Konfirmity

// investigation

The machine proposes, the analyst decides

Automated triage that shows its working, and only earns the right to act on its own conclusions one alert type at a time.

// the problem

Automation you are asked to trust blindly

Most security automation gives you a score and no reasoning. You cannot audit it, cannot argue with it, and cannot tell whether it is right until it is wrong.

Our triage has to show its working, and it has to earn the right to act on its own conclusions one alert type at a time.

// two stages

Cheap first, thorough second

Triage runs in two passes. A cheap first pass on arrival, then an agentic second stage that goes and gathers context before concluding anything.

  • The second stage consults related signals, posture data, CVE dossiers, and the baseline facts you have approved
  • It accounts for the resource's actual exposure and live configuration, not the theoretical severity of the alert class.
  • An input it could not answer is stated rather than quietly omitted, so a thin conclusion looks thin.
  • All of this happens before any analyst sees the signal.

// the vocabulary

Four words that are not synonyms

These distinctions are load-bearing. Collapsing any two of them is how automated security reporting becomes unfalsifiable.

Verdict

What the engine concluded about a signal at triage.

Not a determination. A different actor reaches it, at a different point, about a different question.

Grounds

What the verdict rests on: the signals, facts, postures and dossiers consulted, plus the account of the resource's exposure.

Deliberately not called evidence — that word already names something specific in the compliance domain.

Decision

What the investigation resolved to do: close, downgrade, or raise. Recorded whether or not the machine was permitted to act on it.

Recording a decision the machine could not enact is what makes it reviewable afterwards.

Alert-Type Authority

Whether the machine may act on its own decisions for one alert type, for one client. Earned and lost on the record of analyst review.

Not a global autonomy setting. It is per alert type, per client, and it moves.

// scorekeeping

Confirm and overturn change the score, not the signal

When an analyst reviews a machine decision, that review is scorekeeping and nothing else.

  • A confirm enacts nothing that was being held. An overturn reopens nothing and un-closes nothing.
  • What moves is that alert type's authority for that client — up on confirms, down on overturns.
  • An analyst who disagrees and wants the signal worked has to work it. That is a separate act, deliberately.
  • So autonomy is never granted by configuration. It accumulates from a review record you can inspect, kept by the analysts who work your signals

// why it matters

The machine proposes, the analyst decides

A platform that lets automation close your alerts without recording what it concluded, why, and whether anyone checked, is not saving you work. It is moving the risk somewhere you cannot see it.

// questions this answers

How automated triage works, answered directly

Does AI close security alerts without a human?

Only for alert types where it has earned that authority from the record of analyst review, per client. Elsewhere the machine records what it would have done and holds it, which is what makes the decision reviewable afterwards.

What is the difference between a verdict and a determination?

A verdict is what the engine concluded at triage; a determination is what an analyst decided at closure. Different actor, different point in the lifecycle, different question. A signal can carry a verdict and never reach a determination, and that is not an inconsistency.

Can I see why the machine reached its conclusion?

Yes. Every verdict states its grounds: the related signals, approved baseline facts, posture data and CVE dossiers consulted, plus the resource's actual exposure. An input it could not answer is stated rather than omitted, so a thin conclusion looks thin.

Want to see this one live?

Book 30 minutes and we will walk through “The machine proposes, the analyst decides” in the actual platform, using your environment as the example.

Book a demo