Alessandro AleddaInsider Threat and Risk

ArticlesWhat Holds an Insider Program Together

Four artifacts plus one, and why European rules force you to build them all.

27 JULY 2026  |  10 MIN READ

An insider program has a point where its parts are supposed to meet. Detection produces an event. Governance names a condition. HR holds the person, legal weighs the exposure, compliance checks the control. Five functions, five readings of the same case, and somewhere those readings have to reconcile into one posture. Without that, there is no program, only functions working next to each other.

Most people who run these programs know this. Some know it acutely, because they can see exactly which parts they have and which they are missing. Naming the gap is not the hard part. The hard part is the question the naming leaves open: what is that meeting point actually made of. It is not a recurring invitation or a line on an org chart. It is made of specific things, and if they are absent, the reconciliation does not happen.

There are four of them, at least. And where they are built changes what they have to be, because organizations do not assemble these parts in a vacuum. They assemble them under whatever rules govern how they may watch the people they protect, and those rules are not the same everywhere. That difference is not a footnote. Further on it turns out to be the whole point.

Event and condition#

Those readings ultimately reduce to two, and they pull in different directions long before anyone tries to reconcile them.

The first starts from the event. Something happened, or is happening: a large export, a permission changed, data moved somewhere new. This reading is fast, technical, close to the data, and it is very good at telling you what occurred. It is worse at telling you what it meant. An event is a fact without a motive attached, and the same fact fits more than one story. The same large export is a departure in progress or a deadline being met the only way the person could manage it. The event does not say which.

The second starts from the condition. Not what happened, but the state that makes something likely. Sometimes that state points toward intent: a competitor offer accepted, or a grievance that has curdled into something the person feels entitled to act on. More often it points nowhere near intent at all: fatigue that turns a routine handling of sensitive data into a careless one, workload that makes the shortcut the only way through. This reading is slower, further from the data, closer to the human context, and it is good at telling you where risk is gathering. It is worse at telling you whether anything has occurred. A condition is a disposition with no act behind it yet, and most dispositions never become acts.

Each reading is blind exactly where the other sees. The event has the act and not the why. The condition has the why and not the act. Read alone, each fails in its own direction: the event without context becomes an accusation, the condition without evidence becomes suspicion. But reconciling them is not only about resolving the single case. A case is read against the organization’s posture, what it holds, what it can tolerate, where its exposure concentrates, and that posture is in turn revised by the cases that actually arrive. The seam is where those two corrections happen: judgment about the person tested against the posture of the organization, and the posture tested against the person who actually turned up. Lose either and the program stops being coherent. It reads events it cannot place, or manages a posture no real case ever tests.

What the seam is made of#

The seam is not a state a program arrives at. It is composed of four things, and none of them is a meeting or a mandate. Each is an artifact that either exists or does not, which is the test that settles whether a program has a seam at all.

The first is a shared set of definitions. Not a glossary, but an agreement, written and signed by the functions, on what counts as an event, what counts as a condition, and what a given severity means. The hard part is not drafting it. It is getting the other functions to the table, to approve it, and then to apply it consistently once the cases start, and that is slow work, measured in months and meetings, not in an afternoon. Which is exactly why it has to be settled before monitoring begins, not after, because five functions that never agreed on what serious means will discover the disagreement in the middle of a case, and call it a process failure. It was a definitions failure, and it was foreseeable.

The second is a set of named triggers, each with an owner. Not the principle that a program escalates when things are serious, but the specific list: this condition, observed in this way, moves to this person within this time. A trigger without a named owner is a wish. An owner without a defined trigger is on call for everything and therefore for nothing. The pair is what turns intent into a route a case can actually travel.

The third is a decision record. What was examined, on what basis, who decided, what was concluded. Not for its own sake, but because a program that cannot reconstruct how it reached a call cannot defend the call, cannot learn from it, and cannot show that the same standard was applied to two similar cases. The record is what separates a judgment from a hunch that happened to be right, and it is the difference the second time a case looks like the first.

The fourth is a reporting channel: the route by which human context reaches the program from the people who are not in security. A manager notices, a colleague notices, and unless there is a way for that to arrive without becoming an accusation, it does not arrive. What the security function cannot generate on its own is that context, which is the whole reason the channel exists. It is also the one that dies quietest, since a channel nobody trusts is indistinguishable from a channel nobody needs.

None of the four keeps itself current. Each drifts as the program changes around it, and each has to be revisited on purpose rather than when something breaks.

Under European conditions#

Now place the same four things under European conditions, and each one changes shape.

The shared definitions acquire a column that does not exist where collection is permissive. It is not enough to agree on what counts as an event; the agreement has to record the lawful basis under which that event may be processed at all, in GDPR terms the Article 6 ground, and for the employment relationship whatever more specific national rules implement the Article 88 opening. A severity that no lawful basis supports is not an escalation, it is an exposure. The taxonomy stops being a shared vocabulary and becomes the record of what the program is permitted to do.

The named triggers stop being something a program grows into and become something it must possess before it starts. Where collection is permissive, a program can begin broad and refine its triggers as it learns which ones matter; the discipline arrives with maturity. Under a proportionality regime the order reverses, because purpose limitation and data minimization have to shape the program before processing begins, not be applied to it in review, and because systematic monitoring will commonly require a data protection impact assessment that is meant to precede the processing, not document it afterward. In some member states the sequence is written into labor law: Italy’s Article 4 of the Workers’ Statute requires a union agreement or a labor inspectorate authorization before tools capable of remote monitoring are put in place, subject to its own contested carve-outs, and other member states have their own versions of the same constraint. The trigger is not a filter applied to data already gathered. It is part of the design that has to support lawful processing, which is why it has to exist before the watching, not after.

The decision record stops being good practice and becomes the evidence. Accountability under Article 5(2) is not satisfied by reaching a defensible call; the controller has to be able to demonstrate that it was reached defensibly, which is a different and heavier standard. Without the record, a sound decision and an arbitrary one look identical after the fact, and the program cannot show which one it made. The reconstruction is not for learning alone. It is what stands between the program and the presumption that it acted without basis.

The reporting channel stops being an informal courtesy and becomes a regulated flow. A colleague’s observation about a person is personal data about that person, and the moment it enters the program it is being processed. Where national law governs internal reporting, the channel’s form is largely set from outside it: who may see what, how long it is kept, and what protection the reporter is owed. The component that depends most on trust is the one whose shape is least in its own hands. That is a tension to manage, not a problem to solve.

Take those four changes together and a fifth thing has to exist that a permissive regime never forces into the open. Each of the first four now carries an external commitment: a lawful basis recorded, a justification that precedes the watching, a standard of proof for every decision, a channel whose shape was agreed outside security. Somewhere those commitments have to be gathered, written down, and stated as one account, because scattered across four artifacts they cannot be shown to anyone. That account is the declared perimeter: what the program does, what it does not do, and on what authority, consolidated into the single document a regulator, a works council, or a court would actually ask to see. Elsewhere the four caveats are lighter and stay implicit, so nothing forces their sum to be declared. Here the declaration is the artifact.

Named plainly, it can look like a compliance formality. It is not, because it is the only place the four commitments are reconciled with each other. The perimeter is worth having only if it is done properly: negotiated in good faith, specific about method and not just intent, and honest about what the program can see. One written to satisfy an auditor commits the program on paper to a shape it does not hold in practice, and the distance between the two is itself a finding.

And because it rests on the other four, it cannot sit still. Change any one of them and the declaration is already behind: a new data source moves the lawful basis under the definitions, a new capability shifts what the triggers reach, and the perimeter that described the old sum no longer describes the new one. The other four can each reach a settled state on their own. Their declared sum cannot, because something underneath it is always moving. Keeping the account aligned with what the program has become, so that authority keeps pace with capability, is not a lapse to apologize for. It is a continuous function of running the program, and it depends on parties who are not in the room when a capability ships. The perimeter is the standing obligation to keep a living program honest about itself to people who did not build it and do not answer to it.

The five artifacts
WHAT THE SEAM IS MADE OF

The constraint#

Step back from the five and the shape of the argument is visible. Every one of them is heavier under European conditions than where collection is permissive. The definitions carry a lawful basis, the triggers precede the watching, the record has to prove and not just persuade, the channel is not the program’s to shape alone, and the declared perimeter has to gather all four into one account and keep it current. It would be easy to read that as a catalogue of disadvantage, the constrained program laboring under weight a freer one is spared.

It is closer to the opposite, and to see why, go back to what the seam was for. A program grows out of one of two places. It begins in the SOC, close to the signal, fast at the event and blind to the condition. Or it begins in governance, close to the posture, fluent in the condition and far from the event. Neither is a program yet. It becomes one only when the two are sewn together, and the five artifacts are the stitches: the definitions and the record pull the operational reading toward the institutional one, the triggers and the channel pull the institutional reach back down to the signal, and the perimeter holds the whole thing accountable for what it has become.

Where collection is permissive, that sewing can be left implicit. The SOC keeps running events, governance keeps writing policy, and the two can sit adjacent for years, each calling itself the program, until an incident lands in the gap between them and reveals there was never a seam at all. The constraint removes that option. It does not ask for more than a serious program would build on its own. It only makes the stitching impossible to skip and impossible to postpone, and in doing so it forces the one thing that turns a service and a function into a single program. That is a harder way to begin. But the sewing is what a program is; until it happens, an organization has capable parts and the intention to connect them, which is the stage most programs pass through and some stay in. The constrained one is made to build the seam before it opens. It starts slower, and it starts whole.