Skip to main content

VIP Guard

VIP Guard watches your executive and privileged accounts on two sides and tells you at once when a risky change happens.

Two surfaces

On the mailbox side it checks hourly whether settings such as forwarding have drifted from the baseline. On the identity side it catches events like a new device registration or an MFA method change within fifteen minutes and emails you right away.

Inbox rules

One of the first things an attacker does after taking over an account is to plant a quiet inbox rule. Rules that forward incoming invoices to an outside address, or move alerts from your bank and security team straight to Deleted so the victim never sees them, are the most common way business email fraud hides itself.

VIP Guard reads the inbox rules of the VIPs you monitor and sorts each one into three levels. A rule that forwards outside, deletes messages, or moves any message to a hidden folder (Deleted, Junk, Archive) counts as critical; if such a rule appears later, the hourly pass catches it and alerts you right away. A rule that moves security or notification mail into a folder is usually a legitimate arrangement, so it is flagged for review. Ordinary filing rules are summarized as benign. You can open any rule in the panel to see its condition and action, and mark a rule you have reviewed as reviewed.

This analysis reads only inbox rules; it does not access the content of your email and changes no rule. It requires the mailbox-settings read permission.

What the alert says

The alert says what changed and when; who made the change (the actor) is shown only in the panel and, for privacy, is kept out of the email. The same event does not send two emails; the live layer and the hourly check are de-duplicated.

Privacy

VIP identity data such as phone and email is stored masked. Individual identity is only kept when a finding needs it, and full lists are not stored.

Who receives alerts

Every VIP Guard notification goes to the recipients you define and to the Global Administrator and Security Administrator as well. An alert therefore cannot be quietly turned off. Disabled, guest and break-glass accounts are left out of this list.

Closing a drift

You can close an open drift with dual control. You open the request, a different administrator gives the second approval, and only that VIP's baseline is updated.

Delegation discovered on a new VIP

When you start monitoring a VIP, Controlio discovers that mailbox's existing delegation structure. If the structure is empty, a single administrator's review is enough. But if the discovered structure already holds a sensitive delegation, such as send-on-behalf, send-as, full access, forwarding or an inbox-forwarding rule, confirming it as correct takes dual approval. A delegation like that could have been placed before monitoring began, and we would rather not let one person accept it into the reference. One administrator opens the request, a different Global Administrator or Security Administrator gives the second approval, and only then is the structure treated as the approved reference.