Skip to main content
Capability

Know when a call is pushing past your controls

Map your approval thresholds, verification requirements, and escalation rules to calls in progress. Diopter flags asks that route around your controls before an exception is granted.

30 minutes with a founder. We will sign your NDA first if you want one.
$25.6M
lost when approval controls were bypassed on one call
Source · Arup, 2024
~$100M
in losses after a help desk social engineering attack
Source · MGM, 2023
The verdict

From signals to one action your team can take.

What drove this verdict
  • Approval path
    Dual approval required at this amount, single approver present
    Bypassed
  • Verification
    Callback to the number of record never completed
    Incomplete
  • Threshold
    Amount sits above the limit this approver is cleared for
    Exceeded
  • Exception
    Asked to waive a control, framed as a one-off
    Requested

Hold for policy review. The exception stays pending until the required review path is completed.

How it works

How policy scoring runs

Your thresholds are configured during onboarding, then evaluated against live calls. Diopter reports on your controls; it does not invent them.

  1. 1

    Configure your thresholds

    Your existing rules go in through the console, scoped with your team: transfer limits, dual-approval amounts, MFA and reset requirements, and who may approve what.

    Console · scoping call · per team

  2. 2

    Resolve who people are

    Roles and entitlements come from the systems that already hold them, so a question like whether this person may approve at this amount is answered from your directory rather than a list we keep separately.

    IAM and SCIM integrations

  3. 3

    Map the ask to a control

    What is being requested on the call is matched to the control that governs it, so the evaluation runs against your policy rather than a generic risk model.

    Financial and IT controls

  4. 4

    Log the exception

    Whether the control was followed, waived, or skipped is recorded with the call and its evidence, which is the trail an auditor asks for afterwards.

    Verdict · evidence · exception record

The risk

Where policy gaps are exploited

  • 01

    Urgency that makes policy feel like an obstacle

    Closing deadlines, executive requests, and emergency framing push staff to skip the verification step that would catch the fraud.

  • 02

    Approval chains that get shortened

    A dual-approval requirement or a manager sign-off disappears when the ask arrives with enough authority and pressure.

  • 03

    Out-of-channel and out-of-band asks

    Payment changes, credential resets, and access grants requested through a channel your policy does not support.

The attack playbook

How a policy bypass attack unfolds

These attacks move through a recognizable sequence. Diopter scores that sequence while the call is still in progress.

01
Authority

Authority is established

The caller claims executive status or organizational authority to frame the request as sanctioned from above.

02
Urgency

Urgency makes controls feel costly

A closing window or a critical situation reframes your approval requirements as a risk to the deal.

03
Isolation

The request moves off-channel

The ask arrives through a channel your policy does not cover, removing the normal gatekeepers.

04
Escalation

The exception is normalized

A first small bypass sets the precedent for a larger one that follows immediately after.

05
The ask

The action is taken

A transfer, a reset, or an access grant goes through on the strength of a policy exception that was never authorized.

See this run against your own approval flow.
30 minutes with a founder. We will replay a real incident end to end.
Book a walkthrough
Where it shows up

The controls people talk their way around.

Financial and IT controls fail the same way, so the same scoring applies to a transfer, a reset, and an access grant.

Financial wire fraud

Flag wires that cross approval thresholds without the required second sign-off.

Executive impersonation

Surface authority plays that push staff to bypass their normal approval requirements.

Help desk and IT support

Catch credential resets and access unlocks pushed through without the required verification steps.

Vendor payments

Hold banking-detail changes that arrive outside the verified channel your policy requires.

Why Diopter

Your controls are already written down. The problem is the call.

Nobody needs to be told that a $2M transfer requires two approvers, or that a credential reset requires a callback. The control exists. What happens is that a call makes following it feel obstructive: the deadline is today, the person asking outranks the person checking, and the exception is framed as a one-off. Diopter reads the call against the thresholds you already set and says plainly which control is being walked around, so declining is a policy citation instead of a judgment call your staff has to defend.

An attacker who knows your policies can still exploit the gap between what policy requires and what pressure delivers. Diopter closes that gap in the call.

Honest limits

What policy alignment does not claim

This capability reports on controls you own. It is deliberately not a system of record or an enforcement gate.

It reports, it does not enforce

Diopter surfaces that a control is being bypassed and routes that to a human. It does not hold the approval, block the payment, or override your workflow.

Unconfigured policy cannot be checked

A threshold nobody has told us about is not evaluated. Coverage is exactly as good as what gets configured during onboarding, and the console shows which controls are in scope.

Urgency alone is never the finding

Real deadlines are real. A flag needs the combination of an out-of-policy ask and the pattern around it, which is why a genuine rush does not trip it.

Deployment & trust

Light to deploy, clear about what runs where.

Pilot in days, roll wider through MDM, and keep sensitive call media inside your perimeter.

Deployment & trust
  • On-prem and hybrid deployments supported
  • No caller-side install
  • Bot or bot-free capture
  • Configurable retention, including ZDR
  • MDM rollout (Intune, Jamf)
  • SOC 2 Type II in progress
Walkthrough · 30 min

Walk an attack arc with Diopter.

We will replay a real incident, show the signals Diopter scored, and map the verdict your team would act on. We will sign your NDA first if you want one.

Common questions

What security and fraud teams ask first.

You configure the thresholds, required steps, and channels that matter for your team. Diopter maps calls against those rules.

A genuine urgent request does not also isolate the responder and route around your controls. Diopter flags the combination, not urgency alone.

Yes. The same pattern analysis applies to wire approvals, credential resets, access grants, and vendor changes.

No. Diopter scores the manipulation pattern, not isolated artifacts, so a normal call with real urgency does not trip it. Only the combination, an authority claim plus pressure plus an escalating ask, crosses the threshold. Your team sees fewer alerts with higher signal.

Diopter supports on-prem and hybrid deployments, with configurable retention including a zero-data-retention option. It runs with a meeting bot or bot-free, and needs no caller-side install. SOC 2 Type II is in progress.

Diopter works alongside the video and voice tools your team already uses, and rolls out through your existing MDM such as Intune or Jamf. There is no caller-side install and no change to how your team takes calls.

No. Every verdict carries a confidence level, not a flat flag, and if a call or file could not be fully checked, Diopter reports that rather than defaulting to a clean result. You can see this directly: every report from the Deepfake Detector shows the same confidence scoring behind Diopter's verdicts.