Investigations ship enabled for new tenants. Edg3 assembles bounded evidence from the lakehouse and asks the configured reasoning provider for a structured verdict. Analysts see the cited evidence, ATT&CK context, confidence and gate result, and every investigation is labelled with the signal that triggered it. Their decisions are retained in the investigation history rather than silently changing the underlying record.
Edg3 does not make product authority depend on a model name. The investigation service builds a structured evidence pack, applies a versioned prompt contract, validates the response schema and subjects the result to deterministic grounding and approval rules. Provider availability is a tenant configuration choice.
Detections, reusable query results and retrieved context are presented as bounded evidence rather than unrestricted access to the tenant.
The default investigation path targets an Edg3-operated local model endpoint. External provider adapters require explicit tenant configuration.
The service records the model used and preserves one verdict schema across supported local and explicitly enabled external adapters.
Grounding checks, rate limits, confidence policy and human approval determine what can progress. The model does not gain direct response authority.
A proposed verdict is useful only when the analyst can inspect its basis. The investigation record includes the available evidence, ATT&CK context, confidence, provider identity and deterministic gate result.
The displayed fields depend on the evidence available for that case. Analysts can use the retained context to reproduce pivots and compare the proposal with the underlying events.
Confirmations, downgrades and reclassifications are recorded with the investigation. They provide review evidence and can inform a separately governed model evaluation process; they do not automatically retrain a production model.
Detection engine fires on a rule or anomaly. Supported endpoint verdicts and cloud-side analytics detections enter one tenant-scoped investigation path. The Edg3 cloud pulls cross-source context (endpoint, network, cloud, identity) from the lakehouse.
The provider returns a structured verdict with technique context, evidence references and confidence. Invalid or ungrounded responses fail the deterministic checks.
Cited evidence is one-click reproducible. Analyst confirms, overrides, or reclassifies. Disagreement is logged with reason code.
The analyst decision and reason remain in the append-only investigation log for review, reporting and controlled evaluation.
Prompt, model or policy changes can be tested against retained cases before a new version is selected for production.
Investigation context is sent only to the inference endpoint selected for the tenant. The default path is local-first; external providers require explicit opt-in and should be assessed against the customer’s data-handling policy. Model calls pass through an observability layer that records latency, usage and outcome, with sensitive content redacted from retained telemetry by default. Recursion controls stop the platform investigating its own investigation traffic, and if the inference path is unavailable, detection and alerting continue unchanged; investigations resume when it recovers. A fully self-hosted, no-egress deployment remains on the roadmap. No-egress · Q4 2026
The investigation service gathers repeatable query results and cited context before the analyst opens the case. This shifts effort from manual context assembly toward validation, judgement and response. Results still depend on telemetry quality, query latency and the configured inference provider.
For MSSPs, the same structure can standardise how investigations are assembled across the tenants an analyst is authorised to review, while keeping the underlying records scoped.