Answer questions about Microsoft Sentinel ASIM (Advanced Security Information Model). Use whenever the user asks about ASIM schemas, normalized Microsoft Sentinel fields, field classes, aliases, schema mapping, or mapping events and entities into ASIM.
Answer questions about OCSF (Open Cybersecurity Schema Framework). Use when the user asks about OCSF classes, objects, attributes, profiles, extensions, or event normalization.
Answer questions using the Tenzir documentation. Use whenever the user asks about TQL syntax, pipeline operators, functions, data parsing or transformation, normalization, OCSF mapping, enrichment, lookup tables, contexts, packages, nodes, platform setup, deployment, configuration, integrations with tools like Splunk, Kafka, S3, Elasticsearch, or any other Tenzir feature. Also use when the user asks how to collect, route, filter, aggregate, or export security data with Tenzir, or needs help writing or debugging TQL pipelines, even if they don't mention 'Tenzir' explicitly but are clearly working in a Tenzir context. Also use for questions about Tenzir the company or product, release notes and changelog, blog posts, and solution use cases.
Use when adding changelog entries, creating release notes, cutting releases, and publishing them to GitHub.
Manage Tenzir packages across the full lifecycle: add new packages, inspect existing packages, update manifests, extend or remove package capabilities, refactor user-defined operators, maintain tests and examples, configure inputs and contexts, ship deployable pipelines, publish packages, and retire obsolete package surfaces. Use when the user is working in the context of a Tenzir package or wants to organize reusable capabilities as a package.
Ship changes via pull request in Tenzir projects. Use when the user wants to open a PR, push a branch, add or update changelog entries, create a pull request for review, or when they say "ship this", "open a PR", "send this for review", or "push and create a pull request." Also use for follow-up changes to an existing PR.
Coordinate documentation updates alongside code changes. Use when preparing the `.docs/` checkout, creating a matching docs branch, opening a `tenzir/content` documentation pull request, or cross-linking docs and code PRs. Also use when the user mentions "update the docs", "docs PR", ".docs/", or when a code change affects user-facing behavior that should be reflected in the documentation on tenzir.com.
Tenzir design system: brand tokens (colors, typography, spacing, shadows, motion), design principles and invariants, and official logos. Use when styling anything Tenzir-branded: web UIs (shadcn/ui, Tailwind, plain CSS, or any frontend framework), Quarto documents and reports, slide decks, or diagrams (Mermaid, Graphviz). Also use when the user asks about Tenzir brand colors, fonts, logos, gradients, dark mode, or how to make output look like a Tenzir product.