// signal to closure
A signal, worked to a decision
Most platforms end at the alert. This is what happens after it: who owns it, what they concluded, and what they did about it.
// the problem
An alert is not an answer
Every security tool can raise an alert. The expensive question is what happened next, and most platforms have no answer because nobody was ever accountable for producing one.
We do not show you a queue and call it security operations. Every signal ends in a written decision by a named person, or it is still open.
// the lifecycle
What happens to one signal
This is the actual path, not a simplification of it.
- SignalDetection
Something in your environment trips a detection. The signal is the unit you see and the unit an analyst dispositions.
- InvestigationMachine
Before a human sees it, an agentic run gathers context and reaches a verdict, recording the grounds it rests on. This happens on every signal.
- Broadcast and claimDesk
If nobody was auto-assigned, the work is offered to the analysts eligible to take it. One claims it and becomes its owner. If it reached nobody at all, that is recorded as a coverage gap rather than quietly queued.
- In reviewAnalyst
Ownership and attention are tracked separately, because work can be owned for hours before anyone looks at it, and those are different questions.
- AnalysisAnalyst
The analyst writes an account of what they investigated and what they found. You read it. It is not an internal note.
- ClosureAnalyst
The signal closes with two separate records: what it turned out to be, and what was done about it. Neither implies the other.
// the determination
What it turned out to be
Four values, not a free-text box. Every report we produce is grouped by this, which only works because the set is closed.
- True Positive
Real activity, and malicious.
- Benign Positive
Real activity, and authorised. The detection worked exactly as intended.
Not the same as a false positive, and conflating the two is the mistake this vocabulary exists to prevent.
- False Positive
The detection itself was wrong.
- Inconclusive
Not enough evidence to say. Recorded honestly rather than rounded to one of the others.
// the closure action
And what was done about it
Recorded beside the determination, never derived from it. A signal can be a true positive that was contained, or a true positive that was accepted as a documented risk. Those are different outcomes and the record keeps them apart.
- Blocked on client — we have reviewed it and cannot progress without you acting in your own environment. It sits on a queue of its own rather than being marked done.
- Declared incident — escalated into tracked incident work with provenance back to the signal, and onward into the evidence chain
- Correlated closure — a judgement reached while investigating one signal, applied deliberately to another that shares its correlation key, and labelled as such on your own signal page.
- Resolved without a determination — possible only for historical work predating the closure record. We did not backfill judgements nobody made.
// what you can check
The parts that are hard to fake
- A signal that reached nobody is recorded as a coverage gap, not as awaiting pickup. The distinction is whether anyone was ever asked.
- A breached SLA does not close anything. Breach is stamped alongside the work; the work stays open and still counts against the analyst holding it.
- Removing a signal from the operating picture requires a written justification, because that act is the only record the exclusion happened.
- Every action is attributed to a real member record, so there is always a subject behind a decision — see how the desk is staffed
// questions this answers
How a signal is worked, answered directly
What happens after Konfirmity raises a security alert?
The signal is triaged by machine, then claimed by a named analyst who investigates it and closes it with two separate records: a determination of what it turned out to be, and a closure action describing what was done about it. It stays open until both exist.
What are the possible determinations?
Four, and only four: True Positive (real and malicious), Benign Positive (real activity, authorised), False Positive (the detection was wrong), and Inconclusive (not enough evidence to say). The set is closed because every SOC report is grouped by it.
Does a breached SLA close the work?
No. Breach is stamped alongside the work rather than ending it. A breached signal is still unresolved, still claimable, and still counts toward the analyst holding it.
// keep reading
Where this goes deeper
Want to see this one live?
Book 30 minutes and we will walk through “A signal, worked to a decision” in the actual platform, using your environment as the example.