| name | security-alert-triage |
| description | Triage a security alert by validating signal integrity, affected identity/assets, timeline, scope, likely benign explanations, threat context, and required containment. |
Security Alert Triage
Use when this procedure is the primary professional method needed for the assignment.
Procedure
- Confirm the decision or outcome this work must support, its scope, owner, constraints, and definition of success.
- Establish the evidence baseline using alert payload, logs, identity/asset inventory, recent changes, network/process evidence, and detection logic. Do not fill material gaps with assumptions when they can change the result.
- Preserve raw evidence, enrich asset/identity context, correlate adjacent events, classify confidence/severity, decide containment threshold, and document rationale.
- Exercise realistic edge, failure, transition, or exception cases that could invalidate the result; record unresolved uncertainty explicitly.
- Validate the output against the original outcome and any neighboring professional contracts so this skill does not silently absorb another specialist's authority.
- Record the resulting artifact, measurements, decisions, provenance, and handoff information needed for another owner to reproduce or continue the work.
Quality gate
The disposition is evidence-backed and high-risk uncertainty is escalated rather than prematurely closed.