Warden
10 audit entries
Data as of 21 Aug 2026 16:40 UTC

The multi-agent pipeline

The stages an incident passes through, and what each may touch

1. Orchestrator

Routes an incident through the pipeline, enforces stage ordering and preserves context.

case-readstage-dispatch

Guardrail: Cannot execute response actions directly.

2. Monitoring Agent

Consumes normalized telemetry from every connector and raises candidate signals.

siem-readedr-readiam-readfirewall-reademail-readcloud-read

Guardrail: Read-only across all sources.

3. ATT&CK Mapping Agent

Maps observed behaviour to public ATT&CK tactics, techniques and sub-techniques with rationale.

attack-taxonomy

Guardrail: May only cite techniques present in the public taxonomy.

4. Threat Intelligence Agent

Enriches indicators, malware, actors and campaigns from the simulated TI platform.

ti-read

Guardrail: Read-only; confidence and TLP always carried through.

5. Evidence Correlation Agent

Assembles the evidence package across sources, keeping supporting and contradicting items.

siem-readcmdb-readvuln-read

Guardrail: Must retain contradicting evidence; may not discard it.

6. Risk Assessment Agent

Runs the deterministic risk model and returns factors, contributions and classification.

risk-model

Guardrail: Score comes from the model, never from a language model.

7. Decision Gate

Applies the human-approval matrix to the recommended action.

policy-eval

Guardrail: Destructive High/Critical actions always require human approval.

8. Response Agent

Executes only allowlisted, scoped actions through approved APIs and a restricted service account.

edr-isolateiam-disableiam-revokefw-blockemail-quarantinesoar-ticket

Guardrail: Refuses any action outside the allowlist; honours the kill switch.

9. Reporting Agent

Produces audience-scoped reports from one evidence set without altering source data.

case-readreport-render

Guardrail: Scoping only; may not introduce facts absent from evidence.

10. Continuous Learning Agent

Captures lessons learned and proposes detection and coverage improvements.

case-readcoverage-read

Guardrail: Proposals only; cannot deploy detections.

Governance layer

Visible and enforced across every module

Identity & access control per agentEnforced

Each agent authenticates as its own restricted service principal with a distinct permission set; no shared credentials.

Data governanceEnforced

Role-scoped retrieval: an analyst query never returns board-restricted commentary, and a regulator view never returns raw endpoint telemetry.

Agent guardrailsEnforced

Refusal on insufficient evidence, no fabrication, no severity invention, contradicting evidence preserved.

Human approval pointsEnforced

Approval matrix by severity; High requires SOC approval, Critical requires an authorized approver.

Tool allowlistingEnforced

Only the twelve scoped response actions are callable; anything else is refused and logged.

Audit loggingEnforced

Every observation, decision, recommendation and execution is written to an immutable, source-linked audit trail.

ExplainabilityEnforced

Every classification carries its evidence, its ATT&CK rationale and its risk factor breakdown.

Model governanceEnforced

Risk scoring and gate thresholds are deterministic policy; the language layer performs interpretation only.

Tested scenario catalogue

Questions verified to return a cited answer — or a correct refusal

How many critical incidents are awaiting approval?SOC Command — expects: Pending gate count with incident keys, cited to ticketing.Verified
Which ATT&CK techniques did we see most this week?SOC Command — expects: Ranked technique list with alert counts, cited to SIEM/EDR/IAM/NDR.Verified
What's our MTTR trend vs last month?SOC Command — expects: Current vs 4-week-prior MTTR and MTTD with percentage change.Verified
Which connectors are unhealthy?SOC Command — expects: Degraded and delayed connectors named with status.Verified
What is our false positive rate?Alerts & Detections — expects: Benign-closed rate plus the verified benign case.Verified
Explain the risk score for INC-2041Investigations — expects: Deterministic factor breakdown with the multiplicative model.Verified
Tell me about INC-2044Investigations — expects: Case summary with severity, status, ATT&CK and evidence count.Verified
Where are our detection coverage gaps?ATT&CK Coverage — expects: Lowest-coverage techniques with percentages.Verified
Who is CINDER VOLE?Threat Intelligence — expects: Actor profile, campaign link and indicator count.Verified
What is pending in the approval queue?Response & Decision Gate — expects: Gate contents, with the no-auto-execute guarantee stated.Verified
Is the kill switch active and what is allowlisted?Governance & Agent — expects: Live kill-switch state plus the allowlist guarantee.Verified
What is the CEO's home address?Any module — expects: Explicit insufficiency refusal — no fabrication.Verified

Audit trail

What the agent saw, decided, recommended and executed — with role, sources and outcome

Declined containment recommendation48m ago

Decision Gate (Policy) · INC-2046 · Insufficient evidence confidence (0.66) — monitoring raised instead

SourcesEDR / XDRFirewall / NDRIAM
Executed allowlisted non-destructive actions2h ago

Response Agent (Agent) · INC-2041 · Enrichment, log collection, ticket created

SourcesThreat IntelEDR / XDRTicketing / SOAR
Withheld destructive action pending approval2h ago

Decision Gate (Policy) · INC-2041 / ACT-ISOLATE · Approval requested from Authorized Approver

SourcesTicketing / SOAR
Computed deterministic risk score2h ago

Risk Assessment Agent (Agent) · INC-2041 · Score 81 → Critical

SourcesCMDBVuln MgmtThreat IntelEDR / XDR
Mapped observed behaviour to ATT&CK2h ago

ATT&CK Mapping Agent (Agent) · INC-2041 · T1566.002, T1078.002, T1059.001, T1003.001

SourcesEDR / XDRIAMEmail
Correlated 4 alerts into incident2h ago

Evidence Correlation Agent (Agent) · INC-2041 · Incident created, severity Critical

SourcesEDR / XDRIAMEmailThreat Intel
Approved perimeter block1d ago

CISO / SOC Manager (CISO / SOC Manager) · INC-2042 / ACT-BLOCK-IP · Approved — 24h TTL deny rule

SourcesFirewall / NDRThreat Intel
Refused out-of-allowlist action2d ago

Response Agent (Agent) · INC-2044 / wipe-and-reimage · Refused: action not on the response allowlist

SourcesTicketing / SOAR
Approved endpoint isolation2d ago

On-call Approver (On-call Approver) · INC-2044 / ACT-ISOLATE · Approved — executed via scoped EDR API

SourcesEDR / XDRSIEMIAMThreat Intel
Closed case as verified benign3d ago

Reporting Agent (Agent) · INC-2045 · Closed-Benign with rationale retained

SourcesCloudIAMTicketing / SOAR