The challenge
Security analysts move between alert consoles, asset records, and response procedures to establish what happened. The project connects related events and relevant runbooks in one investigation workflow.
The solution
A triage agent groups related alerts and retrieves authorized asset and identity context. RAG locates approved runbooks, while an evidence agent prepares a timeline with links to source events. Analysts review severity and recommended actions, with approval required before containment or access changes.
Project scope & evaluation
The scope includes read-only security integrations, an evidence workspace, runbook citations, and escalation drafts. Evaluation uses known incident scenarios to assess relevant-event coverage, unsupported conclusions, analyst corrections, and time to assemble a reviewable case.