- Authorized tenant, asset, identity, and collection scope
- Define monitoring purpose, tenants, environments, assets, identities, event families, fields, content capture, threat-intelligence use, retention and analyst access; enforce isolation at ingestion, storage, search and export; mask secrets; record denials; and prohibit collection expansion through model or analyst convenience.
- Immutable telemetry, time integrity, and sensor health
- Preserve originals and digests, validate schemas, retain source and collection times, measure clock drift, heartbeats, parser failures, duplicates, samples and late data, expose gaps and blind spots and prevent normalization, enrichment, redaction or correction from erasing source evidence.
- Versioned rules, intelligence, baselines, and models
- Version every signature, allowlist, threshold, query, baseline, feature, model, provider and ATT&CK mapping; preserve intelligence origin, confidence, age, handling and scope; treat retrieved content as data; isolate untrusted text; validate updates in shadow; and retain rollback and expiry.
- Replayable correlation and honest uncertainty
- Link every candidate to exact supporting and contradicting events, joins, time windows, queries and context versions; distinguish behavior, indicator, anomaly, severity and confidence; expose missing sources and alternate explanations; deduplicate transparently; and forbid invented evidence, attribution or incident state.
- Named investigation and consequence-based response
- Assign analysts and backups, preserve searches and rationale, require peer or incident-owner review where needed, keep incident declaration separate from alert state and require fresh approval, target validation and impact preview for account, host, network, credential, data, service and notification actions.
- Independent rollback, recovery, tuning, and stop authority
- Keep response credentials outside model context, use bounded action schemas and idempotency where possible, reconcile actual effects, preserve rollback and manual recovery, test rule and model changes against true and false cases, reopen wrong dispositions and let independent owners stop collection, correlation, suppression, response or the system.