Appearance
Alerts and real-time response
KAIDAN watches approved metadata from connected AI, agent, cloud, guardrail, vector, observability, and security sources. It turns meaningful changes into a prioritized response queue while keeping the score, source, uncertainty, and evidence boundary visible.
The shortest operating path is:
Observation → Alert → Situation → Case → Response handoff → Verifiable package
An alert tells a person where to look. It is not proof that an attack, breach, policy violation, or legal incident occurred.
What appears in Briard-AI
Workspace owners and administrators see a small KAIDAN summary on the Briard-AI dashboard:
- total active alerts;
- P1, P2, P3, and P4 counts;
- counts for each AI incident category;
- the highest-priority alert titles; and
- protected links that open the selected alert in KAIDAN.
The summary contains no raw prompts, model responses, files, secrets, or full evidence records. Briard-AI creates a short-lived, tenant-scoped KAIDAN session only after the organization agreement, role, and recent authentication are checked. KAIDAN remains the authority for the alert and its evidence.
Four categories
| Category | What it covers |
|---|---|
| Attack & integrity | Prompt injection, model manipulation, integrity changes, guardrail failures, and suspicious source behavior |
| Access & data | Unexpected identities, retrieval exposure, sensitive-data access patterns, and permission changes |
| Agent actions | Tool calls, autonomous steps, execution paths, and actions outside an approved boundary |
| Misuse & operational impact | Abuse, anomalous volume, service impact, cost spikes, and harmful business outcomes |
The category helps route the alert. It does not decide the final incident classification.
P1–P4 priorities
| Priority | Plain-language meaning | Expected first action |
|---|---|---|
| P1 | Immediate and potentially severe impact | Acknowledge now and begin the response process |
| P2 | High risk or meaningful spread | Review promptly and assign an owner |
| P3 | Concerning behavior that needs investigation | Review in the normal response queue |
| P4 | Low-risk or early signal | Monitor, tune, or document why no action is needed |
KAIDAN weighs factors such as severity, confidence, affected asset importance, spread, and operational impact. Open the alert to see why it received its current priority. A high score is a detector inference, not an observed fact.
Real-time delivery
The Alerts page updates through a live event stream when the network and deployment support it. If the live stream is interrupted, KAIDAN falls back to bounded refresh checks and shows that the view is reconnecting or temporarily stale.
Do not claim continuous coverage unless:
- expected connectors are healthy;
- recent source receipts are present;
- the alert view is current; and
- the relevant policy is enabled.
Missing receipts remain a documented visibility gap.
Work an alert
- Open Alerts.
- Start with P1, then P2.
- Confirm the tenant, environment, time, category, priority, confidence, and visibility boundary.
- Review the score explanation and contributing metadata.
- Open the timeline and related alerts.
- Acknowledge the alert so the team knows a person owns the first review.
- Choose the next honest state: investigate, wait for customer action, suppress with a reason, resolve with a reason, or promote to a case.
Acknowledging means “a responder has seen this.” It does not mean the alert is true or contained.
Situations and cases
KAIDAN groups alerts that share meaningful metadata into a situation. A situation helps the responder see possible spread without prematurely declaring one root cause.
Promote an alert or situation to a case when the work needs a durable investigation record, multiple owners, formal conclusions, or a custody-verifiable export. The case retains the originating alert references and their evidence boundaries.
Response handoffs
KAIDAN can create metadata-only response handoffs for configured destinations such as email, a signed webhook, PagerDuty, or ServiceNow. A handoff records what KAIDAN requested or reported. It does not prove that the destination received, executed, or independently verified an action.
Keep these states separate:
- proposed;
- approved;
- sent;
- accepted by the destination;
- reported as executed; and
- independently verified.
KAIDAN does not silently block an AI system or execute a containment decision as an inline control.
Tune without hiding risk
Use suppression, snoozing, and rule controls only with a named owner, reason, scope, and expiration where appropriate. Before changing a rule:
- review recent examples;
- confirm which category and environment are affected;
- check whether a missing source caused the noise;
- preserve the change record; and
- test the result with fictional metadata.
Never reduce noise by deleting evidence or relabeling an inference as a fact.
Safe first exercise
Use fictional metadata to generate at least one alert in every category and at least one P1 and P2. Then:
- confirm the dashboard summary counts match KAIDAN;
- open a protected alert link from Briard-AI;
- review its score and visibility boundary;
- acknowledge it;
- inspect its situation timeline;
- record a metadata-only response handoff;
- promote one alert to a case;
- record a human conclusion; and
- export and independently verify the package.
The exercise must use no real prompt, response, customer file, credential, secret, or regulated data.
