Stop abuse the instant it appears.
Suspend a whole user, or a single operation on a single entity such as an account or contact, in response to KYC, fraud, or OFAC signals — while still permitting chosen operations. Revocation takes effect immediately, with no deployment required.
1. Why suspension is a control of its own
Authentication and authorization decide who may do what on a good day. Suspension is the answer to the bad day: the moment a KYC review fails, a fraud signal fires, or an OFAC match appears, you need to stop the relevant activity now — not at the next release, and not by deleting the account and losing the evidence. It is the “when-to-stop” that completes the access story.
2. Granular, not all-or-nothing
A blunt block — disable the whole account — is often wrong: it punishes legitimate activity and destroys context. B5 Secure suspends at the granularity the situation demands: a whole user, or a single operation on a single entity such as one account or contact, while still permitting chosen operations. A flagged transaction can be frozen while the customer retains read access; one entity can be quarantined without taking down the tenant.
3. Instant, and without a deploy
The value of suspension is its latency. If stopping abuse requires a code change and a release, the window between detection and containment is measured in hours — the same hours an attacker uses to drain a dataset or move funds. B5 Secure makes revocation take effect immediately, evaluated in the request pipeline, so the gap between “we detected it” and “it is stopped” closes to the next request.
4. How B5 Secure handles it
Suspension is a first-class stage in the B5 Secure pipeline, fed by compliance and fraud signals and evaluated on every request. Combined with activity-data authorization, it lets an identity that begins behaving abusively lose exactly the access that matters — immediately, granularly, and auditably — without a deployment.