A finding arrives with a title and a severity. Before acting, someone still needs to understand what happened, who or what was involved and which evidence supports the conclusion.

A good investigation surface preserves that context. Opening an identity should not lose the original finding. Inspecting a resource should keep the relevant access path in view. Returning to the queue should preserve the filter that led to the case.

Start with the recorded fact

Separate the source observation from the interpretation. An event can establish that an API call was recorded. It may not establish intent, ownership or whether the call completed successfully. The explanation should be precise about the claim it makes.

For AI workflows, a tool request, an authorization decision and a tool result are also separate events. Treating them as one can hide the difference between a refused request and an executed action.

Bring the evidence to the decision

An analyst should be able to inspect the source and time of an observation, the policy evaluated, and any limits on attribution. A natural-language summary can help navigate that material, but it should lead back to the material.

An assistant that cannot find sufficient evidence should say so. It can propose what to check next without pretending the missing evidence exists.

Close the loop carefully

Acknowledging a finding means somebody has seen it. Resolving it asserts something stronger. A response workflow should record the reason for a transition, who requested it and what the system confirmed.

Consequential actions need a similarly clear result. A requested change, an accepted job and a verified outcome are different stages. The interface should show the stage it actually knows.

That is the workflow Zorro is being built around: a focused queue, inspectable evidence and an explicit next step. The measure of a useful screen is whether it helps someone make a defensible decision.