency
Can we detect, contain and recover, and does it hold under repeat?
Whether the organisation can still do the thing its continuity plan says it can do, under repeat.
Time to restore the named process in exercise
Assurance & Compliance
Can we prove the controls work?
Control evidence assembled from work that actually happened, dated, and traceable to the playbook that produced it.
Controls with current, dated evidence
Third-Party Risk
What have we imported, and does the vendor's rating match how their accounts actually behave here?
The disagreement between a supplier's external rating and how their identities actually behave inside your estate.
Rating coverage and freshness across the supplier base
Physical Security
Does the physical estate hold when it is tested?
The estate treated as a measured control surface: who actually entered, whether the door held, and whether the last remediation stayed in place.
Stale physical access revoked, and whether it stayed revoked
Every domain ends with the same question.
Whichever domain you start in, the loop is identical: correlate the signal, prescribe a gated playbook, capture the baseline at approval, execute, and re-measure. IO reports the result even when the result is that nothing moved. That is the whole differentiator.
Open the domain that is on fire this quarter.
The demo carries every domain scored from evidence, so you can read your own worst one first.