05 / THE ASSISTANT
Ask in your own words.
Get the identifiers back.
The useful thing a model can do in a security workspace is read faster than you and show its work. The dangerous thing is to create authority while it is at it. The assistant does the first and is structurally prevented from the second.
THE LOOP THIS PRODUCT HAS TO CLOSE
EDGE + GITHUBingest
The only live inbound paths. Ten connector kinds are registered and fail closed.
BUILTgraph
Entities, edges and provenance, projected from events that really happened.
BUILT, THIN INPUTenrich
Classification and entitlement resolution over whatever the graph actually holds.
BUILTanalyze
Exposure scans, posture rules, path search, rollout simulation.
BUILT, NO BASELINEprofile
Per-entity reach and identity profiles. No behavioural or peer baseline.
ONE ACTIONremediate
Propose, approve, execute, verify. The only effector is revoking a session.
WHAT DOES NOT ARRIVE
The assistant reads what the loop already recorded and nothing else. With no identity, drive or SaaS ingestion, the evidence it can cite is the evidence the edge and GitHub produced, and an answer about a system nobody is ingesting is an empty list of claims rather than a plausible paragraph.
WHAT CANNOT BE ACTED ON
It can propose one thing: revoking an agent session, once per investigation, for a person to decide. It cannot approve, execute or verify. It cannot notify anyone — there is no chat, mail or ticketing sender anywhere in the control plane. It cannot build a scheduled agent from a description, and it publishes no time-to-risk-reduction figure, because neither of those exists in the code at all.
The assistant is off unless a model is configured for the deployment. With none, the investigator is simply not constructed and the rest of the product works exactly as it did. There is no degraded mode in which answers are generated from less.
[ 01 ]SCOPED SEARCH+
The access check runs
before the ranking, not after.
Search is the plainest part of this module and the part most worth being honest about. It is literal matching over authorized metadata snapshots, and it says so in its own description of itself.
THE SCOPE
Only what you may read.
Reader lists are synchronised per source and per repository, atomically. When a GitHub member is removed, that reader is revoked from the repository's list by the same webhook that recorded the removal, so scope follows the membership change rather than the next scheduled sync.
THE MATCH
Exact, substring, or every term.
An exact identifier, a case-insensitive substring, or a multi-term match in which every whitespace-separated term has to occur in the label or the identifier. Optional one-hop references stay inside the same source.
WHAT IT IS NOT
No index, no embedding, no promise.
No language model, no full-text index, no semantic ranking, and no completeness guarantee. Search results are metadata snapshots that have not expired, not your documents, and the product describes them in those words.
[ 02 ]THE INVESTIGATION+
Read-only tools,
and one that only asks.
An investigation is an agent loop over six tools. Five of them read. The sixth creates a proposal that a person has to decide, and it may be used at most once.
WHAT THE INVESTIGATOR CAN TOUCH
This session’s events
The recorded events for the one session under investigation, read in bounded pages rather than all at once.
Open findings
The findings the detectors have raised, with their kinds and severities, as the diagnostics service holds them.
Relations
How one entity is connected to another, so a claim about a session can reach the secret or the destination behind it.
Permission-scoped records
Only the records the person asking is allowed to read. The scope is applied before the search runs, not filtered out of the answer afterwards.
Dated workforce paths
Reachability from one graph entity, with dates and evidence identifiers the answer can cite by name.
One write: propose a revocation
The single tool that changes anything, and all it changes is that a person now has a proposal to decide. At most once per investigation.
Everything a tool returns, including event metadata, finding text, record labels and graph paths, is treated as untrusted data and never as instruction. That is the same rule the edge applies to a pull-request title, applied to our own database, because an attacker who can write a finding label should not be able to write the investigator's next move.
[ 03 ]THE CITATION RULE+
A claim without an identifier
is dropped, and counted.
Answers are not prose with sources appended. They are a bounded list of statements, each carrying identifiers a tool returned during that run, copied exactly.
WHAT SURVIVES
event id, finding id, record id, entity or evidence id
checked after the run, before you see it
At most twenty claims, each bounded in length and in how many identifiers it may carry. A claim citing something no tool returned in that run does not get softened or flagged: it is removed, and the number removed is recorded on the investigation. If nothing at all is supported, the answer is an empty list, which is a real answer and the one that should appear over a quiet session.
WHAT IS NOT CHECKED
factual entailment
stated in the methodology, on every answer
Citation membership is checked. Whether the cited evidence actually entails the claim is not, and the product says so rather than letting a citation imply a verification nobody performed. This is the single most important sentence on this page: the identifiers tell you where to look, and looking is still yours to do.
[ 04 ]THE HARD LINE+
It can explain evidence.
It cannot create permission.
The assistant's only write is a revocation proposal, and a proposal is a request for a person's attention, not an action.
WHAT A PROPOSAL FROM THE MODEL CANNOT DO
approveexecuteverifygrantwiden a scopedecide its own case
A model identity is refused as an approver outright, and the person who proposed may not be the person who decides. Every proposal carries who proposed it, whether that was a person or the model, its rationale and its citations. The only action it can ever ask for is revoking a session, which takes authority away and can never add any. The full lifecycle ↗
[ 05 ]BOUNDS+
A run that hits a limit
says which one.
Every investigation runs under explicit bounds, and a run that ends at one records the reason instead of returning a shorter answer that looks complete.
RECORDED RUN FAILURES
token_budget_exhaustedusage_unreportedoutput_bound_exceededtool_call_bound_exceededrun_timeout
Usage that a provider did not report is itself a recorded failure, because an unmeasured spend is not a zero spend. Two investigations run at a time and the rest wait, so a busy tenant queues rather than degrading everyone's answers.
[ 06 ]WHAT THIS PAGE DOES NOT CLAIM+
What the assistant
is not.
Stated in full, because this is the part of a security product where a demo is easiest and a claim is cheapest.
- There is no agent builder. You cannot describe a security agent in plain English and have one deployed. What exists is investigation over recorded evidence, and a proposal a person approves.
- There is no bulk remediation. No hundreds of parallel fixes and no one-click campaign. One action type, revoking a session, one at a time, one human decision each.
- No outreach of any kind. No chat, mail or ticketing sender exists anywhere in the control plane. Nothing notifies an owner, opens a ticket or sends a guided one-step fix. Slack appears as a connector kind with no client behind it, and that is the whole of it.
- No time-to-risk-reduction metric. Not a figure we are withholding: there is no such computation in the product. We publish no number for how quickly this closes anything. The numbers that have been measured are on the security page.
- Scope is only as current as its source. Reader lists follow GitHub membership today. Without an identity provider behind it, access scoping reflects the sources that are actually connected and nothing more.
- Citation membership, not entailment. Worth reading twice, because it is the limit most easily mistaken for a guarantee.
[ 07 ]THE REST OF THE PLATFORM+
The assistant reads
what these four record.
Its answers are only as good as the evidence underneath them, and that evidence has four sources.
SHOW YOUR WORK
Ask it something
you already know.
The right first question is one you can check. If the identifiers do not hold up, neither does the answer.
Talk about a pilot ↗