Guide

Every Move Is Permitted. The Pattern Is the Breach.

February 3, 2026 Alexandre Genest 8 min

Your most valuable data leaves on access you granted on purpose. Every individual move is permitted, so every tool you own correctly lets it through. The danger is the pattern across moves. Why this blind spot is universal and where to close it.

Every Move Is Permitted. The Pattern Is the Breach. cover image

A file gets read in one account. Minutes later, more of the same files get read, at an odd hour, by the same approved user, toward a destination that is on the allow list and almost never used for this kind of data. No rule broke. No alarm fired. The data left anyway.

Most breach analysis starts by hunting for the broken rule. Who got in without permission, which credential was stolen, which control failed. That instinct is right often enough to have built a whole industry. It also has a wide blind spot.

A large share of the data that leaves a company leaves on access granted on purpose. The user was real. The job was approved. The destination sat on an allow list. Every individual move was permitted, so every tool built to check permission correctly let it through. Nothing failed. That is the problem.

The danger was never any single move. The danger is the pattern across moves.

Every tool you own is a permission checker

Walk the stack and the shape repeats. Identity and access management decides whether this user may reach this resource. Data loss prevention decides whether this file matches a policy on this channel. Cloud posture management decides whether this configuration is allowed. Endpoint detection decides whether this process is known-bad. Each one asks a version of the same question: is this action permitted right now?

These tools answer that question well. They were built for it, and for the threat model where the attacker does something they are not allowed to do. Stolen credential, unmanaged device, misconfigured bucket, malware signature. When the wrong thing is also the disallowed thing, this stack works.

The permitted-pattern breach breaks the assumption under all of it. The action is allowed. So the answer every tool returns is yes, and yes is the correct answer to the question each tool was asked. The question was the wrong one.

What the pattern looks like

Each move is individually unremarkable. Together they are the breach.

A user with legitimate read access to a customer dataset pulls from it on a normal schedule for a normal report. Over three weeks the same user pulls a wider slice, at a different hour, toward a destination that is approved but rarely used for this kind of data. No single pull is large. No single pull violates a policy. The access was granted on purpose and used through an approved path.

Swap the actor and the story holds. A real service account doing real work starts moving data between two systems it is allowed to touch, at a volume and cadence that is new for that identity. An AI agent with a valid token starts reading across repositories it has rights to but has never had reason to read together.

The permission is right every time. Only the behavior changed. The breach is not a move. It is the shape of many moves, seen together, scored against what that specific identity normally does. No permission checker is built to see a shape. It sees a sequence of allowed actions and, correct by its own logic, stays quiet.

Why this is universal, not a niche

File this under insider threat, or under one industry, and you have made it too small. It is broader than both.

Any company that moves valuable data across cloud workloads, SaaS, user endpoints, and AI agents has granted a large surface of legitimate access on purpose. Fintech moves money and the data around it. Healthcare moves records between systems built to interoperate. Legal and accounting platforms move client data through workflows that exist to move client data. AI infrastructure hands agents broad read access so they can be useful. The more legitimate movement a business runs, the more cover a permitted-pattern breach has. It hides inside exactly the traffic everyone agreed to allow.

This does not claim everyone has been breached this way. It locates where the blind spot lives. It lives in the gap between permission and behavior, and that gap opens anywhere access is granted in advance and used over time. Which is everywhere.

Why the timing is the hard part

Teams try to close the gap in two places today. Both are off by a step.

One is to predict. Guess in advance which access will be misused, write more granular policy, tighten the allow lists. Predictive controls are wrong often. They drown teams in false alarms. And they still cannot catch the move that looks exactly like the work it imitates, because in advance it is indistinguishable from legitimate use.

The other is to reconstruct. Read the logs after something feels wrong and assemble the pattern in hindsight. Forensics can find the shape. By the time it does, the data has already left. The pattern is a disclosure letter now.

The only place to see the pattern in time to act is at runtime, while the data is moving. Not before, when the move is still a guess. Not after, when it is already a loss. During, while the shape is forming and there is still something to do about it.

Where Hilt closes it

Hilt is runtime Data Movement Governance. It watches data movement at the kernel, metadata only by default, off the path. The collector is light, on the order of 0.1% of one core and 4 to 8 MB of memory per host, single-tenant inside your own cloud. It does not sit inline, and it does not block, drop, or alter traffic. It observes the move instead of standing in its way.

It resolves each move to a probabilistic, source-dependent identity: which user or service, which job behind it, which destination, and whether this fits what that identity normally does. That resolution turns a stream of individually permitted actions into a pattern you can reason about. The user is allowed to read the dataset. The job is a known job. The destination is approved. And the shape, this identity at this volume at this hour down this rarely-used approved path, does not match how that identity normally moves data. Any one signal is noise. Together they are a pattern, and a pattern is a case, not an alert.

When the pattern is dangerous, Hilt writes the case and responds with host-level network isolation, quarantine, from the control plane. It contains the host without ever sitting between your data and where it was going. Because the default vantage is metadata, it sees that the pattern is wrong without reading your data. Content-aware inspection is there when you want it. It is never the price of admission.

What Hilt does not replace

This is a layer, not a teardown. Keep your IAM. It should still decide who may touch what. Keep your DLP and your posture. They catch the disallowed move, and the disallowed move is real. Hilt can stand in for your endpoint sensor, and many clients retire their EDR once it is in place; keep an EDR alongside only if you want the malware and intrusion layer too. Hilt does not re-answer the permission question. It answers the one underneath, the one the permission checkers were never built to ask: across all these permitted moves, does the pattern fit, and when it does not, here is the case while there is still time to act.

The blind spot is structural. Not a vendor failing, not a configuration mistake. It is what you get when every tool you own evaluates permission and the breach lives in behavior. Closing it does not mean buying a stricter permission checker. It means watching the movement itself, at runtime, resolved to the identity behind it.

To walk through how this would look against your own data movement, the next step is a 30-minute call, engineer to engineer. No deck. We will trace one real pattern and you can decide whether the gap is yours.