Explained by authorization
noulDoes a valid, matching authorization or maintenance record explain the observed activity?
Jev example · Security triage
Evaluate a potentially alarming action in an approved environment.
This is the context Jev receives before answering the typed question.
{
"alert": "Scheduled script created",
"asset": {
"environment": "sandbox",
"owner": "developer"
},
"change": {
"approved": true,
"scope": "Nightly build cleanup"
},
"script_summary": "Deletes temporary build files only"
}Does a valid, matching authorization or maintenance record explain the observed activity?
Select a review route from available evidence. Do not execute any containment.
How strong is the evidence of unauthorized activity?
Change the scope to include credential files.
Catalog source: TypeSafeAI/typesafe-playground, reused under MIT. This is an independent community catalog, not an official TypeSafe AI product.
Background source: Inspired by TypeSafe workflow evals; examples authored for this playground