Open vs contained
Click a slice to drill into the cases behind it
NIST phase distribution
Where the active caseload sits
Detection & response trend
Twelve weeks, derived from case timestamps
ATT&CK coverage summary
70% average technique coverage · 7 techniques below 60%
Connector health
Simulated sources the agent consumes — it never replaces them
Residual risk trend
Composite of open findings, exposure and incident load
Now
30
4 weeks ago
40
Compliance flags
Generated views only — no filing is performed
Grid Operator Security Directive (synthetic)
Grid Operator Security Directive (synthetic)
Internal Control Standard NW-SEC-14
Internal Control Standard NW-SEC-09
Customer Data Handling Policy (synthetic)
Outcomes
What the governed agent changed
Faster detection
MTTD down from 45 to 16 minutes
Analyst productivity
64% of low/medium work automated
Consistent response
3 destructive actions held at the gate right now
Risk reduction
Residual risk 58 → 30
Audit trail
Everything the agent saw, decided and executed
Decision Gate · INC-2046 · Insufficient evidence confidence (0.66) — monitoring raised instead
Response Agent · INC-2041 · Enrichment, log collection, ticket created
Decision Gate · INC-2041 / ACT-ISOLATE · Approval requested from Authorized Approver
Risk Assessment Agent · INC-2041 · Score 81 → Critical
ATT&CK Mapping Agent · INC-2041 · T1566.002, T1078.002, T1059.001, T1003.001
Evidence Correlation Agent · INC-2041 · Incident created, severity Critical
CISO / SOC Manager · INC-2042 / ACT-BLOCK-IP · Approved — 24h TTL deny rule
Response Agent · INC-2044 / wipe-and-reimage · Refused: action not on the response allowlist
On-call Approver · INC-2044 / ACT-ISOLATE · Approved — executed via scoped EDR API
Reporting Agent · INC-2045 · Closed-Benign with rationale retained