Appearance
KAIDAN: start here
KAIDAN is the Briard-AI security add-on for AI and large language model (LLM) incident detection and response. It turns approved metadata into explainable real-time alerts, helps responders connect related activity, and carries the work into an evidence-cited investigation and custody-verifiable case package.
KAIDAN and Briard-AI are products of Unfettered Minds LLC.
Watch a video demo of KAIDAN — an 11-minute, 47-second narrated walkthrough of alerts in Briard, governed case-access choices, evidence review, and the return to policy review. Includes captions, chapters, and a transcript. No sign-in needed.
Open the KAIDAN application at briard-ai.app/Kaidan. KAIDAN is free for every signed-in Briard-AI workspace from August 13, 2026 at 00:00 UTC until August 13, 2027 at 00:00 UTC. Briard-AI records the required organization agreement before enabling the add-on; no paid Briard-AI subscription is required for KAIDAN during this window.
KAIDAN does not automatically convert to a paid plan. For organizations that separately elect to continue after the free window, the KAIDAN platform fee will not exceed $399 USD per organization per month through August 12, 2028. Customer-selected infrastructure, source products, taxes, custom deployment work, and optional professional services are separate.
You do not need to be technical to use this guide. Each page tells you:
- who needs to participate;
- what you need before you start;
- what you can do yourself;
- when to hand a step to a technical operator;
- what proof to keep; and
- when to stop instead of guessing.
IMPORTANT
Briard-AI remains your governance and subscription portal. KAIDAN remains the authority for alerts, situations, security evidence, cases, connector receipts, findings, and custody verification. Accepting KAIDAN access in Briard-AI does not deploy KAIDAN or connect a source.
IMPORTANT
KAIDAN retains platform evidence records and immutable evidence-package objects for 365 days by default. Active legal holds may delay disposition, and customer-controlled external copies follow their own retention controls. Review the full access and agreement notice before enabling KAIDAN.
Choose your starting point
| Your situation | Start here |
|---|---|
| You want to understand the product first | What KAIDAN does |
| You want to see the workflow in action | Watch the KAIDAN video demo |
| You are a Briard-AI owner or administrator | Access and agreement |
| You are responsible for installing software | Setup and deployment |
| You own cloud, security, observability, or AI tools | Connect sources |
| You need to understand or work the alert queue | Alerts and real-time response |
| You need a closer case investigation | Choose what KAIDAN can access |
| You are responding to an AI incident | User guide |
| You need continuity, support, or exit details | Continuity and customer exit |
| Something is not working | Troubleshooting |
| You need the privacy and evidence rules | Security and data boundaries |
What KAIDAN does
KAIDAN brings together approved event metadata from sources such as:
- AI and LLM runtimes;
- agents and tool calls;
- guardrails and AI security products;
- cloud audit services;
- vector databases;
- OpenTelemetry and observability platforms; and
- SIEM and other security systems.
It then helps responders:
- categorize and prioritize meaningful activity as P1–P4 alerts;
- understand the score, confidence, source, and visibility boundary;
- connect related alerts into a situation and common timeline;
- separate observed facts from source claims, detector inferences, and human conclusions;
- acknowledge, assign, hand off, investigate, suppress, or resolve with a reason;
- promote warranted work into a tenant-scoped case; and
- export a package whose custody and integrity can be checked.
What KAIDAN does not do
KAIDAN does not:
- silently block or control an AI system;
- decide whether an incident legally occurred;
- prove intent or causation when the evidence does not;
- turn an alert into a confirmed fact;
- make missing provider receipts appear present;
- replace counsel, an incident-response professional, an assessor, or an executive decision maker; or
- require raw prompts, model responses, files, credentials, secrets, or regulated content through normal intake.
Case-specific content access is separate from metadata-only normal intake, disabled by default, and must not be enabled through the normal setup path. See the two governed choices before requesting a closer investigation.
The complete customer journey
Phase 1: authorize
A signed-in Briard-AI workspace opens KAIDAN in the sidebar during the fixed free launch-year window. An owner or administrator reads the agreement, checks the authorization box, and accepts. Briard records the agreement version and hash, user, role, workspace, method, request identifier, and timestamp. The free window does not convert automatically into a paid plan.
Phase 2: plan
Assign business, security, platform, identity, and data owners. Decide where KAIDAN will run, which sources are allowed, and which areas are excluded.
Phase 3: deploy
A technical operator uses the signed KAIDAN setup bundle to render a customer-specific plan. The plan must pass preflight and receive five separate approvals before it can be applied.
Phase 4: connect
Each source owner creates a least-privilege credential or workload identity, stores it in the approved secret manager, tests the source, and records the receipt. A source is not “connected” merely because a form was filled out.
Phase 5: validate
Run fictional metadata-only observations across all four alert categories. Confirm P1–P4 counts, alert deep links, live updates, evidence scope, tenant isolation, response handoffs, and both an online and offline package through the trusted verifier.
Phase 6: operate
Triage alerts, monitor situations, open cases, record response handoffs and conclusions, export evidence, monitor source health, rotate credentials, rehearse rollback, and review access on a schedule.
People you may need
One person can hold several roles in a small organization, but the approval record must still show who made each decision.
| Role | Plain-language responsibility |
|---|---|
| Workspace owner or administrator | Accepts the KAIDAN add-on agreement in Briard-AI |
| Security owner | Owns incident-response policy and case decisions |
| Platform operator | Deploys, upgrades, validates, and rolls back KAIDAN |
| Identity owner | Configures sign-in, roles, MFA, and service identities |
| Source owner | Approves and tests each connected data source |
| Data/privacy owner | Approves metadata fields, retention, region, and exclusions |
| Reviewer or auditor | Reads reports and verifies packages without changing setup |
Safe first exercise
Do not begin with a real incident. Use fictional names and metadata:
- alert: “Fictional assistant tool-call anomaly”;
- system: “Sample Support Assistant”;
- user: a pseudonymous identifier;
- source: a test connector or approved synthetic package;
- content: no real prompt, response, customer file, credential, or regulated data.
The exercise is complete only when you can generate and acknowledge an alert, explain its priority and category, trace an event to its source, identify at least one known gap, promote warranted work to a case, record a human conclusion, export the case, and verify the export independently.
Get help
For product and onboarding help, contact support@briard-ai.app. For a suspected security issue involving Briard-AI or KAIDAN, contact security@briard-ai.app.
Never email credentials, tokens, raw prompts, model responses, customer files, or incident evidence.
