Section 04c · CLAD · Human Risk Layer
Insider Risk — workforce exposure
Risk originating inside the operator's payment organisation: privileged access, device posture and data movement. Distinct from customer-facing manipulation scoring.
Ecosystem Correlation
1 of 8 institutions illuminated
Staff in scope
31
mobile payments cohort
Devices enrolled
29/ 31
2 unenrolled · retail, support
DLP policies enforced
5
of 5 channel policies
Open insider alerts
0
no open cases
Workforce exposure
Cohort by role · access level · device posture
| Role | Headcount | System access | Device posture | Risk band |
|---|---|---|---|---|
| Retail channel agent | 12 | SIM lifecycle · override | 11/12 enrolled | Band 2 · standard |
| KYC reviewer | 7 | Identity records · read | 7/7 enrolled | Band 1 · nominal |
| Settlement ops | 6 | Ledger · reconcile | 6/6 enrolled | Band 1 · nominal |
| Support tier 2 | 6 | Wallet notes · read | 5/6 enrolled | Band 2 · standard |
Institution sees named staff, devices and access history. UFI sees the band per cohort.
Data loss prevention
Egress policy by channel · managed endpoints
- BlockedPersonal WhatsAppmanaged devices · outbound files
- BlockedPersonal emailcustomer-record patterns
- BlockedUSB / removableall endpoints
- MonitoredScreenshot capturerecord-detail views
- MonitoredBulk record exportthreshold 50 rows
Institution sees the blocked payload. UFI sees only that a policy event occurred.
Live · Insider signals
Insider signal feed
Streaming
- No insider signals. Advance the scenario to the retail-channel override.
Illustrative of CLAD Security's workforce human-risk capability. Not a live integration; no staff data is processed in this prototype.