Curated demo content by default.
The /demo route group is a public demonstration surface. Its stories, report packs, and portal views are intentionally curated unless a live tenant is explicitly selected.
Current route truth
Preview-grade detection outputThe public route exists now and demonstrates detection-and-response storytelling; it remains preview-grade demo output rather than a live SOC feed.
Strongest first view
Open BoardStart here when you need the strongest first commercial story: risk, consequence, funding decision, and executive ownership.
This TDR report is a synthetic public demo surface. It is intended to show representative response and detection storytelling, not to imply guaranteed detection, full verification, or identical live-portal delivery on every authenticated route.
Demo truth model
Persona switching, posture, blast radius, and remediation delta are anchored to real platform/runtime contracts.
Identity-led threat narrative, time-to-impact, AI confidence, and automation-vs-manual response framing.
Report credibility
Every field is shown explicitly. Items not yet provided are labelled (Roadmap, Unavailable, Not applicable, Missing) rather than hidden.
Demo seed — period derived from synthetic profile, not live tenant telemetry
Reference IF-TDR-RUN-MRI-
No prior version to diff — the public demo regenerates deterministically per request.
Named report owner is captured in webapp tenant scope settings — surfaced once a tenant is provisioned.
Approver sign-off block lands with the Audit / PBC workspace milestone.
Substantia signed-evidence chain is exercised in the authenticated webapp, not in the public demo route.
This is not a loose collection of anomalies. It is a linked identity threat story with a likely time-to-impact of 6 hours and 69% confidence based on correlated path and telemetry evidence.
Initial access begins at acme.user.jane.doe (Okta, standard analyst, no phishing-resistant MFA), then pivots through Okta, Entra ID, AWS IAM.
The path remains realistic because the supporting control weaknesses already exist: Okta: push-based MFA (not FIDO2) for analyst cohort is susceptible to MFA fatigue attacks; Entra CA: CA-FederatedSessions lacks step-up requirement for Okta-sourced tokens.
The decision point is whether to contain automatically now or accept a shorter analyst reaction window while the path remains live.
1,247
Suspicious Logins
6
Confirmed Incidents
42
High-Risk Anomalies
User logged in from UK and Singapore within 3 minutes
Service account attempted role elevation outside baseline
OAuth token reused across multiple IP addresses
3
Linked Incidents
14
Systems Affected
62
Resources Accessible
6h
Time to Impact
69%
AI Confidence
Blast radius: Attack path linked to 3 confirmed incident(s), affecting 14 systems and 62 accessible resources.
Automated containment
Disable exposed identity, revoke active sessions, and apply conditional access lock within minutes.
Analyst-led fallback
Validate the path manually, coordinate owners, and sequence account, token, and policy changes across several handoffs.
Preferred mode
Automate first, then review exceptions.
Password reset + session revocation
Forced password reset · 15/03/2026, 14:32:00
Disabled affected service account
Account disabled · 15/03/2026, 14:35:00
Triggered conditional access lockdown
CA lockdown · 15/03/2026, 14:40:00
No alerting on lateral movement via trusted federation
High PriorityLimited visibility into SaaS-to-SaaS identity flows
Medium PriorityTDR Report · Prepared by IdentityFirst Ltd · Prepared for Acme Corp · Ref IF-TDR-RUN-MRI- · v1.0 · Confidential - Demonstration Use Only · SAMPLE - SYNTHETIC DATA - NOT FOR DISTRIBUTION