Skip to main content

Is This Person Who They Say They Are, Doing the Job You Hired Them For?

State-linked operatives are getting hired into remote technical roles under fabricated identities. Crogl ties the identity record from hiring to access and activity data, so the question gets asked again after day one.

Crogl handles the investigation. The analyst makes the call.

The hiring check happens once. The access happens every day.

The FBI, State Department, and Treasury have warned repeatedly since 2022 that North Korean IT worker schemes place operatives in remote engineering, IT, and data roles at Western companies. Resumes and video interviews can be faked or proxied. The strongest signal, access that doesn't fit the role, shows up months later in a different system owned by a different team.

2022

First joint FBI, State, and Treasury advisory on DPRK IT workers, updated through 2025

Months

How long after hire the strongest signal, out-of-role access, tends to surface

2 teams

HR security and the SOC each hold half of the evidence

One question, asked at hire and every day after.

1

Identity Record Resolved

Crogl pulls the identity and corroboration records you already hold for the employee under review, alongside their access grants.

2

Access Checked Against the Role

The knowledge graph links the person across your identity provider, SIEM, and ticketing, then checks access and activity against what the role requires.

3

Evidence Assembled for Review

An identity mismatch or an out-of-scope grant is worth a look. Both together make a stronger case. Either way the analyst gets the evidence, and the analyst makes the call.

Watch an insider threat investigation, end to end.

One Workflow for HR Security and the SOC

The identity question and the access question get one auditable answer.

Rechecked for the Whole Tenure

Run the review at hire, at 90 days, or whenever access changes.

Identity Pivots Across Systems

The knowledge graph follows one person from email to identity provider to ticketing without schema normalization.

Stays Inside Your Boundary

Personnel and access data never leave your environment, which matters when the subject of the review may be on your network.

SplunkMicrosoft SentinelCrowdStrikeServiceNowJiraDatabricksSnowflakeAmazon S3

“Who they said they were. What they have access to. One answer.”

Frequently asked questions

Does Crogl replace background checks?

No. Crogl works with the identity and corroboration records you already hold from hiring, and correlates them with access grants and activity data. The knowledge graph links the person across your identity provider, SIEM, and ticketing, then checks access against what the role requires. The review can run at hire, at 90 days, or whenever access changes.

Can Crogl use interview and deepfake detection data?

Yes. Deepfake detection partners such as Reality Defender feed their findings into the Crogl investigation through a connector. Those findings sit alongside identity records, access grants, and activity data, so an identity mismatch and out-of-role access can be weighed together. The analyst gets the assembled evidence and makes the call.

Would you know if a remote hire's access stopped matching their job?

We'll show you how Crogl connects identity records to access and activity across your stack, inside your environment.

Deployed in air-gapped federal environments, critical infrastructure, and Fortune 500 financial institutions.