Skip to content

Alerts and real-time response

KAIDAN watches approved metadata from connected AI, agent, cloud, guardrail, vector, observability, and security sources. It turns meaningful changes into a prioritized response queue while keeping the score, source, uncertainty, and evidence boundary visible.

The shortest operating path is:

Observation → Alert → Situation → Case → Response handoff → Verifiable package

An alert tells a person where to look. It is not proof that an attack, breach, policy violation, or legal incident occurred.

What appears in Briard-AI

Workspace owners and administrators see a small KAIDAN summary on the Briard-AI dashboard:

  • total active alerts;
  • P1, P2, P3, and P4 counts;
  • counts for each AI incident category;
  • the highest-priority alert titles; and
  • protected links that open the selected alert in KAIDAN.

The summary contains no raw prompts, model responses, files, secrets, or full evidence records. Briard-AI creates a short-lived, tenant-scoped KAIDAN session only after the organization agreement, role, and recent authentication are checked. KAIDAN remains the authority for the alert and its evidence.

Four categories

CategoryWhat it covers
Attack & integrityPrompt injection, model manipulation, integrity changes, guardrail failures, and suspicious source behavior
Access & dataUnexpected identities, retrieval exposure, sensitive-data access patterns, and permission changes
Agent actionsTool calls, autonomous steps, execution paths, and actions outside an approved boundary
Misuse & operational impactAbuse, anomalous volume, service impact, cost spikes, and harmful business outcomes

The category helps route the alert. It does not decide the final incident classification.

P1–P4 priorities

PriorityPlain-language meaningExpected first action
P1Immediate and potentially severe impactAcknowledge now and begin the response process
P2High risk or meaningful spreadReview promptly and assign an owner
P3Concerning behavior that needs investigationReview in the normal response queue
P4Low-risk or early signalMonitor, tune, or document why no action is needed

KAIDAN weighs factors such as severity, confidence, affected asset importance, spread, and operational impact. Open the alert to see why it received its current priority. A high score is a detector inference, not an observed fact.

Real-time delivery

The Alerts page updates through a live event stream when the network and deployment support it. If the live stream is interrupted, KAIDAN falls back to bounded refresh checks and shows that the view is reconnecting or temporarily stale.

Do not claim continuous coverage unless:

  • expected connectors are healthy;
  • recent source receipts are present;
  • the alert view is current; and
  • the relevant policy is enabled.

Missing receipts remain a documented visibility gap.

Work an alert

  1. Open Alerts.
  2. Start with P1, then P2.
  3. Confirm the tenant, environment, time, category, priority, confidence, and visibility boundary.
  4. Review the score explanation and contributing metadata.
  5. Open the timeline and related alerts.
  6. Acknowledge the alert so the team knows a person owns the first review.
  7. Choose the next honest state: investigate, wait for customer action, suppress with a reason, resolve with a reason, or promote to a case.

Acknowledging means “a responder has seen this.” It does not mean the alert is true or contained.

Situations and cases

KAIDAN groups alerts that share meaningful metadata into a situation. A situation helps the responder see possible spread without prematurely declaring one root cause.

Promote an alert or situation to a case when the work needs a durable investigation record, multiple owners, formal conclusions, or a custody-verifiable export. The case retains the originating alert references and their evidence boundaries.

Response handoffs

KAIDAN can create metadata-only response handoffs for configured destinations such as email, a signed webhook, PagerDuty, or ServiceNow. A handoff records what KAIDAN requested or reported. It does not prove that the destination received, executed, or independently verified an action.

Keep these states separate:

  1. proposed;
  2. approved;
  3. sent;
  4. accepted by the destination;
  5. reported as executed; and
  6. independently verified.

KAIDAN does not silently block an AI system or execute a containment decision as an inline control.

Tune without hiding risk

Use suppression, snoozing, and rule controls only with a named owner, reason, scope, and expiration where appropriate. Before changing a rule:

  • review recent examples;
  • confirm which category and environment are affected;
  • check whether a missing source caused the noise;
  • preserve the change record; and
  • test the result with fictional metadata.

Never reduce noise by deleting evidence or relabeling an inference as a fact.

Safe first exercise

Use fictional metadata to generate at least one alert in every category and at least one P1 and P2. Then:

  1. confirm the dashboard summary counts match KAIDAN;
  2. open a protected alert link from Briard-AI;
  3. review its score and visibility boundary;
  4. acknowledge it;
  5. inspect its situation timeline;
  6. record a metadata-only response handoff;
  7. promote one alert to a case;
  8. record a human conclusion; and
  9. export and independently verify the package.

The exercise must use no real prompt, response, customer file, credential, secret, or regulated data.

Briard-AI and KAIDAN are products of Unfettered Minds LLC. Governance documentation and review support. Not legal advice or certification.