SYNTHETIC INSIDER THREAT MATRIX

Protect all your insiders. Even the synthetic ones

Protect all your insiders. Even the synthetic ones

The Synthetic Insider Threat Matrix is an open, vendor-neutral framework for understanding how AI agents create insider risk. Created by Forscie with Above Theory, it gives defenders a shared language for investigating the next generation of insiders.
Real-time guidance

Guide the move.
The moment
it matters

Above steps in the instant a risky move takes shape — guiding your people to the company-approved way, before it happens. Not another alert after the fact.
Trusted by

The Synthetic Insider Threat Matrix™

The Insider Threat Matrix™ (ITM) gave practitioners a common way to describe how people create risk from inside an organization. The Synthetic Insider Threat Matrix™ (SITM) extends that work to AI agents operating with delegated human authority.
The SITM sits alongside the human-centric ITM. It sits alongside it so teams can investigate both kinds of insiders through one shared model. The patterns are familiar. The speed and scale are not.
Built by Forscie with research from the Above Theory team, the SITM is here to help you address our newest insiders: the agentic ones.
See it in action

Guidance, the moment it matters

Scroll — watch a risky prompt meet a real Above nudge in the flow of work.

Insiders aren’t exclusively human

AI agents will continue to permeate the enterprise, and they are insiders in everything but name. They can access internal systems, use delegated credentials, make decisions, and carry out work at a speed and scale no human insider could match. To achieve true insider risk maturity, the modern enterprise must account for insiders, both organic and synthetic.

Always on

An agent can take thousands of actions while a human team is still reviewing the first one.

Fully credentialed

It can inherit access to source code, customer records, financial systems, and internal knowledge from day one.

Autonomous by design

It makes non-deterministic decisions. The same instruction can produce different behavior as prompts, context, and models change.

Already inside

This is not a future workforce. AI agents are operating inside enterprises now.

Practitioner created,
community driven

STEP 1
Foundation
Forscie created and stewards the Insider Threat Matrix™, the open framework practitioners use to describe how insider harm occurs. It was built by investigators who have worked real insider cases, and it's versioned openly on GitHub.
STEP 2
Synthetic extension
Above Theory, Above Security's insider risk research group, worked directly with Forscie to create the synthetic extension. Drawing on real-world agent behavior, Above researchers built the foundation of the new categories and helped connect synthetic techniques to the established human-centric framework.
STEP 3
Inaugural sponsor
Above has been the inaugural sponsor of the ITM since early 2026, funding sustained development, community programming, and active maintenance. Sponsorship does not grant editorial control. That is the point.
STEP 4
The result
The result is the Synthetic Insider Threat Matrix: open, vendor-neutral, free to use, and designed to evolve with the practitioners doing the work.
See it in action

Operationalizing the SITM

Above turns the common SITM language into continuous behavioral investigations. Above's fleet of AI investigators connect behavior by a single person, an AI collaborator, several identities, and hundreds of automated actions to build the narrative, explain what happened, why it matters, and what to do next.
That is the difference between alerting on activity and understanding the position.
Every investigation maps to the relevant ITM and SITM categories, giving security, legal, and HR teams a consistent way to understand and act on risk.
That is the difference between alerting on activity and understanding the position.
Every investigation maps to the relevant ITM and SITM categories, giving security, legal, and HR teams a consistent way to understand and act on risk.
See it in action

Guidance, the moment it matters

Scroll — watch a risky prompt meet a real Above nudge in the flow of work.

Ready to investigate like a practitioner and lead like a CISO?

The ITM is your shared language. Above is your operational capability.

Ready to investigate like a practitioner and lead like a CISO?

The ITM is your shared language.
Above is your operational capability.
For CISOs
Audit your current stack against the Matrix and see where your gaps are.
Book a framework walkthrough
For practitioners
See how Above maps insider risk to the Matrix in real time and turns signals into investigation-ready timelines.
Schedule a demo
For researchers & community builders
insiderthreatmatrix.org — open-source, maintained by Forscie, backed by Above.
Check out the Insider Threat Matrix

Questions teams ask when comparing

What is the Synthetic Insider Threat Matrix?
The Synthetic Insider Threat Matrix is an open, vendor-neutral framework describing how AI agents create insider risk inside an organization. It extends the Insider Threat Matrix™ to cover non-human actors operating with legitimate, delegated access.
What is a synthetic insider?
A synthetic insider is an AI agent that acts with legitimate, delegated access inside an organization and whose behavior can diverge from what anyone intended. It has no motive of its own, but its actions can still create the same kinds of risk associated with a human insider.
Who created the SITM?
The SITM was created by Forscie together with Above Theory, the insider risk research group at Above Security. Forscie created and stewards the Insider Threat Matrix™. Above Theory researchers built the foundation of the synthetic extension and contributed research grounded in real-world agent behavior.
Does the SITM replace the Insider Threat Matrix™?
No. The SITM sits alongside the human-centric ITM. It connects synthetic-insider techniques to their human counterparts so practitioners can reason across both through one shared model.
Is the SITM an Above product?
No. The SITM is an open, vendor-neutral framework hosted on insiderthreatmatrix.org and available to any organization, regardless of which security products it uses. Above is a major contributor to the framework and uses ITM and SITM categories within its own behavioral investigation model. Above's sponsorship does not grant editorial control over the framework.
Is the SITM free to use?
Yes. The SITM is open, vendor-neutral, and freely available through insiderthreatmatrix.org. The ITM is published on GitHub under the Apache 2.0 license. [5] Using it does not require an Above product or customer relationship.
How does Above use the SITM?
Above maps investigations to relevant ITM and SITM categories. Its AI investigators correlate behavior across people and AI agents, assemble investigation-ready timelines, and recommend the right response, from in-the-moment guidance to escalation.
How is this different from AI security frameworks such as MITRE ATLAS? 

They address different problems. Frameworks such as MITRE ATLAS describe attacks against AI systems. The SITM describes insider risk created by AI agents using legitimate access inside an organization.
Does the SITM replace DLP, UEBA, SIEM, or identity governance?
No. The SITM complements existing controls. It gives teams a common way to classify and investigate agentic behavior that may be authorized, high-volume, or difficult to evaluate through static rules and baselines alone.
Where can I learn more about applying the Matrix in investigations?
Forscie maintains a Knowledge Center covering ITM structure, terminology, and applied investigative practice.

Every endgame starts with the right opening.

Most insider threats are preventable.
The difference is how you develop your material.
Ready to make your move?
Schedule demo

Contact us

You've made a great move.
We'll be in touch shortly

Close