Telemetry from many sources flowing through the Centric-AI Fabric into entity-level risk scores

Centric-AI Fabric

Decisions driven by meaning, not volume.

The intelligence architecture of ClearSkies iISOC.

Most platforms add intelligence beside the security stack, so the models reason over whatever each product chose to raise. Here every normalized event is resolved into one shared context model before anything is adjudicated.

The architectural choice

Placement is an architectural decision, not a packaging one

Security operations today, per independent research.

46%of alerts are false positivesMicrosoft and Omdia, State of the SOC 2026
42% to 63%of alerts never investigatedVectra AI and Omdia, 2026
40%higher labor cost when operations fragmentMicrosoft and Omdia, as above

Intelligence beside the stack

  • Reasons only over what each product chose to raise
  • Inherits every product's judgment about severity
  • One identity counted twice when two sources name it differently
  • No chain, no owner, no record of why the one that mattered closed

Intelligence inside the platform

  • Reasons over the whole normalized record, not just the alerts
  • One comparable score, so prioritization means something across layers
  • One identity, one chain, one incident, one owner
  • Every decision written to an immutable record of actor, evidence and action

How it works

From a normalized event to a recorded decision

1

Resolve

Events map onto six entity types: user, host, identity, domain, asset and session. What cannot be resolved with confidence is surfaced, not merged.

2

Enrich

Each entity gains what no single detection carries: criticality and business role, tenant policy, baselines and intelligence matches.

3

Sequence

Related events join on shared entities and time into a chain mapped to MITRE ATT&CK, and position in the chain feeds scoring.

4

Decide

The Risk Scoring Formula produces one score comparable across every layer, and response runs through SOAR and Playbooks within tenant policy.

Write-back

Every outcome, override and service-level result returns to the model, so scoring and routing improve with each incident.

Generative, agentic and governed

What may act unattended is a policy decision, not a model decision

The generative layer

Explains

It writes the incident narrative and the reasoning behind a ranking, and the evidence behind any passage can be opened.

It does not decide severity and it does not act.

The agentic layer

Works

It gathers missing evidence, validates indicators and tests the benign explanations before anything is escalated.

It acts only within the action classes, asset scopes and risk bands the tenant allows. Every unattended action is reversible.
LevelWhat reaches itWhat it may do
AI-SecOps Autonomous AnalystsRoutine, high volume, lower riskTriages and investigates. Acts only where policy allows.
Human first lineMedium riskConfirms before action. Corrections are recorded as overrides.
Human senior lineHigh risk and complex chainsDecides at every gate.

Cross-layer visibility

Four detections. Three of them dismissible alone.

Cloud identity · Medium

A finance user signs in from an unfamiliar network, then registers a new MFA method.

DNS resolver · Informational

Lookups of a recently registered domain, from a host known only by IP address.

Endpoint · Medium

A signed binary spawns a scripting host under an account unknown to the directory.

Configuration and baseline

The asset carries a finance role, and the account never signs in outside business hours.

In ClearSkies iISOC

All four resolve to one identity and one ATT&CK chain. One incident, one score, one owner, and the lowest-severity input is what lifts it from medium to high.

Beside the stack

Four alerts in four consoles on severity scales that do not compare, one identity counted twice, no chain and no owner.

Inside the platform

One model, twelve Core Functions drawing on it

The iCollector normalizes inside your trust boundary, the Fabric resolves and enriches, the TDIR Engine orchestrates. Every connector runs both ways.

iCollectorcollects, normalizes and masksinside the trust boundaryCentric-AI Fabricresolves, enriches and linksinto one shared context modelTwelve Core Functionsdraw on the resolved modeland return their resultsTDIR Engineorchestrates detection,investigation and responseoutcomes, overrides and service-level results return to the model
DetectionFactoryRisk ScoringFormulaIntelligentAlert RoutingGenerative andAgentic AISOAR andPlaybooksThreatHuntingThreatIntelligenceUEBAKPIs andSLAsRegulatoryFrameworksThird-PartyMarketplaceAI-SecOpsAutonomous AnalystsDetection FactoryRisk Scoring FormulaIntelligent Alert RoutingGenerative and Agentic AISOAR and PlaybooksThreat HuntingThreat IntelligenceUEBAKPIs and SLAsRegulatory FrameworksThird-Party Add-ons MarketplaceAI-SecOps Autonomous AnalystsCentric-AI Fabricone shared context model

Detection Factory

Receives resolved entities and outcome feedback. Returns detection logic and technique mapping.

Risk Scoring Formula

Receives business impact, confidence, chain position and tenant context. Returns the score that drives ranking.

Intelligent Alert Routing

Receives the ranked alert and its evidence set. Returns the assignment and escalation decision.

Generative and Agentic AI

Receives the evidence and entity context the models operate on. Returns narratives, findings and proposed actions.

SOAR and Playbooks

Receives incident context and the technique that selects a playbook. Returns execution results as new evidence.

Threat Hunting

Receives the entity model a hypothesis is tested against, and generated hypotheses. Returns hunt findings.

Threat Intelligence

Receives observed indicators for enrichment. Returns intelligence that raises or lowers confidence.

UEBA

Receives resolved identity and asset history. Returns baselines and deviations that enter scoring as context.

KPIs and SLAs

Receives the decision record and its timestamps. Returns service-level state, which re-prioritizes work before a breach.

Regulatory Frameworks

Receives the audit trail and technique coverage. Returns the obligations that shape what must be evidenced.

Third-Party Add-ons Marketplace

Receives context for third-party controls reached during response. Returns third-party telemetry.

AI-SecOps Autonomous Analysts

Receives case context and evidence for triage of low-level alerts. Returns triage outcomes and analyst feedback.

Select a function to see what it receives from the Fabric and what it returns.

A native add-on is different. It reports its findings to the engine and receives nothing back.

Detection Factory. Receives resolved entities and outcome feedback. Returns detection logic and technique mapping.

Risk Scoring Formula. Receives business impact, confidence, chain position and tenant context. Returns the score that drives ranking.

Intelligent Alert Routing. Receives the ranked alert and its evidence set. Returns the assignment and escalation decision.

Generative and Agentic AI. Receives the evidence and entity context the models operate on. Returns narratives, findings and proposed actions.

SOAR and Playbooks. Receives incident context and the technique that selects a playbook. Returns execution results as new evidence.

Threat Hunting. Receives the entity model a hypothesis is tested against, and generated hypotheses. Returns hunt findings.

Threat Intelligence. Receives observed indicators for enrichment. Returns intelligence that raises or lowers confidence.

UEBA. Receives resolved identity and asset history. Returns baselines and deviations that enter scoring as context.

KPIs and SLAs. Receives the decision record and its timestamps. Returns service-level state, which re-prioritizes work before a breach.

Regulatory Frameworks. Receives the audit trail and technique coverage. Returns the obligations that shape what must be evidenced.

Third-Party Add-ons Marketplace. Receives context for third-party controls reached during response. Returns third-party telemetry.

AI-SecOps Autonomous Analysts. Receives case context and evidence for triage of low-level alerts. Returns triage outcomes and analyst feedback.

Governance and assurance

Evidence a risk officer can use

Standard or frameworkRole in the intelligence layerPosition
MITRE ATT&CKEnterprise, Cloud, IdentityTechnique vocabulary for sequencing and scoringSupported
OCSFSchema alignment for resolved eventsAligned
STIX and TAXIIStructured intelligence in enrichmentSupported
EU AI ActGovernance of the AI functions deployedEvidenced
NIST AI Risk Management Framework 1.0Practice framework for AI riskAligned
ISO/IEC 27001 and 27002Control mapping and audit evidenceEvidenced
NIS2, DORA and GDPRReporting, resilience and decision transparencyEvidenced

The platform produces the evidence these duties require. It does not deliver compliance. The resolved model, the scores and the decision record can all be exported.

Outcomes

What it delivers

End user

For the security team

Fidelity
Ranking reflects business impact, confidence and chain position, not alert counts.
Investigation
Work starts from an assembled account with its evidence attached.
Defensibility
Every conclusion traces to its evidence and every action to its actor.

Service provider

For the managed security provider

Coverage
One team serves many tenants, because the virtual analyst absorbs routine triage.
Federated learning
Detection improves across the whole book, with no tenant data crossing the isolation boundary.
Commercial model
Outcome-based delivery becomes credible, with dwell time and service-level attainment measured per tenant.

The layer, in one line

Correlation as a property of the architecture, not an integration project