How it works
Detect → Correlate → Investigate → Authorise → Respond → Verify → Learn
Every step states what happens, who or what performs it, what evidence it produces and which claim state that evidence carries.
Step 1: Detect
Telemetry from your existing tools is normalised at the customer edge and matched against detections and decoy activity.
- Performed by
- Aegis edge service, through adapters to your existing tools.
- Evidence
- Source events with origin, timestamp and integrity hash, retained in your perimeter.
- Claim state
- OBSERVED
Step 2: Correlate
Related signals across hosts, identities and time are grouped into a candidate incident with a stated confidence.
- Performed by
- Correlation engine, running on the edge or in the control plane on metadata.
- Evidence
- Links between observed events, each with the rule or model that proposed the link.
- Claim state
- INFERRED
Step 3: Investigate
Aegis gathers further context, tests hypotheses and builds a timeline — separating what was seen from what is suspected.
- Performed by
- Investigation agents, with analysts able to review and challenge every step.
- Evidence
- Timeline entries, queries run and artefacts collected, each labelled with its claim state.
- Claim state
- OBSERVEDINFERRED
Step 4: Authorise
Response options are proposed with scope, expected impact and rollback. Policy decides whether a human must approve.
- Performed by
- Policy engine and the named approvers your policy requires.
- Evidence
- The proposal, the policy rule applied, and the approver identity and decision.
- Claim state
- PROPOSED
Step 5: Respond
Approved actions run through the customer-edge service — never through inbound access from the control plane.
- Performed by
- Aegis edge service, using the adapters and credentials you grant it.
- Evidence
- Action record with parameters, executor, start and end time, and result.
- Claim state
- EXECUTED
Step 6: Verify
An independent check confirms whether the action achieved its intended effect, and flags it if not.
- Performed by
- Verification checks, separate from the component that executed the action.
- Evidence
- Verification result and the observations it was based on.
- Claim state
- VERIFIED
Step 7: Learn
Outcomes feed proposed tuning for detections and playbooks. Changes are reviewed before they take effect.
- Performed by
- Learning module proposes; your team or policy approves.
- Evidence
- Versioned change proposals linked to the incidents that motivated them.
- Claim state
- PROPOSED
Claim states
Five labels, used everywhere.
The same claim states appear in incidents, timelines, reports and the evidence vault, so a reader always knows how much weight a statement can bear.
- OBSERVED
Directly seen in source telemetry or evidence. Carries its origin and integrity hash.
- INFERRED
A conclusion drawn by analysis or AI, shown with confidence. Never presented as fact.
- PROPOSED
A recommended action with scope and rollback, awaiting authorisation under policy.
- EXECUTED
An action that has been carried out, with who or what performed it and when.
- VERIFIED
An outcome confirmed by an independent check, separate from the executor.
Governed autonomy
Authorisation is policy, not guesswork.
The Authorise step is where policy decides whether an action may run automatically or needs a named approver. Levels are set per action class.
Level 0: Observe
Aegis detects and records. No investigation or action is taken automatically.
Level 1: Investigate
Aegis gathers context and builds hypotheses. Every response is proposed for human approval.
Level 2: Controlled autonomy
Pre-approved, reversible actions within a defined scope may run automatically. Everything else needs approval.
Level 3: Expanded autonomy
Broader automatic response for explicitly authorised action classes, with verification and rollback enforced.
See exactly what Aegis does when something goes wrong.
We will walk your team through an incident from first signal to verified outcome. You will see what Aegis observed, what it inferred, what it proposed and what actually happened.