It audits the investigation for gaps
Before a case can close, the work done on it is examined for missing evidence — the questions that were not asked, the sources that were not checked.
Most platforms sort an alert into a queue and wait for a person. Ours runs an investigation on it — gathering evidence, testing what it means, auditing its own work for gaps, and stopping at the line you drew. What reaches you is a case, not a notification.
An alert arriving at CYBERSHIELD AI is not classified and filed. It is worked through a nine-stage investigation against the triage procedure that fits it, using procedures our analysts wrote while running Microsoft Sentinel in production.
The difference shows up in what comes out of the other end. A queue-sorting tool returns a priority and a category, and the work of establishing what actually happened still belongs to your team. A pipeline returns a verdict with the evidence that supports it, the scope it covers, and the reasoning that got there.
A conductor agent runs the sequence: it tasks the right agent at the right moment, enforces the completeness gate before anything closes, holds high-impact actions for human approval, and hands your SOC a case ready to close.
Every alert, every time, in this order.
Work out what we are looking at before a step runs.
Resolve the identities, devices and addresses to the real objects in your directory, rather than the strings the alert carried.
Look back across your own history for incidents that resemble this one, so a repeat is recognised as a repeat.
The Fusion agent asks early whether this might belong to something wider, rather than letting it be investigated as an isolated event.
Gather the evidence, then refuse it until it is complete.
Run the steps the matched procedure calls for, in parallel, each gathering evidence with its own scoped set of tools.
Audit the investigation for evidence gaps before it is allowed to progress.
Sends the work back for more evidence, as many times as it takes
With the full investigation in hand, Fusion merges the incident into an existing case if it belongs to one, rather than closing it standalone.
Reach a verdict, decide, and hand it over.
Weigh the evidence gathered into an assessment, with a confidence score attached.
Apply policy and your own decision templates to reach close or escalate. Not taken by the model.
The report, the timeline, the closing statement, the handover if it escalated, and the notification.
Case, and campaign. A case is a collection of related incidents. A case can also be marked as a campaign. An incident that Fusion finds a home for is merged into the case rather than closed on its own.
Want to watch one run end to end? See a worked investigation on the platform page
Or see the services it runs underneath: Detection & Response
Every automated investigation has the same failure mode: it finds an explanation that fits, and it stops. The completeness gate is the stage built to prevent exactly that.
Before a case can close, the work done on it is examined for missing evidence — the questions that were not asked, the sources that were not checked.
Not a warning that something is missing. The additional investigative steps needed to close the gap are produced as work to be done.
The new evidence goes back into the case and the conclusion is tested again against it. A verdict that no longer holds does not survive the gate.
If the audit concludes nothing further is needed, a deterministic check runs anyway. Any failed step, any low-confidence step, any recorded anomaly forces follow-up work regardless of what the audit decided.
An investigation can go back for more evidence more than once, and how hard the gate looks scales with the severity of the incident. A serious incident gets a longer argument with itself.
It is what stops an investigation settling on the first plausible explanation. It is also why our own analysts trust the output enough to sign it.
The close-or-escalate call is not the model’s to make. It is reached by applying your own decision templates and the policy that sits above them, as written rules rather than as a judgement. That separation is deliberate, and it is the honest answer to "how do I know it is not just making this up".
Policy overrides are evaluated first, and nothing closes past them. A failed high-priority investigation step escalates. Evidence gathering that came back empty escalates rather than closing on an absence. Confidence below the bar you set escalates.
Where more than one of your own rules matches and no override applies, the model is used only to arbitrate between the rules you wrote. It is never the thing that decides an incident is finished.
You get a verdict with evidence behind it, not a guess with a confidence score painted on.
Two clocks rather than one tidy round number, because triage and investigation are different jobs and quoting a single figure for both would flatter one of them.
Measured across our own SOC. Both clocks start at the same point: the moment a signal reaches CYBERSHIELD AI — not when an analyst opens it, and not when the ticket is assigned.
Not a product property, a configuration — set per agent and per tenant. The three settings below are the dial. Where you set it is your call, and it is the first thing we agree at onboarding.
Agents triage, investigate and act inside the limits you set, without waiting for anyone. Every action is still recorded and reviewable in the Control Centre.
Nominate the points where a person must approve before anything proceeds. Set it per agent, so containment can wait for a human while enrichment does not.
You set the bar. Above it the agent proceeds; below it the work routes to an analyst. This is where most customers settle once they have watched it run.
On the managed service, senior analyst sign-off is the default rather than an upgrade. That is a deliberate choice about accountability: somebody with a name is answerable for the verdict that reaches you.
An agent that acts without leaving a record is indistinguishable from an agent that acted wrongly. Everything the pipeline does reports into the Control Centre, whether it waited for a person or not.
That record is what makes the documents on every incident possible, and it is the same record an auditor can be walked through months later.
Entity context discovery. The identities, devices and addresses in the alert are resolved to the real objects in your directory before anything is investigated, so the work is done against who was actually involved rather than the strings the alert carried. Average time to an L1 verdict is 3m 30s.
No. The model assesses the evidence. The close-or-escalate call is then reached by applying your own decision templates and the policy above them, as written rules. A failed high-priority step, evidence gathering that returned nothing, or confidence below your bar all escalate regardless of what the assessment said.
Stage five of nine. It audits the case for evidence gaps, generates the steps needed to fill them, runs those, then reassesses the conclusion against the new evidence. If the audit says nothing is missing, a deterministic check runs anyway. It is what stops an investigation settling on the first plausible explanation.
Only as far as you allow. Autonomy is configurable per agent and per tenant: fully autonomous inside set limits, held for human approval at nominated points, or autonomous above a confidence threshold you set. On the managed service, senior analyst sign-off is the default.
Both start at the same point: the moment a signal reaches CYBERSHIELD AI. Average L1 verdict is 3m 30s and average L2 verdict is 7m 50s, measured across our own SOC rather than quoted from a datasheet.
A full investigation report with the evidence attached, an escalation write-up where the incident was escalated, a closing statement in plain English, and a draft notification for your stakeholders. Every investigation, not only the ones somebody had time for.
Yes. OT telemetry joins the IT signal in the same pipeline and is worked by the same agent roster against the same completeness gate, so lateral movement from the corporate network into the plant reads as one chain of events rather than two unrelated alerts.
An hour with a SOC analyst: a live investigation from signal to signed verdict, the completeness gate doing its job, and the autonomy dial set where you would set it. Your scenarios, not a canned demo.