Introducing Zorro Security / A new perspective on AI security ↗
zorroSECURITYSign in Build with us ↗

05 / THE ASSISTANT

Ask in your own words.
Get the identifiers back.

The useful thing a model can do in a security workspace is read faster than you and show its work. The dangerous thing is to create authority while it is at it. The assistant does the first and is structurally prevented from the second.

THE LOOP THIS PRODUCT HAS TO CLOSE

EDGE + GITHUB

ingest

The only live inbound paths. Ten connector kinds are registered and fail closed.

BUILT

graph

Entities, edges and provenance, projected from events that really happened.

BUILT, THIN INPUT

enrich

Classification and entitlement resolution over whatever the graph actually holds.

BUILT

analyze

Exposure scans, posture rules, path search, rollout simulation.

BUILT, NO BASELINE

profile

Per-entity reach and identity profiles. No behavioural or peer baseline.

ONE ACTION

remediate

Propose, approve, execute, verify. The only effector is revoking a session.

WHAT DOES NOT ARRIVE

The assistant reads what the loop already recorded and nothing else. With no identity, drive or SaaS ingestion, the evidence it can cite is the evidence the edge and GitHub produced, and an answer about a system nobody is ingesting is an empty list of claims rather than a plausible paragraph.

WHAT CANNOT BE ACTED ON

It can propose one thing: revoking an agent session, once per investigation, for a person to decide. It cannot approve, execute or verify. It cannot notify anyone — there is no chat, mail or ticketing sender anywhere in the control plane. It cannot build a scheduled agent from a description, and it publishes no time-to-risk-reduction figure, because neither of those exists in the code at all.

The assistant is off unless a model is configured for the deployment. With none, the investigator is simply not constructed and the rest of the product works exactly as it did. There is no degraded mode in which answers are generated from less.

The access check runs
before the ranking, not after.

Search is the plainest part of this module and the part most worth being honest about. It is literal matching over authorized metadata snapshots, and it says so in its own description of itself.

THE SCOPE

Only what you may read.

Reader lists are synchronised per source and per repository, atomically. When a GitHub member is removed, that reader is revoked from the repository's list by the same webhook that recorded the removal, so scope follows the membership change rather than the next scheduled sync.

THE MATCH

Exact, substring, or every term.

An exact identifier, a case-insensitive substring, or a multi-term match in which every whitespace-separated term has to occur in the label or the identifier. Optional one-hop references stay inside the same source.

WHAT IT IS NOT

No index, no embedding, no promise.

No language model, no full-text index, no semantic ranking, and no completeness guarantee. Search results are metadata snapshots that have not expired, not your documents, and the product describes them in those words.

Read-only tools,
and one that only asks.

An investigation is an agent loop over six tools. Five of them read. The sixth creates a proposal that a person has to decide, and it may be used at most once.

WHAT THE INVESTIGATOR CAN TOUCH

This session’s events

The recorded events for the one session under investigation, read in bounded pages rather than all at once.

Open findings

The findings the detectors have raised, with their kinds and severities, as the diagnostics service holds them.

Relations

How one entity is connected to another, so a claim about a session can reach the secret or the destination behind it.

Permission-scoped records

Only the records the person asking is allowed to read. The scope is applied before the search runs, not filtered out of the answer afterwards.

Dated workforce paths

Reachability from one graph entity, with dates and evidence identifiers the answer can cite by name.

One write: propose a revocation

The single tool that changes anything, and all it changes is that a person now has a proposal to decide. At most once per investigation.

Everything a tool returns, including event metadata, finding text, record labels and graph paths, is treated as untrusted data and never as instruction. That is the same rule the edge applies to a pull-request title, applied to our own database, because an attacker who can write a finding label should not be able to write the investigator's next move.

A claim without an identifier
is dropped, and counted.

Answers are not prose with sources appended. They are a bounded list of statements, each carrying identifiers a tool returned during that run, copied exactly.

WHAT SURVIVES

event id, finding id, record id, entity or evidence id

checked after the run, before you see it

At most twenty claims, each bounded in length and in how many identifiers it may carry. A claim citing something no tool returned in that run does not get softened or flagged: it is removed, and the number removed is recorded on the investigation. If nothing at all is supported, the answer is an empty list, which is a real answer and the one that should appear over a quiet session.

WHAT IS NOT CHECKED

factual entailment

stated in the methodology, on every answer

Citation membership is checked. Whether the cited evidence actually entails the claim is not, and the product says so rather than letting a citation imply a verification nobody performed. This is the single most important sentence on this page: the identifiers tell you where to look, and looking is still yours to do.

It can explain evidence.
It cannot create permission.

The assistant's only write is a revocation proposal, and a proposal is a request for a person's attention, not an action.

WHAT A PROPOSAL FROM THE MODEL CANNOT DO

approveexecuteverifygrantwiden a scopedecide its own case

A model identity is refused as an approver outright, and the person who proposed may not be the person who decides. Every proposal carries who proposed it, whether that was a person or the model, its rationale and its citations. The only action it can ever ask for is revoking a session, which takes authority away and can never add any. The full lifecycle ↗

A run that hits a limit
says which one.

Every investigation runs under explicit bounds, and a run that ends at one records the reason instead of returning a shorter answer that looks complete.

RECORDED RUN FAILURES

token_budget_exhaustedusage_unreportedoutput_bound_exceededtool_call_bound_exceededrun_timeout

Usage that a provider did not report is itself a recorded failure, because an unmeasured spend is not a zero spend. Two investigations run at a time and the rest wait, so a busy tenant queues rather than degrading everyone's answers.

What the assistant
is not.

Stated in full, because this is the part of a security product where a demo is easiest and a claim is cheapest.

The assistant reads
what these four record.

Its answers are only as good as the evidence underneath them, and that evidence has four sources.

SHOW YOUR WORK

Ask it something
you already know.

The right first question is one you can check. If the identifiers do not hold up, neither does the answer.

Talk about a pilot ↗