Konfirmity

// signal to closure

A signal, worked to a decision

Most platforms end at the alert. This is what happens after it: who owns it, what they concluded, and what they did about it.

// the problem

An alert is not an answer

Every security tool can raise an alert. The expensive question is what happened next, and most platforms have no answer because nobody was ever accountable for producing one.

We do not show you a queue and call it security operations. Every signal ends in a written decision by a named person, or it is still open.

// the lifecycle

What happens to one signal

This is the actual path, not a simplification of it.

  1. SignalDetection

    Something in your environment trips a detection. The signal is the unit you see and the unit an analyst dispositions.

  2. InvestigationMachine

    Before a human sees it, an agentic run gathers context and reaches a verdict, recording the grounds it rests on. This happens on every signal.

  3. Broadcast and claimDesk

    If nobody was auto-assigned, the work is offered to the analysts eligible to take it. One claims it and becomes its owner. If it reached nobody at all, that is recorded as a coverage gap rather than quietly queued.

  4. In reviewAnalyst

    Ownership and attention are tracked separately, because work can be owned for hours before anyone looks at it, and those are different questions.

  5. AnalysisAnalyst

    The analyst writes an account of what they investigated and what they found. You read it. It is not an internal note.

  6. ClosureAnalyst

    The signal closes with two separate records: what it turned out to be, and what was done about it. Neither implies the other.

// the determination

What it turned out to be

Four values, not a free-text box. Every report we produce is grouped by this, which only works because the set is closed.

True Positive

Real activity, and malicious.

Benign Positive

Real activity, and authorised. The detection worked exactly as intended.

Not the same as a false positive, and conflating the two is the mistake this vocabulary exists to prevent.

False Positive

The detection itself was wrong.

Inconclusive

Not enough evidence to say. Recorded honestly rather than rounded to one of the others.

// the closure action

And what was done about it

Recorded beside the determination, never derived from it. A signal can be a true positive that was contained, or a true positive that was accepted as a documented risk. Those are different outcomes and the record keeps them apart.

  • Blocked on client — we have reviewed it and cannot progress without you acting in your own environment. It sits on a queue of its own rather than being marked done.
  • Declared incident — escalated into tracked incident work with provenance back to the signal, and onward into the evidence chain
  • Correlated closure — a judgement reached while investigating one signal, applied deliberately to another that shares its correlation key, and labelled as such on your own signal page.
  • Resolved without a determination — possible only for historical work predating the closure record. We did not backfill judgements nobody made.

// what you can check

The parts that are hard to fake

  • A signal that reached nobody is recorded as a coverage gap, not as awaiting pickup. The distinction is whether anyone was ever asked.
  • A breached SLA does not close anything. Breach is stamped alongside the work; the work stays open and still counts against the analyst holding it.
  • Removing a signal from the operating picture requires a written justification, because that act is the only record the exclusion happened.
  • Every action is attributed to a real member record, so there is always a subject behind a decision — see how the desk is staffed

// questions this answers

How a signal is worked, answered directly

What happens after Konfirmity raises a security alert?

The signal is triaged by machine, then claimed by a named analyst who investigates it and closes it with two separate records: a determination of what it turned out to be, and a closure action describing what was done about it. It stays open until both exist.

What are the possible determinations?

Four, and only four: True Positive (real and malicious), Benign Positive (real activity, authorised), False Positive (the detection was wrong), and Inconclusive (not enough evidence to say). The set is closed because every SOC report is grouped by it.

Does a breached SLA close the work?

No. Breach is stamped alongside the work rather than ending it. A breached signal is still unresolved, still claimable, and still counts toward the analyst holding it.

Want to see this one live?

Book 30 minutes and we will walk through “A signal, worked to a decision” in the actual platform, using your environment as the example.

Book a demo