Record
Capture the accountable official, purpose, limits, term, protected boundary, and required evidence in a versioned authority record.
Explore the platformRecords an official's decision with its purpose, limits and evidence, then tests what happened against that record.
See the evidence walkthroughYou have the ticket. You have the account. But when an auditor asks who granted the authority, whether it was still valid, and whether execution stayed inside it, the answer is scattered across systems that were never designed to agree.
Cerydora connects the decision to the evidence—and preserves the basis for human review.
The operating arc
Capture the accountable official, purpose, limits, term, protected boundary, and required evidence in a versioned authority record.
Explore the platformNormalize what directory, cloud, delegation, and execution sources report without letting a collector decide what the facts mean.
Inspect the evidenceSeal the conclusion with its sources, timing, and coverage limits so a third party can inspect the record without the engine.
See offline verificationPlatform
Declared authority remains the standard. Evidence sources report what they saw; Cerydora reconciles those facts and routes consequential judgment to accountable people.
Shows what each governed service account, workload identity, bot, or AI agent was authorized to do versus what it was observed doing—across on-prem Active Directory, Entra ID, and supported activity sources.
Surfaces dormant, ownerless, over-privileged, and revalidation-required states where the evidence supports them.An open, signed evidence package with declared authority, evaluated conditions, source references, integrity material, and explicit coverage limits—the artifact an examiner receives.
Checks format conformance, payload integrity, signature validity, and issuer trust as four separate results, without contacting the engine or a network service.
These checks cover the package. Source truth and legal sufficiency require separate review.Ties each authorization to an immutable directory identity instead of a reusable username, then records when that approving principal is disabled or deleted.
What the record shows
Every evaluated condition lands in a closed disposition, with the evidence and timing behind it. The outward package can be curated without exposing internal working state.
Honesty rule: no evidence is not evidence of conformance. If an instrument stops reporting or evidence becomes stale, the record says so.
Agent operations / departed approver
Internal operator view, as rendered for the synthetic corpus. The examiner projection withholds these determinations and says so. Names, identifiers, and evidence are fictional.
Four separate results; no aggregate “verified” verdict. Issuer trust is not established for the self-presented demonstration identity.
cerydora-verify <bundle> · no network.
Exit 0: format PASS, integrity PASS, signature VALID, issuer trust not MISMATCH. Issuer trust may still be NOT ESTABLISHED. Exit 1: verification failed. Exit 2: unreadable or structurally nonconforming input.
Crosswalk by reference
Framework identifiers travel with the authority record. Cerydora reproduces no control text, claims no certification, and does not decide whether a control is met.
Offerings
Each engagement starts with a named operation and a limited set of actors. The aim is usable authority evidence, not another abstract governance program.
A fixed-price engagement to record, observe, and preserve accountable authority for a named set of AI systems and non-human actors.
Request the scopePut an agency or business AI policy in place, connect it to named decisions and evidence, and define how exceptions reach an accountable human.
Discuss a policy stand-upWork the non-human-actor authorization queue on retainer, with reviewer-role templates and request handling for cases such as app-registration admin consent.
Review the operating modelControl-by-control evidence for Rule 60GG-2's identity, authorization, and monitoring subset, shaped for the July 31 gap assessment and the triennial risk assessment.
Review the named subsetFlorida public sector · 60GG-2 Evidence Pack
Trusted AI for a more resilient public sector
Every Florida agency head files a strategic and operational plan with the Florida Digital Service by July 31, including a gap assessment against Rule 60GG-2, and re-authorizes systems through a triennial risk assessment. The named identity, authorization, and monitoring subset is PR.AC-1, PR.AC-4, PR.PT-1, PR.IP-7, DE.CM-3, DE.CM-6 and neighboring identifiers.
The Cerydora 60GG-2 Evidence Pack generates control-by-control evidence from recorded authority and observed activity: what each human and non-human actor was authorized to do, who granted it, whether it was still valid, and whether execution stayed inside it. Output is shaped for the July 31 gap assessment, the risk assessment's authorize-and-monitor steps, System Security Plan authorization-boundary sections, and after-action reports — each artifact signed and verifiable offline.
Coverage is the identity, authorization, and monitoring subset. It does not replace the agency's plan, training, network controls, or the information security manager's judgment.
Latest
The NHA Ledger leads with one question for every service account, workload, and agent: is a current human authorization on record? Attested, unattested, no active authorizer, or not evaluated—each with its reason, and never a blank.
Product noteFormat, integrity, signature validity, and issuer trust stay separate. The verifier needs no engine connection and never turns missing trust into a clean result.
Product noteOther systems enforce or infer authority. Cerydora proves who granted it, whether it was still valid, and whether execution stayed inside it.
Field noteCompany
Cerydora is founder-led and based in Florida, built by practitioners who have run identity, endpoint, and compliance programs inside regulated public-sector environments.
hello@cerydora.comOperational boundaries
Cerydora never approves an activity. It makes the responsible person's decision precise, durable, and checkable.
Evidence sources do not grade themselves. The declared authorization remains the standard.
Silence, gaps, and stale observations are recorded as such. They are not treated as evidence that the boundary held.
Internal detail stays separate from curated evidence views, while omissions and coverage limits remain explicit.
A fully synthetic Cascadia corpus with 2025 source dates runs end to end: authorizer lifecycle and execution receipts reconcile as governed ledger records; internal views distinguish binding outcomes, authorizer currency, execution-continuity findings, and cases not evaluated; the served read-face exports in internal and examiner modes; and the offline verifier checks proof-bundle format v1.
Cascadia demonstration
Trace one authorization from the approving official through the day the directory deleted their account, the receipts the actors kept producing, and the four separate offline verification results.