The four parts
| Part | Meaning |
|---|---|
| Verdict | benign, malicious or needs a person. |
| Confidence | A number from 0 to 1. Thresholds for automation are set per playbook. |
| Recommendation | The next step in the platform's vocabulary: close, escalate, isolate, ask. |
| Evidence grade | A letter for how much of the cited evidence is actually about this alert and entity. A grade of A means the reasoning stands on the alert's own events; a low grade means the summary leans on general knowledge or on loosely related events. |
The grade exists because a confident verdict on thin evidence is the dangerous case. Read the grade before the summary.
The summary
Below the four parts is a short plain-language summary of what happened and why the verdict follows, with the events it relied on linked. Every linked event opens in the Logs page.
What the workflow ran
The AI tab lists the steps the bound playbook executed before the verdict: enrichment lookups, correlation results, the investigation agent's queries. You can see exactly what the model was given.
Acting on it
- Agree: close or escalate with your disposition. Your choice is recorded as agreement.
- Disagree: choose a different disposition. Your choice is recorded as disagreement, and the rule inspector's "AI agrees" figure moves.
- Uncertain: the verdict is advice. Investigate as you would without it.
Deterministic verdicts
Without a configured model, the verdict block shows the deterministic result: the rule's severity, the enrichment hits and the correlation membership, labelled as deterministic.