Appearance
Choose what KAIDAN can access
Start with the alert or case you want to investigate. KAIDAN's Access for this investigation card shows routine monitoring separately from any extra access for that case. You do not need to expand Review details or enter Expert view to find it. Open KAIDAN from the selected item in Briard-AI to keep the alert or case navigation context. Sign-in and any required phone-code check still apply. KAIDAN checks your actual workspace, role, case, source, policy, and permissions; Briard-AI does not grant or copy case access.
The screenshots below show a fictional local candidate, not a live customer source. Source choices, requests, and approvals shown in this walkthrough were simulated in the browser; no provider ran and no person approved a real request.


What happens without an extra request?
Routine monitoring: Metadata only. KAIDAN records facts about approved events, such as time, source, tool, and outcome. It does not collect message or file contents through normal intake. You can keep monitoring without submitting anything. A case may separately have an approved, active, completed, failed, or unknown extra-access request; the routine-monitoring sentence is not the case's overall access status. Read the case's actual request history in KAIDAN. If status cannot be loaded, use Retry rather than assuming no extra access.
Two choices for a closer look
| Choice shown in KAIDAN | What it can examine | What may be kept for this case |
|---|---|---|
| Analyze and keep findings (Private analysis) | Approved content inside your environment, within the case and source limits | Findings and receipts, not the original content as case evidence |
| Collect selected evidence (Case forensics) | Only approved items for this case, within the case and source limits | Approved originals in a protected customer quarantine. Keeping exact files in an evidence vault requires a separate later decision and vault controls |
These labels describe case retention, not every temporary processing step or copies still held by the original source. A case-forensics request has a policy maximum retention; exact vault retention is a separate later promotion decision. Neither choice deletes existing evidence, enables an unconfigured source, or proves provider collection is ready. Normal event intake remains metadata-only. Extra access requires a linked case, an eligible approved source, an active privacy policy, a bounded purpose and scope, and the existing authorization controls.

The three request screens
- Choose the check. Open Request deeper investigation on the access card. Compare both choices before selecting one. Keep metadata only leaves without sending a request. Opening, cancelling, or leaving a draft grants no access.
- Tell us what to check. Confirm the linked case and friendly source name. Explain why this case needs the check. Review the proposed material, time range, item and size limits, and required storage or retention. KAIDAN may fill known facts and narrow limits from trusted records, but it must not invent a purpose, permission, source, policy, or readiness. An authorized person must resolve anything missing.
- Review and send. Read the exact proposed case, tool, source, material, limits, purpose, expiry, retention and handling, and who may approve. Keep the least-evidence confirmation. A broader scope needs its required reason. Technical details shows exact identifiers and policy versions without hiding a required privacy or retention decision. Send for approval creates a request; it does not start collection.



This capture shows a proposed request, not an approval or a provider collection.
The request and decision history stays in KAIDAN. Two distinct eligible people other than the requester must approve before extra access can be authorized. Reviewers see the same plain summary and the exact underlying restrictions. They record their decisions and reasons in KAIDAN; Briard-AI does not approve on their behalf.
Expert controls can still accept a legacy customer-side connector ID when no named source choice is available. Manual entry is not source verification, activation, or permission; the bounded request still needs the same review and approvals. The ordinary guided path uses friendly names from configured choices and does not ask a requester to type a connector, encryption-key, or region ID when approved configuration already supplies it.
Read the actual state, not a reassuring guess
| KAIDAN state | What it means |
|---|---|
| Waiting for approval — 0 of 2 / 1 of 2 | The request has not started collection. |
| Approved — collection has not started | Both approvals exist; this alone is not evidence that a source ran. |
| Investigation in progress | Supported by the actual collection state. |
| Some evidence received | Collection is partial; inspect what remains missing. |
| Request completed | Inspect receipts, findings, and actual handling outcomes. Completion does not mean the incident is fixed. |
| Denied, expired, or failed | Read the reason and permitted next action. Expiry does not mean previously collected evidence was deleted. |
| Access status unavailable | Retry. Do not infer that access is off or on. |
Several requests may exist for one case. Read all of them in KAIDAN's authoritative request history rather than relying on one badge. A response request being sent is a separate event and does not prove remediation or independent verification.


If you cannot continue
| What is missing | Safe next step |
|---|---|
| No linked case | Use KAIDAN's authorized Create a case to continue path; do not create a case silently. |
| Your role cannot request or review | Use the displayed authorized help path. Do not borrow another account or bypass sign-in. |
| Source, privacy policy, storage, or retention is not ready | An authorized administrator or operator completes the customer-managed KAIDAN setup or deployment binding, with case context preserved. Do not invent a source or default a required decision to “none.” |
| Sign-in is old | Complete the existing sign-in or phone-code check. The selected navigation context may resume, but KAIDAN rechecks tenant, role, case, and source. |
| Request expired, denied, partial, or failed | Read the actual history and the allowed next action. Do not treat expiry as evidence deletion, or a partial result as a completed collection. |
There is no implied Stop access or Delete evidence shortcut. Those actions require separate backend authorization, collection, retention, and legal-hold controls. Do not put raw prompts, model replies, customer files, credentials, or secrets in a support message or ordinary case comment.
For the broader alert workflow, see Alerts and real-time response. For security controls, see Security and data boundaries. For access problems, see Troubleshooting. For product help, contact support@briard-ai.app with safe record identifiers and timestamps only.
