Triage verdicts

How to read the advisory verdict on an alert: verdict, confidence, recommendation, evidence grade.

The four parts

PartMeaning
Verdictbenign, malicious or needs a person.
ConfidenceA number from 0 to 1. Thresholds for automation are set per playbook.
RecommendationThe next step in the platform's vocabulary: close, escalate, isolate, ask.
Evidence gradeA letter for how much of the cited evidence is actually about this alert and entity. A grade of A means the reasoning stands on the alert's own events; a low grade means the summary leans on general knowledge or on loosely related events.

The grade exists because a confident verdict on thin evidence is the dangerous case. Read the grade before the summary.

The summary

Below the four parts is a short plain-language summary of what happened and why the verdict follows, with the events it relied on linked. Every linked event opens in the Logs page.

What the workflow ran

The AI tab lists the steps the bound playbook executed before the verdict: enrichment lookups, correlation results, the investigation agent's queries. You can see exactly what the model was given.

Acting on it

  • Agree: close or escalate with your disposition. Your choice is recorded as agreement.
  • Disagree: choose a different disposition. Your choice is recorded as disagreement, and the rule inspector's "AI agrees" figure moves.
  • Uncertain: the verdict is advice. Investigate as you would without it.

Deterministic verdicts

Without a configured model, the verdict block shows the deterministic result: the rule's severity, the enrichment hits and the correlation membership, labelled as deterministic.