Data left, and nothing fired. The first instinct is to fix the rules. Tune the DLP policy. Lower a threshold. Add the destination to a watchlist. Write the detection that catches this one.
The instinct is reasonable. It is also wrong. It reads a missed exfiltration as a rule that was almost right, one tuning pass away from correct. Usually there was no rule to tune. The data left on access you granted on purpose, through a channel you approved, on a credential that was supposed to have it. Every individual move passed because every individual move was supposed to pass.
So tuning has nothing to grab. Tuning sharpens the tools you already own, and the thing you are missing does not live inside any of them. It lives in the seam between them, in a question none of them was built to ask. That is not a configuration problem. It is an architecture problem.
Every move is permitted; the pattern is the breach
Your most valuable data rarely leaves through a hole in the wall. It leaves through the door, on a credential that was issued, toward a destination that was reachable, in a volume any single transfer would justify.
A researcher pulls proprietary code through an approved transfer job. An integration reads patient records it is entitled to read. A service account exports from a warehouse it is allowed to query. Check any one against policy and it passes. It passes because it should. The permission was correct when you granted it, and it is correct right now.
The danger is not in any single move. It is in how the moves line up. A job runs at an hour that job never runs. An identity reads paths it has never touched, in a window too short for a human, toward a destination it has never sent to. Each step is permitted. The sequence is the theft. That is the sentence your stack cannot read, because nothing in it owns the sequence.
Why the pattern has no owner
Walk the layers and the gap opens in plain view.
Identity and access tooling answers one question. Is this principal allowed to do this thing. When the answer is yes, the work is finished. It does not watch what the principal does after the allow. It was never built to.
DLP and the predictive tools sit at the application layer and guess in advance. They match content against patterns, classify documents, flag the obvious upload to personal storage. Loud and early, which means wrong a lot, and the permitted move still slides past. There is no pattern to match. The document was supposed to move, by that user, on that day.
Endpoint and network controls each watch their own slice. The endpoint agent knows what ran on the host. The network control knows what crossed the perimeter. Neither one ties the move back to the identity behind it and the job that issued it. Neither one carries the history of how that identity has moved data over the last six months.
Detection and response tells you after. It is forensics. By the time the case is written, the data is gone and the deliverable is a disclosure letter.
Every tool is good at its own question. None of them owns the question that spans all of them. Across these permitted moves, by this resolved identity, does this pattern fit how the data actually moves here. That question lives in the seams between products, and seams have no owner. That is the structural gap. You cannot tune your way to an answer no tool in the stack was built to produce.
Why tuning cannot reach it
The reflex is strong and the budget is usually sitting right there, so be precise about why more configuration does not help.
Tuning moves a line inside a tool. It changes a threshold. It does not change what the tool observes or the question it asks. A DLP policy tuned to perfection still grades content and permission, one move at a time, with no memory of how this identity behaved last Tuesday. An access policy tuned to perfection still answers allow or deny at the moment of the grant, then goes silent the instant it says allow.
Sharpen each tool at its own job and the gap holds, because the gap is not inside any of their jobs. The gap is the absence of a vantage that sees movement across the permitted layer, resolves each move to a real identity and the job behind it, and scores the pattern against how that identity has actually behaved. No threshold produces that. It is a different architecture, not a tighter setting.
The vantage that closes it
To judge the pattern across permitted moves, watch the moves themselves, as they happen, at a layer below the application where every move has to show up. That layer is the kernel.
Hilt watches data movement at the kernel, metadata only by default, off the path. One lightweight collector runs single-tenant inside your own cloud and observes the move instead of standing in it. It costs on the order of 0.1% of one core and 4 to 8 MB of memory per host. It does not sit inline. It does not block, drop, or alter traffic. It does not have to read your data to do its work. Content-aware inspection is there when you want it, never the price of admission.
Every move resolves to a probabilistic, source-dependent identity. Which user or service. Which job behind it. Which destination. Whether this fits what that identity normally does. That resolution is the thing the seams between your other tools never carry, and it is what turns a stream of permitted moves into a pattern you can actually judge.
When the pattern is wrong, the signals arrive together. The job is unusual for that identity. The read is a bulk pull of high-value paths in a short window. The volume is unusual for that channel, approved or not. Any one of those alone is noise. Stacked, they are a case, not an alert. Hilt writes the case and responds with host-level network isolation, quarantine, from the control plane. The collector stays off the path the entire time.
What this does not change about your stack
This is a layer that can also stand in for others. Your identity tooling still answers the permission question, and it should. Your DLP still catches the careless upload to personal storage. On the endpoint, Hilt can stand in for your endpoint sensor, and many clients retire their EDR once it is in place; keep an EDR alongside only if you want the malware and intrusion layer too. Your network controls still cover the slice they were built for.
What it adds is the missing owner. A vantage on the pattern across permitted moves that none of those tools was built to hold. It answers the question they were never asking, and on the endpoint it can carry the data movement work your sensor was doing on its own.
The next time data leaves and nothing fires, hold off on the reflex to go tune. Ask whether anything in your stack ever owned the pattern across those moves. If the honest answer is no, the fix is not a sharper rule. It is a vantage you do not have yet.
If that is the question you are sitting with, the useful next step is a short, engineer-to-engineer call. Thirty minutes, where we walk through where a kernel-level collector would sit in your environment and what the pattern looks like once each move resolves to the job behind it.