Use when constructing SCOPE attack candidate chains from audit artifacts and rejecting facts that do not form attacker progressions.
Use when formatting SCOPE controls detection candidates into detections.md, detections.json, dashboard-readable SPL sections, or controls-schema detection records.
Use when attaching schema-valid SCOPE evidence handles to attack candidates, hops, observations, assumptions, and caveats.
Use when scope-exploit has operator-approved attack paths and needs to generate the narrative red team playbook, execution steps, persistence, post-exploitation, and IAM policy JSON without detection or SOC guidance.
Use when scope-investigate completes an investigation and needs a facts-only analyst summary, evidence timeline, query appendix, investigation gaps, and optional saved investigation artifact.
Use when a SCOPE top-level agent starts a run and needs bounded environment knowledge, durable observations, reasoning notes, coverage gaps, and Splunk patterns before planning.
Use after SCOPE evidence review, final disposition, or operator-approved save to update durable environment knowledge, observations, coverage gaps, or proposed reasoning-note improvements.