Jev example · Security triage

An alert during approved maintenance

Check whether the approval actually matches the activity.

Workflows & decisionsnoulchoicescore

State

This is the context Jev receives before answering the typed question.

{
  "alert": "Remote service restarted on staging-app-2 at 02:15",
  "change": {
    "approved": true,
    "asset": "staging-app-2",
    "window": "02:00–03:00",
    "scope": "Restart service"
  },
  "observed_actor": "approved-ops"
}

Typed questions (3)

Explained by authorization

noul

Does a valid, matching authorization or maintenance record explain the observed activity?

Try in Playground

Triage route

choice

Select a review route from available evidence. Do not execute any containment.

Try in Playground
  • close | Documented benign activity
  • investigate | Ambiguous or incomplete evidence
  • urgent_review | Strong indicators of active unauthorized activity

Evidence strength

score

How strong is the evidence of unauthorized activity?

Try in Playground
  • Benign or no supporting evidence
  • Weak signal
  • Multiple credible signals
  • Direct evidence of compromise

Try changing the scenario

Change the asset to a production server outside the approval.

Catalog source: TypeSafeAI/typesafe-playground, reused under MIT. This is an independent community catalog, not an official TypeSafe AI product.

Background source: Inspired by TypeSafe workflow evals; examples authored for this playground