Appearance
KAIDAN: start here
KAIDAN is the Briard-AI security add-on for AI and large language model (LLM) incident response. It helps an authorized response team collect approved metadata, connect related events, investigate what the available evidence supports, and export a custody-verifiable case package.
Open the KAIDAN application at briard-ai.app/Kaidan. KAIDAN is free for every signed-in Briard-AI workspace from August 13, 2026 at 00:00 UTC until August 13, 2027 at 00:00 UTC. Briard-AI records the required organization agreement before enabling the add-on; no paid Briard-AI subscription is required for KAIDAN during this window.
You do not need to be technical to use this guide. Each page tells you:
- who needs to participate;
- what you need before you start;
- what you can do yourself;
- when to hand a step to a technical operator;
- what proof to keep; and
- when to stop instead of guessing.
IMPORTANT
Briard-AI remains your governance and subscription portal. KAIDAN remains the authority for security evidence, cases, connector receipts, findings, and custody verification. Accepting KAIDAN access in Briard-AI does not deploy KAIDAN or connect a source.
Choose your starting point
| Your situation | Start here |
|---|---|
| You want to understand the product first | What KAIDAN does |
| You are a Briard-AI owner or administrator | Access and agreement |
| You are responsible for installing software | Setup and deployment |
| You own cloud, security, observability, or AI tools | Connect sources |
| You are responding to an AI incident | User guide |
| Something is not working | Troubleshooting |
| You need the privacy and evidence rules | Security and data boundaries |
What KAIDAN does
KAIDAN brings together approved event metadata from sources such as:
- AI and LLM runtimes;
- agents and tool calls;
- guardrails and AI security products;
- cloud audit services;
- vector databases;
- OpenTelemetry and observability platforms; and
- SIEM and other security systems.
It then helps responders:
- place related events on a common timeline;
- see where each statement came from;
- separate observed facts from source claims, detector inferences, and human conclusions;
- record missing evidence and contradictions;
- collaborate in a tenant-scoped case; and
- export a package whose custody and integrity can be checked.
What KAIDAN does not do
KAIDAN does not:
- silently block or control an AI system;
- decide whether an incident legally occurred;
- prove intent or causation when the evidence does not;
- turn an alert into a confirmed fact;
- make missing provider receipts appear present;
- replace counsel, an incident-response professional, an assessor, or an executive decision maker; or
- require raw prompts, model responses, files, credentials, secrets, or regulated content through normal intake.
Content-bearing restricted forensic capture is a separate mode. It is disabled by default and must not be enabled through the normal setup path.
The complete customer journey
Phase 1: authorize
A signed-in Briard-AI workspace opens KAIDAN in the sidebar during the fixed free launch-year window. An owner or administrator reads the agreement, checks the authorization box, and accepts. Briard records the agreement version and hash, user, role, workspace, method, request identifier, and timestamp. The free window does not convert automatically into a paid plan.
Phase 2: plan
Assign business, security, platform, identity, and data owners. Decide where KAIDAN will run, which sources are allowed, and which areas are excluded.
Phase 3: deploy
A technical operator uses the signed KAIDAN setup bundle to render a customer-specific plan. The plan must pass preflight and receive five separate approvals before it can be applied.
Phase 4: connect
Each source owner creates a least-privilege credential or workload identity, stores it in the approved secret manager, tests the source, and records the receipt. A source is not “connected” merely because a form was filled out.
Phase 5: validate
Run a fictional metadata-only incident. Confirm events arrive, evidence remains tenant-scoped, unknowns stay visible, and both an online and offline package pass the trusted verifier.
Phase 6: operate
Open cases, investigate, record conclusions, export evidence, monitor source health, rotate credentials, rehearse rollback, and review access on a schedule.
People you may need
One person can hold several roles in a small organization, but the approval record must still show who made each decision.
| Role | Plain-language responsibility |
|---|---|
| Workspace owner or administrator | Accepts the KAIDAN add-on agreement in Briard-AI |
| Security owner | Owns incident-response policy and case decisions |
| Platform operator | Deploys, upgrades, validates, and rolls back KAIDAN |
| Identity owner | Configures sign-in, roles, MFA, and service identities |
| Source owner | Approves and tests each connected data source |
| Data/privacy owner | Approves metadata fields, retention, region, and exclusions |
| Reviewer or auditor | Reads reports and verifies packages without changing setup |
Safe first exercise
Do not begin with a real incident. Use fictional names and metadata:
- incident: “Fictional assistant tool-call anomaly”;
- system: “Sample Support Assistant”;
- user: a pseudonymous identifier;
- source: a test connector or approved synthetic package;
- content: no real prompt, response, customer file, credential, or regulated data.
The exercise is complete only when you can trace an event to its source, identify at least one known gap, record a human conclusion, export the case, and verify the export independently.
Get help
For product and onboarding help, contact support@briard-ai.app. For a suspected security issue involving Briard-AI or KAIDAN, contact security@briard-ai.app.
Never email credentials, tokens, raw prompts, model responses, customer files, or incident evidence.
