FIG. 3The gate
illustrative values
alert
detection, trigger rows, playbook
tenant context
how this detection was decided before; what else fired on the same user or host; first-seen and baseline facts
fixed lookups when the alert fires, no model in the loop
one Jev calldecision, benign explanation, threat shape, fifteen yes/no questions0.5 s
A sharp answer: Jev closes it
1 2 3 4 5 5outcome
Service account interactive logon
svc_backup, logon type 2, BKP-01, 02:14, 02:15
  • past triage: always dismissed, nightly backup
  • svc_backup: service account, 3 years old
  • BKP-01: backup server, window 02:00-04:00
  • no other alerts on either, no external IPs
not escalated0.86 escalated0.09 missing data0.05
benign explanation
routine automation0.81
yes/no, one of fifteen
enough evidence to decide0.92
closedprobability stored next to it, 0.5 s
A flat answer: hand it to the agent
1 2 3 4 5 5outcome
New OAuth app consented by user
m.levi consents to "Mail Sync Pro", Mail.Read
  • past triage: twice, once escalated, once not
  • m.levi: regular user for 2 years, IL and DE
  • "Mail Sync Pro": never seen in this tenant
  • IP not blocklisted, no other alerts on m.levi
escalated0.44 not escalated0.38 missing data0.18
benign explanation
nothing in the context settles it
yes/no, one of fifteen
enough evidence to decide0.31
to the agent, as todayabout two minutes
flat, missing dataor, when the trigger rows name no actor or target: flag for enrichment instead of deciding
Jev never has to be right about everything. It has to know when it doesn't know.