Different actors. Same movement out.
A departing employee, an AI agent, and a user pasting into a personal model account look different in policy tools. At runtime they create the same evidence: a permitted identity reads data, stages it, then sends it somewhere that person or job normally does not.
Three forms of one problem
| Actor | Surface | What changes |
|---|
| Human insider | Shell, browser, sync client, or removable media | The identity, timing, volume, or destination no longer fits the person's work |
| AI agent | Cloud workload, MCP server, endpoint process, or pipeline | The job touches a new dataset or opens egress outside its established task |
| Shadow AI | Browser or desktop application using a personal account | A sensitive read becomes an upload to an unsanctioned model destination |
How Hilt catches the sequence
Hilt watches data movement at the kernel across Linux workloads and macOS endpoints, off the path and metadata-only by default. It resolves movement to the human or non-human identity, process, workload, and job, then scores the read, stage, and send as one sequence. A finding carries the paths, volume, timing, and destination that made the movement abnormal.
Rules cover what must never happen. Behavioral detection catches what nobody predicted. With response enabled, Hilt can alert through Slack or email, block a supported endpoint transfer, or quarantine a cloud host at the network.