How it works

Detect → Correlate → Investigate → Authorise → Respond → Verify → Learn

Every step states what happens, who or what performs it, what evidence it produces and which claim state that evidence carries.

  1. Step 1: Detect

    Telemetry from your existing tools is normalised at the customer edge and matched against detections and decoy activity.

    Performed by
    Aegis edge service, through adapters to your existing tools.
    Evidence
    Source events with origin, timestamp and integrity hash, retained in your perimeter.
    Claim state
    OBSERVED
  2. Step 2: Correlate

    Related signals across hosts, identities and time are grouped into a candidate incident with a stated confidence.

    Performed by
    Correlation engine, running on the edge or in the control plane on metadata.
    Evidence
    Links between observed events, each with the rule or model that proposed the link.
    Claim state
    INFERRED
  3. Step 3: Investigate

    Aegis gathers further context, tests hypotheses and builds a timeline — separating what was seen from what is suspected.

    Performed by
    Investigation agents, with analysts able to review and challenge every step.
    Evidence
    Timeline entries, queries run and artefacts collected, each labelled with its claim state.
    Claim state
    OBSERVEDINFERRED
  4. Step 4: Authorise

    Response options are proposed with scope, expected impact and rollback. Policy decides whether a human must approve.

    Performed by
    Policy engine and the named approvers your policy requires.
    Evidence
    The proposal, the policy rule applied, and the approver identity and decision.
    Claim state
    PROPOSED
  5. Step 5: Respond

    Approved actions run through the customer-edge service — never through inbound access from the control plane.

    Performed by
    Aegis edge service, using the adapters and credentials you grant it.
    Evidence
    Action record with parameters, executor, start and end time, and result.
    Claim state
    EXECUTED
  6. Step 6: Verify

    An independent check confirms whether the action achieved its intended effect, and flags it if not.

    Performed by
    Verification checks, separate from the component that executed the action.
    Evidence
    Verification result and the observations it was based on.
    Claim state
    VERIFIED
  7. Step 7: Learn

    Outcomes feed proposed tuning for detections and playbooks. Changes are reviewed before they take effect.

    Performed by
    Learning module proposes; your team or policy approves.
    Evidence
    Versioned change proposals linked to the incidents that motivated them.
    Claim state
    PROPOSED

Claim states

Five labels, used everywhere.

The same claim states appear in incidents, timelines, reports and the evidence vault, so a reader always knows how much weight a statement can bear.

  • OBSERVED

    Directly seen in source telemetry or evidence. Carries its origin and integrity hash.

  • INFERRED

    A conclusion drawn by analysis or AI, shown with confidence. Never presented as fact.

  • PROPOSED

    A recommended action with scope and rollback, awaiting authorisation under policy.

  • EXECUTED

    An action that has been carried out, with who or what performed it and when.

  • VERIFIED

    An outcome confirmed by an independent check, separate from the executor.

Governed autonomy

Authorisation is policy, not guesswork.

The Authorise step is where policy decides whether an action may run automatically or needs a named approver. Levels are set per action class.

  1. Level 0: Observe

    Aegis detects and records. No investigation or action is taken automatically.

  2. Level 1: Investigate

    Aegis gathers context and builds hypotheses. Every response is proposed for human approval.

  3. Level 2: Controlled autonomy

    Pre-approved, reversible actions within a defined scope may run automatically. Everything else needs approval.

  4. Level 3: Expanded autonomy

    Broader automatic response for explicitly authorised action classes, with verification and rollback enforced.

See exactly what Aegis does when something goes wrong.

We will walk your team through an incident from first signal to verified outcome. You will see what Aegis observed, what it inferred, what it proposed and what actually happened.