Investigation flows

Keep evidence, ownership, and approval intact while enrichment services fail or arrive late.

Illustrative reference architecture 3 min read

Reference diagram

Evidence collection and case action have separate responsibilities

Evidence

  1. Alert + entityIdentity scope and event interval
    Bound the pivot
  2. Timed lookupsIndependent deadlines and permissions
    Record every outcome
  3. Evidence ledgerSource references, times, and explicit gaps

Case decisions

  1. Owned caseAccountable analyst and versioned state
    Review a specific proposal
  2. ApprovalResolved target, arguments, and authority
    Execute authorized request
  3. Action ledgerStable operation ID and reconciled result

Connections between paths

  • Alert + entity→Owned case

    Create or correlate under an explicit policy

  • Evidence ledger→Approval

    Supply evidence and disclose missing context

  • Action ledger→Evidence ledger

    Append the outcome reference

Lookups can fail independently. Case actions require their own authorization and retry contract; an enrichment result is not approval.

Begin with a bounded question

In this reference design, I start with an alert and a question an analyst can investigate: which activity belongs to this account during the relevant interval? The alert includes its rule version, source event references, event time, and ingestion time. An entity pivot uses a tenant-scoped identifier and an explicit time window. An IP address alone is insufficient to establish that two observations concern the same person.

Assume a durable case store, authenticated analysts, and enrichment services with independent availability. The workflow assists investigation; it does not determine guilt or close a case from an automated summary.

Make each result traceable

The workflow schedules bounded lookups for identity, asset, and related-event context. Each result records its source, query interval, retrieval time, source record identifiers, and the transformation that produced it. Preserve a reference or permitted snapshot so another analyst can understand what was available at the time.

Observations and interpretations remain distinguishable. A directory membership is an observation; a claim that access was inappropriate needs additional reasoning. STIX's distinction between observed data and intelligence assertions is useful here. Contradictory results remain visible, including the time and scope that might explain the disagreement.

Give the case one accountable owner

A correlation policy can suggest attaching an alert to an existing case. It records the matched entities, interval, and policy version; an ambiguous match goes to review. Attaching a related alert must not silently transfer ownership or expand access to sensitive evidence.

Case assignment and status changes use version checks so concurrent analysts cannot overwrite each other's decisions. Each enrichment step has a deadline and a distinct result: succeeded, unavailable, denied, or timed out. The case can progress with explicit gaps. Late results append evidence and may prompt review; they do not rewrite a completed decision.

Retry work without repeating its effect

Adding a case note uses a stable operation identifier and a destination that atomically records that identifier with the write. A retry returns the recorded result. A changed note or target requires a new operation; identical identifiers with different arguments are rejected.

For a consequential action, show the analyst the target, change, and supporting evidence. Bind approval to those arguments and recheck authorization when executing. A timeout after dispatch leaves an uncertain outcome: reconcile with the destination before trying again. If the external service cannot deduplicate or reveal its result, stop automatic retries and assign reconciliation to a person.

Observe the gaps without copying the evidence

Track unassigned case age, enrichment deadlines missed, source freshness, approval age, and unresolved action outcomes. Measure each dependency separately; a successful lookup elsewhere must not disguise a missing source. Workflow logs contain identifiers and status, with protected evidence kept behind its own access checks.

Apply sensitivity labels to derived notes as well as source records. Give retained snapshots an explicit purpose and expiry. Deletion needs to reach exports and cached summaries where applicable. If evidence expires, retain an appropriate deletion record and mark the case's reference unavailable rather than inventing a replacement.

Use orchestration where it earns its cost

Persistent steps and explicit outcomes make interrupted investigations easier to resume, but they add state migrations, ownership rules, and integration maintenance. An analyst must still decide whether the evidence answers the question and whether another explanation fits.

For a small team with a few reliable sources, a structured case checklist and direct searches may be easier to operate. I would add orchestration when repeated enrichment and handoffs consume attention, while keeping the same provenance, permission, and approval requirements.

References

Search the site

Search experience, studies, articles, projects, and contributions.

Try a topic