Finds the temporary exceptions that never ended
Every security policy needs a way to say "not this time", so exceptions get granted: a firewall rule opened for a migration, multi-factor waived for a service account, an unsupported operating system kept alive for one application, a vendor allowed to connect without meeting the standard. Each is a defensible decision made by a competent person under real pressure, with an end date attached.
The end date is the part that fails. Nobody is measured on closing an exception, the pressure that created it disappears the moment it is granted, and the owner moves on. The register grows, and after a few years the organisation's real posture is its policy minus a list nobody has read end to end.
The compounding version is worse than any single entry. Three individually reasonable exceptions can combine into a path — an unpatched host, reachable from a segment opened temporarily, using an account exempted from multi-factor. Nobody granted that path. It exists because three separate approvals never met.
This agent reads the register against reality: what expired and is still in force, what is owned by someone who left, which compensating controls were promised and never implemented, and which combinations form a path. It grants nothing, changes nothing, and never asserts that anything is secure.
Because what should have closed becomes visible.
The combinations nobody approved on purpose.
What is exempt, why, and for how long.
Nobody is measured on closing one, and the pressure that created it vanished the day it was granted.
Exceptions are approved on the promise of one. It is the first thing to go unimplemented and the last thing anyone checks.
Three reasonable exceptions that together form a path. No single approver ever saw it, because no approver saw the other two.
Owned by someone who left. An exception with no owner is never going to be closed by anyone.
Your real standard is the policy minus this list, and almost nobody has ever read it end to end.
It touches no control, no rule and no register entry, and never states that anything is secure.
Why Cybersecurity in particular. Nobody is measured on closing an exception, and the pressure that created it vanishes the day it is granted. Worse, three individually reasonable exceptions can form a path no approver ever saw.
Runs unattended
Started by you or by an event, and it finishes on its own. Nothing waits for someone to be at a desk.
The same standard every time
The two-hundredth item is held to the bar the first one was. Consistency is the part people cannot sustain.
It cannot act on its own
Security Exception Auditor has no path to sending, spending or committing. That limit is why its output is safe to act on.
This agent runs server-side through the PROMIVO runtime. Each run is logged step by step and every tool call is permission-checked before it executes.
Read-only by design. This agent has no path to sending, spending, publishing or committing anything. Where that limit is the product, removing it would remove the reason to trust the output.
Demo dataIllustrative sample output, abridged.
{
"asAtDate": "2026-09-02",
"exceptions": []
}{
"escalate": true,
"noExpiry": [
"6 exceptions have no expiry date and apply to production systems. A permanent exception is a policy change that was never made as one."
],
"orphaned": [
"9 exceptions are owned by 4 people who have left. Nobody is going to close these."
],
"disclaimer": "A review of the register and records supplied. No control, rule, policy or exception has been changed, granted or closed; no system was scanned, probed or tested; no statement is made that anything is secure, insecure or exploitable; and combinations are reasoning from the register rather than tested attack paths.",
"combinations": [
{
"basis": "Reasoning from the register only. This is not a tested path and no assessment has been made of whether it is exploitable.",
"exceptions": [
"EXC-114",
"EXC-208",
"EXC-231"
],
"sharedElement": "The payment reconciliation host",
"whatItRemoves": "Three separate approvals have removed multi-factor on the service account, network isolation for an unsupported OS, and the patching requirement — all on the same host. No approver saw the other two."
}
],
"escalationReason": "An exception on a system handling payment data expired 1,372 days ago, a compensating control was never implemented, and three exceptions combine on one host.",
"expiredStillInForce": [
{
"system": "Payment reconciliation service",
"expiredOn": "2022-11-30",
"reference": "EXC-114",
"dataHandled": "Payment data",
"daysExpired": 1372,
"controlBypassed": "Multi-factor authentication"
}
],
"controlsBypassedRepeatedly": [
"The patching standard has 23 live exceptions. That is a control that does not fit the estate, not 23 separate decisions."
],
"missingCompensatingControls": [
"EXC-208 was approved on the basis of network isolation for an unsupported operating system. No isolation appears in any record. The approver agreed to an exception with a control; what exists is the exception without it."
]
}No integrations required.
What expired, what has no owner, what has no control.
What an assessor will ask about first.
Which exceptions lost their owner.
The real posture, not the policy.
$399/month
Billed monthly through your PROMIVO subscription. Cancel at any time.
Runs consume your plan allowance for agent executions and tokens. See plan limits.
No. It touches no control, no firewall rule, no policy and no register entry. Closing an exception can break a live system, and that decision belongs to the people who own it.
Never. It performs no scanning, probing or testing of any kind. It reads the register and the records you supply.
By checking whether exceptions touch the same system, account, or network path. It reports the combination and what it would allow, and states plainly that it is reasoning from the register rather than from a tested attack path.
No reviews yet. Reviews open once customers have run this agent.
Tell us what to change and our team will scope a customised version for your business.
Customize this agent