Automated Alert Triage
Every alert triaged before your analyst sees it
The Triage agent runs a 12-point evaluation on every finding — indicator reputation, entity history, behavioral anomaly, geolocation — and delivers a confidence-scored verdict with full evidence before the alert enters the analyst queue.
20s
average triage time per alert
95%
analyst time saved per alert
85–95%
auto-closure rate after 90 days
100%
alert coverage — no alert left unreviewed
How triage works
Structured verdict on every alert
The Triage agent evaluates every finding against a 12-point protocol covering indicator reputation, entity history, behavioral anomaly, timing, and geolocation. The output is a structured verdict — true positive, false positive, or escalated — with a 0–100 confidence score.
- 12-point structured evaluation protocol
- Confidence score from 0 to 100 per alert
- Verdict rationale stored per case for audit
Structured verdict on every alert
Evidence package before the analyst sees it
Every escalated alert arrives with a pre-assembled evidence package: IP reputation, domain age, WHOIS, entity timeline, similar past alerts, and the triage agent's reasoning chain. Analysts make decisions with full context, not half-facts.
- IP reputation and threat intel lookups automated
- Entity behavioral history across 90 days
- Related alert correlation across the same entity
Evidence package before the analyst sees it
False positives closed automatically
Alerts the Triage agent classifies as false positives are closed with a documented rationale — the rule that fired, why the evidence doesn't support escalation, and the entity history that informed the assessment. No more silent false positive accumulation.
- 85–95% auto-closure rate after 90-day tuning period
- Closure rationale available for compliance review
- Analyst can override and escalate any auto-closed alert
False positives closed automatically
Before and after automated triage
Before ManySignal
- 200+ alerts per day, manually reviewed by 2–3 analysts
- Most alerts reviewed 4–8 hours after firing
- 30–40% of alert backlog never touched
- Analysts spend 70% of time on false positives
- Real threats buried in the queue
- No documentation on why alerts were closed
After ManySignal
- 200+ alerts triaged automatically in 20 seconds each
- Confidence score and verdict before analyst sees the alert
- Zero untriaged alert backlog
- Analysts review 10–20 pre-packaged escalations per day
- Every real threat escalated within 90 seconds of detection
- Full documentation on every closure decision
Alert triage — common questions
What is the triage agent's evaluation protocol based on?
The 12-point protocol covers: indicator reputation (IP, domain, hash), entity behavioral baseline deviation, peer-group anomaly, authentication pattern, geolocation, timing, privilege level, data access volume, lateral movement indicators, threat intelligence match, prior incident history, and alert rule age. Each dimension is scored and weighted in the final confidence score.
How long does it take to triage one alert?
The triage agent completes a full 12-point evaluation in 20–45 seconds for most alert types. Complex cases involving lateral movement correlation or multi-entity analysis may take 60–90 seconds. In all cases, the agent completes its work before a human sees the alert.
Can we configure the triage thresholds ourselves?
Yes. The confidence score threshold for auto-closure, the threshold for autonomous escalation, and the threshold requiring approval are all configurable in the platform UI. You can set different thresholds per rule category, data source, or asset criticality level.
What data sources inform the triage decision?
The triage agent draws on all connected sources: threat intelligence feeds, entity graph history, WHOIS and IP reputation databases, endpoint telemetry, identity provider logs, and cloud activity logs. Sources that aren't yet connected are flagged in the evidence package as gaps.
How does auto-closure differ from just suppressing alerts?
Alert suppression discards events that match a rule — they're gone. Auto-closure evaluates the alert, determines it's a false positive based on specific evidence, documents that evidence, and closes the case with a rationale. The alert is preserved in the audit log. You can search closed alerts, review closure rationale, and audit the triage agent's decisions.
What happens when the triage agent is uncertain — low confidence but not clearly a false positive?
Alerts below the escalation confidence threshold but above the auto-closure threshold are placed in a 'pending review' state and routed to the analyst queue with the agent's partial evidence and the specific questions it couldn't answer. Analysts see exactly why the agent was uncertain, which focuses their investigation rather than leaving them with a blank slate.
Can we audit the triage agent's decisions and override them when we disagree?
Yes. Every triage decision is fully auditable: the 12-point protocol scores, the data sources queried, the confidence score calculation, and the resulting verdict are all logged and viewable. Analysts can override a false-positive closure (re-open the case with a rationale) or escalate a triage verdict they disagree with. Overrides are tracked and fed back into the system to improve future triage accuracy on similar alerts.
How quickly does triage accuracy improve after deployment?
The triage agent's false positive rate decreases measurably in the first two weeks as behavioral baselines initialize and the agent learns your environment's normal patterns. Most customers see 70–80% auto-closure coverage by the end of week one, reaching the typical 85–95% range by week six. The improvement curve is visible in the SOC metrics dashboard — you can see accuracy improving per alert category over time.
Does automated triage create any compliance risk around regulated data in alerts?
No. The triage agent processes log events and metadata — not the content of emails, documents, or personal records. It evaluates indicators, entity behavior, and contextual signals. Evidence packages stored with closed alerts contain the same event metadata that would appear in your SIEM. The triage decisions and rationales are audit trail entries, which auditors consistently treat as evidence of effective monitoring, not a compliance liability.
See triage run on your real alert queue
Connect your noisiest data source. We'll run the triage agent against your live alert queue in the first session and show you verdicts, confidence scores, and the evidence package for each finding.