How can a model investigate without authority?
Cyberdroid AI Investigation separates judgment from authority. The model decides what to ask, software decides what it may read, and a person accepts the result.
See the methodMethod
Each case starts from Detection findings and SIEM alerts. The model chooses to investigate or monitor, and names the evidence that would disprove it.
The model states an intent. Software turns it into read-only queries, checks every field, fixes the scope and enforces row, time and cost budgets.
Each result carries into later reasoning, with truncation disclosed. When the budget runs out, the case is parked incomplete.
A separate critic tests whether the evidence earns the conclusion. Objections it cannot resolve stay attached to the case.
Verdict, confidence, rationale and evidence references, with disagreement recorded. The case ends in review, for a person to accept.
Measures
Correct and incorrect conclusions, unsupported assertions, cases parked incomplete and reviewer effort, on a labelled set agreed before the first case. We publish the method, not a score.
Limits
AI Investigation is in early access and never remediates. Critique without new evidence can repeat an error, so a person accepts every case.
Sources
Related
Products

Takes a Detection finding or SIEM alert through read-only queries and challenges its own verdict before writing the case.

Cross-source behavioral detection on your SIEM: identity, network, DNS, process and firewall telemetry, baselined against each entity’s own history.