Begin with a bounded question
In this reference design, I start with an alert and a question an analyst can investigate: which activity belongs to this account during the relevant interval? The alert includes its rule version, source event references, event time, and ingestion time. An entity pivot uses a tenant-scoped identifier and an explicit time window. An IP address alone is insufficient to establish that two observations concern the same person.
Assume a durable case store, authenticated analysts, and enrichment services with independent availability. The workflow assists investigation; it does not determine guilt or close a case from an automated summary.
Make each result traceable
The workflow schedules bounded lookups for identity, asset, and related-event context. Each result records its source, query interval, retrieval time, source record identifiers, and the transformation that produced it. Preserve a reference or permitted snapshot so another analyst can understand what was available at the time.
Observations and interpretations remain distinguishable. A directory membership is an observation; a claim that access was inappropriate needs additional reasoning. STIX's distinction between observed data and intelligence assertions is useful here. Contradictory results remain visible, including the time and scope that might explain the disagreement.
Give the case one accountable owner
A correlation policy can suggest attaching an alert to an existing case. It records the matched entities, interval, and policy version; an ambiguous match goes to review. Attaching a related alert must not silently transfer ownership or expand access to sensitive evidence.
Case assignment and status changes use version checks so concurrent analysts cannot overwrite each other's decisions. Each enrichment step has a deadline and a distinct result: succeeded, unavailable, denied, or timed out. The case can progress with explicit gaps. Late results append evidence and may prompt review; they do not rewrite a completed decision.
Retry work without repeating its effect
Adding a case note uses a stable operation identifier and a destination that atomically records that identifier with the write. A retry returns the recorded result. A changed note or target requires a new operation; identical identifiers with different arguments are rejected.
For a consequential action, show the analyst the target, change, and supporting evidence. Bind approval to those arguments and recheck authorization when executing. A timeout after dispatch leaves an uncertain outcome: reconcile with the destination before trying again. If the external service cannot deduplicate or reveal its result, stop automatic retries and assign reconciliation to a person.
Observe the gaps without copying the evidence
Track unassigned case age, enrichment deadlines missed, source freshness, approval age, and unresolved action outcomes. Measure each dependency separately; a successful lookup elsewhere must not disguise a missing source. Workflow logs contain identifiers and status, with protected evidence kept behind its own access checks.
Apply sensitivity labels to derived notes as well as source records. Give retained snapshots an explicit purpose and expiry. Deletion needs to reach exports and cached summaries where applicable. If evidence expires, retain an appropriate deletion record and mark the case's reference unavailable rather than inventing a replacement.
Use orchestration where it earns its cost
Persistent steps and explicit outcomes make interrupted investigations easier to resume, but they add state migrations, ownership rules, and integration maintenance. An analyst must still decide whether the evidence answers the question and whether another explanation fits.
For a small team with a few reliable sources, a structured case checklist and direct searches may be easier to operate. I would add orchestration when repeated enrichment and handoffs consume attention, while keeping the same provenance, permission, and approval requirements.