The complete analyst workflow,
in one console.
Decisions come with evidence, verdicts can be overridden, and every action lands in the audit log. This page covers the full capability set, from the queue to client reporting.
Native SIEM + XDR connectors
Live alerts from your existing stack normalized into one canonical pipeline. Defender, Sentinel, CrowdStrike, Splunk, Wazuh available today. Elastic Security in Q3. Details on the Integrations page.
Evidence-backed AI triage
The model only uses the provided evidence bundle, it never invents facts. Insufficient evidence returns inconclusive, not a confident guess. Prompt version is tracked like code.
Analyst review console
Alert summary, evidence list, confidence score, recommended verdict, and override button in one focused view. Available in English and French.
Three-tier confidence bands
β₯0.75 flows to quick confirm/deny. 0.50β0.74 flags for deeper analyst review. Below 0.50 bypasses the queue and escalates immediately, no analyst bottleneck on genuine threats.
Multi-tenant isolation
Every DB query is scoped to a tenant ID at the database layer. Customer A cannot query, see, or access Customer B's alerts, cases, or reports. Essential for MSSPs.
Full audit trail
Every verdict change, override, and escalation is logged with timestamp, actor, and reason. HMAC-chained records. Searchable history for compliance and client reporting.
Weekly client reports
Automated reports showing alerts processed, top families, override rate, and tuning changes, ready to share with clients without analyst time.
Escalation routing
Escalations route to Slack, PagerDuty, email, or webhook based on per-tenant configuration. Priority support channels stay separate from low-signal noise.
SLA enforcement
A dedicated 60-second SLA watcher loop escalates cases that exceed configured response windows. No alert ages out silently.
Built around the confirm/override loop.
The console optimizes one path: from alert fired to correct decision recorded. Four views cover the whole job.
Queue
All open cases sorted by severity and SLA pressure, filterable by family, verdict, band, and connector. An analyst can clear the high-confidence tier in minutes because the evidence work is already done.
Case detail
The AI's verdict, confidence, key evidence, and reasoning next to the raw alert and every enrichment panel, IP reputation, user context, host criticality, related alerts. Confirm or override with a reason; both paths write to the audit chain.
Deterministic case notes
Closed cases get an auto-generated case note built from the structured verdict data rather than another model call. Notes come out consistent, audit-friendly, and free.
Tenant settings
Per-tenant confidence thresholds, disabled alert families, MFA enforcement, notification routing, and security policy, all self-serve, all versioned in the audit trail.
Five roles, least privilege by default.
| Role | Can | Cannot |
|---|---|---|
| Viewer | Read cases and reports | Change any verdict or setting |
| Analyst | Confirm, override, escalate cases | Manage users or tenant settings |
| Senior Analyst | Everything an Analyst can, plus deeper case actions | Manage users or tenant settings |
| SOC Lead | Run the queue: assignments, SLA oversight, team reporting | Change tenant-wide security settings |
| Admin | Manage tenant users, settings, connectors, API keys | Access other tenants |
Bilingual by design
The full console ships in English and French as first-class languages. For Quebec MSSPs and Law 25-regulated clients, analysts work in their language and client-facing reports match it.
MFA where you need it
TOTP-based MFA enforcement is a per-tenant switch. Turn it on for a regulated client's tenant, leave it optional elsewhere. Session tokens expire after 8 hours regardless.