AI workflows

Twelve investigations.
Already shipped.

Every workflow ships with a golden eval set, a published accuracy number, and a configurable approval policy. Run them in shadow before you trust them in production.

Workflow docs →
Sample · phishing triage

Watch an investigation, end to end.

01

Ingest report

User-reported phishing · subject "Q4 invoice review" · sender finance@acm3.com

PLAN
02

Header + URL analysis

SPF fail · DKIM none · domain registered 6 days ago · 1 URL → typosquat

INVESTIGATE
03

Detonate URL

Sandbox · credential-harvesting page · brand impersonation: Microsoft 365

INVESTIGATE
04

Identify exposure

M365 logs · 3 users opened · 1 clicked · 0 submitted credentials

INVESTIGATE
05

Verify

Verifier model: confidence 0.94 · pass

VERIFY
06

Respond

Quarantine across mailboxes · force MFA on clicker · ticket opened in Jira

RESOLVE
Catalog

Production workflows.

Tier-1

Phishing triage

End-user-reported and gateway-detected. Auto-quarantine, user notify, identity step-up.

Acc 97.2% · 4s median

Tier-1

Suspicious login

Impossible travel, new device, residential proxy, atypical OS — enriched + verdicted.

Acc 96.8% · 11s

Tier-1

EDR alert triage

CrowdStrike, SentinelOne, Defender. Process tree + RTR pivots + verdict.

Acc 94.5% · 18s

Tier-2

Lateral movement hunt

Auth graph + Kerberos + SMB usage. Builds a timeline, scopes blast radius.

Acc 89.4% · 2m

Tier-2

Ransomware containment

Two-person approval. Isolate host, revoke sessions, rotate creds, snapshot.

Acc 95.1% · 38s

Tier-2

Cloud misconfig sweep

AWS / Azure / GCP. Drift detection + IAM blast radius + remediation PR.

Acc 92.7% · 1m

Hunt

Identity risk review

Weekly digest of privilege drift, stale access, MFA gaps, OAuth grants.

Scheduled

Hunt

Insider risk review

DLP + Git + email egress. Pattern-based, human-confirmed.

Scheduled

Hunt

Threat-intel sweep

New IOC drops → retro-hunt against 90 days of logs.

Scheduled

Custom

Vendor account review

Per-vendor SaaS account hygiene with auto-revocation paths.

Customizable

Custom

DLP investigation

Triage outbound data events — attribute, classify, escalate.

Customizable

Custom

Bring your own

Define a workflow in plain English. Triago ships a draft + evals within 48h.

Forward-deployed

Run a workflow on your data.

Shadow mode for 7 days. Real verdicts. Real numbers.

Start pilot