
Centric-AI Fabric
Decisions driven by meaning, not volume.
The intelligence architecture of ClearSkies iISOC.
Most platforms add intelligence beside the security stack, so the models reason over whatever each product chose to raise. Here every normalized event is resolved into one shared context model before anything is adjudicated.
The architectural choice
Placement is an architectural decision, not a packaging one
Security operations today, per independent research.
Intelligence beside the stack
- Reasons only over what each product chose to raise
- Inherits every product's judgment about severity
- One identity counted twice when two sources name it differently
- No chain, no owner, no record of why the one that mattered closed
Intelligence inside the platform
- Reasons over the whole normalized record, not just the alerts
- One comparable score, so prioritization means something across layers
- One identity, one chain, one incident, one owner
- Every decision written to an immutable record of actor, evidence and action
How it works
From a normalized event to a recorded decision
Resolve
Events map onto six entity types: user, host, identity, domain, asset and session. What cannot be resolved with confidence is surfaced, not merged.
Enrich
Each entity gains what no single detection carries: criticality and business role, tenant policy, baselines and intelligence matches.
Sequence
Related events join on shared entities and time into a chain mapped to MITRE ATT&CK, and position in the chain feeds scoring.
Decide
The Risk Scoring Formula produces one score comparable across every layer, and response runs through SOAR and Playbooks within tenant policy.
Every outcome, override and service-level result returns to the model, so scoring and routing improve with each incident.
Generative, agentic and governed
What may act unattended is a policy decision, not a model decision
The generative layer
Explains
It writes the incident narrative and the reasoning behind a ranking, and the evidence behind any passage can be opened.
The agentic layer
Works
It gathers missing evidence, validates indicators and tests the benign explanations before anything is escalated.
| Level | What reaches it | What it may do |
|---|---|---|
| AI-SecOps Autonomous Analysts | Routine, high volume, lower risk | Triages and investigates. Acts only where policy allows. |
| Human first line | Medium risk | Confirms before action. Corrections are recorded as overrides. |
| Human senior line | High risk and complex chains | Decides at every gate. |
Cross-layer visibility
Four detections. Three of them dismissible alone.
A finance user signs in from an unfamiliar network, then registers a new MFA method.
Lookups of a recently registered domain, from a host known only by IP address.
A signed binary spawns a scripting host under an account unknown to the directory.
The asset carries a finance role, and the account never signs in outside business hours.
In ClearSkies iISOC
All four resolve to one identity and one ATT&CK chain. One incident, one score, one owner, and the lowest-severity input is what lifts it from medium to high.
Beside the stack
Four alerts in four consoles on severity scales that do not compare, one identity counted twice, no chain and no owner.
Inside the platform
One model, twelve Core Functions drawing on it
The iCollector normalizes inside your trust boundary, the Fabric resolves and enriches, the TDIR Engine orchestrates. Every connector runs both ways.
Detection Factory
Receives resolved entities and outcome feedback. Returns detection logic and technique mapping.
Risk Scoring Formula
Receives business impact, confidence, chain position and tenant context. Returns the score that drives ranking.
Intelligent Alert Routing
Receives the ranked alert and its evidence set. Returns the assignment and escalation decision.
Generative and Agentic AI
Receives the evidence and entity context the models operate on. Returns narratives, findings and proposed actions.
SOAR and Playbooks
Receives incident context and the technique that selects a playbook. Returns execution results as new evidence.
Threat Hunting
Receives the entity model a hypothesis is tested against, and generated hypotheses. Returns hunt findings.
Threat Intelligence
Receives observed indicators for enrichment. Returns intelligence that raises or lowers confidence.
UEBA
Receives resolved identity and asset history. Returns baselines and deviations that enter scoring as context.
KPIs and SLAs
Receives the decision record and its timestamps. Returns service-level state, which re-prioritizes work before a breach.
Regulatory Frameworks
Receives the audit trail and technique coverage. Returns the obligations that shape what must be evidenced.
Third-Party Add-ons Marketplace
Receives context for third-party controls reached during response. Returns third-party telemetry.
AI-SecOps Autonomous Analysts
Receives case context and evidence for triage of low-level alerts. Returns triage outcomes and analyst feedback.
Select a function to see what it receives from the Fabric and what it returns.
A native add-on is different. It reports its findings to the engine and receives nothing back.
Detection Factory. Receives resolved entities and outcome feedback. Returns detection logic and technique mapping.
Risk Scoring Formula. Receives business impact, confidence, chain position and tenant context. Returns the score that drives ranking.
Intelligent Alert Routing. Receives the ranked alert and its evidence set. Returns the assignment and escalation decision.
Generative and Agentic AI. Receives the evidence and entity context the models operate on. Returns narratives, findings and proposed actions.
SOAR and Playbooks. Receives incident context and the technique that selects a playbook. Returns execution results as new evidence.
Threat Hunting. Receives the entity model a hypothesis is tested against, and generated hypotheses. Returns hunt findings.
Threat Intelligence. Receives observed indicators for enrichment. Returns intelligence that raises or lowers confidence.
UEBA. Receives resolved identity and asset history. Returns baselines and deviations that enter scoring as context.
KPIs and SLAs. Receives the decision record and its timestamps. Returns service-level state, which re-prioritizes work before a breach.
Regulatory Frameworks. Receives the audit trail and technique coverage. Returns the obligations that shape what must be evidenced.
Third-Party Add-ons Marketplace. Receives context for third-party controls reached during response. Returns third-party telemetry.
AI-SecOps Autonomous Analysts. Receives case context and evidence for triage of low-level alerts. Returns triage outcomes and analyst feedback.
Governance and assurance
Evidence a risk officer can use
| Standard or framework | Role in the intelligence layer | Position |
|---|---|---|
| MITRE ATT&CKEnterprise, Cloud, Identity | Technique vocabulary for sequencing and scoring | Supported |
| OCSF | Schema alignment for resolved events | Aligned |
| STIX and TAXII | Structured intelligence in enrichment | Supported |
| EU AI Act | Governance of the AI functions deployed | Evidenced |
| NIST AI Risk Management Framework 1.0 | Practice framework for AI risk | Aligned |
| ISO/IEC 27001 and 27002 | Control mapping and audit evidence | Evidenced |
| NIS2, DORA and GDPR | Reporting, resilience and decision transparency | Evidenced |
The platform produces the evidence these duties require. It does not deliver compliance. The resolved model, the scores and the decision record can all be exported.
Outcomes
What it delivers
End user
For the security team
- Fidelity
- Ranking reflects business impact, confidence and chain position, not alert counts.
- Investigation
- Work starts from an assembled account with its evidence attached.
- Defensibility
- Every conclusion traces to its evidence and every action to its actor.
Service provider
For the managed security provider
- Coverage
- One team serves many tenants, because the virtual analyst absorbs routine triage.
- Federated learning
- Detection improves across the whole book, with no tenant data crossing the isolation boundary.
- Commercial model
- Outcome-based delivery becomes credible, with dwell time and service-level attainment measured per tenant.
The layer, in one line