The investigation workflow

Collect the record. Reconstruct the matter. Approve the next step.

Three stages, one connected record. The workspace does the collection and the reconstruction; the decision stays with a named analyst.

01
Collect the record

Detections and related telemetry are collected into one Matter. Each row keeps the system, record reference and collection time it came from, so nothing in the Matter is a paraphrase.

  • Alerts from SIEM and EDR open a Matter on arrival
  • Identity, cloud, email and network records are collected against the same entities
  • Read-only access by default; write scopes are requested separately
02
Reconstruct the matter

Entities are connected, the sequence is rebuilt, and the evidence is grouped so a reviewer can see what is settled and what is not.

  • Known facts, contradictory evidence and unresolved questions kept apart
  • Timeline with source-stamped events and visible gaps
  • Confidence stated with the basis behind it
03
Approve the next step

Recommended steps are scoped and reversible, and they stay recommendations until a named analyst approves them.

  • Approve, request more evidence, or reject — each recorded with the analyst's name
  • High-impact actions require approval; observe-only mode is available
  • Executive brief and compliance pack are drafted from the same record

AI may collect, correlate, summarize, score confidence, and draft; every matter receives human review; AI cannot close critical matters alone.

Capabilities

What the workspace does, stated plainly.

Alert Investigation Engine

Every alert opens as a Matter with its source evidence collected and its confidence stated.

Attack Path Mapper

Entities connected into a readable path, each link naming the record that supports it.

False Positive Filter

Alerts closed as reviewed-benign with the reasoning kept and the decision reversible.

Response Recommendations

Scoped, reversible next steps drafted with their evidence attached, awaiting named approval.

Executive Incident Brief

Impact, scope, what is known and what remains unresolved — reviewed before it is sent.

Compliance Evidence Pack

Evidence, decisions and approvals exported against SOC 2, ISO 27001, PCI DSS and NIST CSF references.

Investigation Matter record

One connected record holding evidence, sequence, uncertainty and the approval history.

Investigation Operations Dashboard

Workload across the queue: what is open, what waits on review, and what has been approved.

Walk the workflow

Bring us one investigation.

We take one alert through collection, reconstruction and the approval gate, and you keep the Matter that comes out of it.