Explained by authorization
noulDoes a valid, matching authorization or maintenance record explain the observed activity?
Jev example · Security triage
Give the model an explicit incomplete-information case.
This is the context Jev receives before answering the typed question.
{
"alert": "Unusual process activity",
"asset": "unknown",
"process_details": null,
"owner": null,
"authorization_lookup": "failed"
}Does a valid, matching authorization or maintenance record explain the observed activity?
Select a review route from available evidence. Do not execute any containment.
How strong is the evidence of unauthorized activity?
Add a known owner and the process command summary.
Catalog source: TypeSafeAI/typesafe-playground, reused under MIT. This is an independent community catalog, not an official TypeSafe AI product.
Background source: Inspired by TypeSafe workflow evals; examples authored for this playground