Operator Panel

Configure coverage scoring, telemetry, connectors, and AI proposal cycles.

Detection Coverage Settings

Include community rules
When off, only your SIEM's own rules contribute to coverage scores. Community rules remain visible in the queue but are excluded from scoring.
Industry segment
Enables threat-scenario coverage relevant to your customers and boosts priority of industry-specific techniques.

Surfaces

Protectable surfaces the board cares about. Criticality feeds readiness scoring.

0 surfaces
Loading surfaces…

Log Source Inventory

Tell the platform which log sources you ingest. Coverage will be scored against applicable techniques only.

0 / 0 selected

SIEM Connectors

Auto-refreshes every 30s
No SIEM connectors configured
Splunk and Sentinel rules can still be ingested manually from the Rules page.

AI Proposal Cycle

Detection Rule Proposals
Triggers an on-demand cycle. Uses the gap selector — top-ranked uncovered techniques are picked automatically.
Pending proposals
0
Review queue →
Max per cycle
5 (server default)
Rate limit
per server policy
Recent cycles

Cycle history is coming in the next release. For now, head to the review queue to see the latest proposals.

Changes here apply immediately to coverage scoring and proposal generation across the platform.