01SOURCE
Detection engineering
Source-controlled rules + ATT&CK context
Detection source, rule logic, status metadata, and ATT&CK-aligned context live in the detections repo. Reviewable in plain text, version-controlled, mappable.
→02CONTRACT
Telemetry confidence
Route contracts + visibility evidence
Telemetry routes and contracts are treated as visibility or private/internal evidence. Public-safe runtime/signal status requires a separate promotion gate.
→03CONTROLLED
Validation
Deterministic verifiers + controlled fixtures
Controlled-test validation packages and fixtures support controlled validation claims. Verifiers fail closed; no runtime promotion happens here.
→04SUPPORT-ONLY
Alert-to-case flow
Case packets, support gates, blocked actions
Case-packet schemas and samples model analyst support, response gates, and blocked actions. Mutation, closure, and disposition authority stay outside the contract.
→05AI SUPPORT-ONLY
AI-assisted triage
Sanitized summaries + missing context
AI may summarize sanitized facts and call out missing context. It does not decide disposition, close cases, approve actions, or promote proof.
→06HUMAN
Human review authority
Visible reviewer + MERGE_APPROVED
Visible human review is the authority layer. AI is below human review; CI is below human review; momentum is below human review.
→07PROOF CEILING
Proof-controlled reporting
Reviewer packets at the current ceiling
Proof Pack 001 and proof records route reviewer claims under the current ceiling. Website rendering remains a route to proof, not proof itself.