The Platform Automates the Triage. Someone Still Owns the Verdict.
Somebody in the room asks who signed off on the rule that closed the case, and the question arrives weeks after the close and days into an incident. The pipeline had worked: enrichment ran, correlation grouped what belonged together, the rule read the evidence and reached the disposition it was configured to reach. Until that morning, nobody had been asked to put a name against it.
The pipeline reached a verdict and the case closed
An alert arrives. Enrichment attaches the identity, the asset, the history and what the external sources say. Correlation gathers the events belonging to one story. A rule reads what came back, sets a disposition, and the case closes with no analyst having opened it. Reaching that state takes months of careful work.
The thing that closes is bigger than the alert. Cortex XSIAM records each alert as an issue and groups the related ones into a case by tracing the causality behind them, so an automated disposition lands on a group the platform decided belongs together. The case carries a score, set by rule or by machine learning from the issues inside it, and what that score states is urgency. Detection content reaches the case from two directions. Analytics BIOCs ship with the platform and are maintained by Palo Alto Networks, raising an issue when behavior departs from a baseline the engine builds and tunes on its own. Beside them sit three rule types your engineers author: IOC rules, BIOC rules and correlation rules, written against your datasets and about your systems, with the correlation work expressed in Cortex Query Language. Those rules, together with the playbooks enabled from a Marketplace content pack and the local exclusions covering what the estate has already accounted for, are where an automated close gets its authority. Where the line sits for what a person reads is a decision your organization made once, and it is a different question from whether the disposition was right.
Cortex XSIAM carries out the disposition it was configured to reach, and Palo Alto Networks builds that execution to behave the same way in every estate running the platform, which is the property that makes an automated pipeline worth trusting at all. Which of your alerts may be closed without a person reading them is a question of risk appetite, answered against the systems your business runs on and the consequences it would carry. That answer has only ever come from inside your organization.
A disposition is a decision, and it was a decision when an analyst made it. Their name went on the case and they knew it was there. Whether anyone answers for a case the automation closed wrongly now depends on something written down before that case existed. Take every rule that can end a case by itself and write down what it decides.
- Which alerts a human sees at all. Anything the pipeline closes sits under a threshold for a person's attention, and somebody set that threshold once.
- What the enrichment means. Attaching a reputation verdict is gathering. Reading it as benign is a judgment about how much that verdict is worth.
- Which events are one story. Grouping decides how many things happened, and one story gets one disposition.
- When a case is finished. A close says nothing further is required, measured against a definition somebody wrote in a workshop.
The verdict has two authors
The decision left the analyst and landed on two people. One is the engineer who wrote the disposition logic, working to a specification agreed months ago and tested against cases that were real at the time. The other is whoever agreed the logic could run without a person watching. The transfer happens quietly: from inside the build it looks like engineering work on one side and a scoping approval on the other, so the two people who now hold the verdict are the last two who would describe themselves that way.
That split is how the accountability gets lost. The engineer holds the reasoning and treats the work as engineering, which it was. The approver holds the risk and remembers a scoping call during a build. Between them the case that closed on Tuesday has an author the way a form has an author, and the stake in whether it was right is unclaimed.
The asymmetry underneath matters. An analyst who closes an alert wrongly has closed one alert on one shift, and carries some memory of it. A rule that closes wrongly closes every alert matching it, on every shift, until somebody changes it. The hundredth looks exactly like the first.
- The reasoning stops appearing on the case. An analyst's close carried a note in their own words. A rule's close carries the rule.
- The informal review disappears. Somebody reading the queue used to notice a close that looked wrong. Cases nobody opened reach nobody.
- The error is consistent, which makes it harder to see than a person having a difficult week.
- The reasoning can leave the building. The engineer who wrote it moves teams or employers, and the logic carries on deciding.
The rule was written by a person and approved by a person, which is where the verdict belongs no matter how many cases it disposes of without one.
A wrong close does not announce itself
Human error in a queue is noisy. A close made in error leaves traces: a colleague queries it, or the analyst thinks about it on the way home and reopens it. All of that runs on somebody having looked, which is the one ingredient an automated close leaves out.
The right closes and the wrong ones leave the same record, because being wrong is invisible to the rule that made the decision. So a wrong close surfaces one way. Weeks later an incident gets reconstructed, the timeline walks backward, and arrives at a case that ended quietly with the rule applied correctly to the evidence in front of it.
Three Cortex XSIAM deployments, all of them carried through post-deployment work by CWS, and in none of the three did this question have a written answer. It had never come up, because a pipeline doing what it was built to do prompts nobody to ask who owns its mistakes. Enrichment, correlation and disposition ran as configured in all three. The name against a wrong close is one your organization writes, and four things keep it out of view until the day it is needed.
- A closed case reaches a human again only through a review somebody scheduled.
- The measure your program reports moves the right way. Fewer alerts reaching an analyst is what the work was for, and a wrong close moves that number the same direction as a right one.
- Volume. The classes handed to automation are the ones there was too much of to read.
- The reconstruction happens inside an incident. The room wants an account of that incident, and the standing question about the rule leaves with the report.
Both a right close and a wrong close reduce the number of alerts reaching your analysts, which is why that number cannot tell your organization which one it has.
Sampling is the mechanism
Accountability for an automated disposition, and sampling automated closes as the mechanism that tests it, are CWS positions. Both describe work your organization writes for itself, and both are open to argument.
The available mechanism is old and dull. Draw a sample of the cases automation closed and read them as though they had arrived unclosed. It is the one route by which a closed case reaches a human.
How the sample is drawn decides what the review is worth. Drawn at random across a defined period, it describes the population. Picked by a reviewer for looking worth a check, it describes the reviewer. The size belongs to the organization: argue about what you can afford to have closed wrongly, then write the number down with the reasoning beside it. That sentence protects the number a year later when somebody asks.
The reviewer also needs somewhere to put a disagreement. A review producing observations produces a document. A review producing a change to a named rule, with an owner and a date, has closed the loop it was built for. Set that route up before the first review.
- Who reads the sample, by name, with the hours booked. A rota of whoever is free reads to a different standard every month.
- How it is drawn and over what period, long enough to hold a quiet week and a bad one.
- How many cases, and the sentence explaining why that many. Write it while nobody is under pressure.
- What the reviewer is answering. The rule fired correctly. The question is whether the disposition it reached is the one a competent analyst would have reached from the same evidence.
- Where a disagreement goes: which rule, whose name, what changes, and by when.
Write the name before you need it
The model that sits around the pipeline is short, and its whole value is existing in writing beforehand. Written afterward, it gets composed in a room where somebody is looking for a name, and it lands on whoever is present.
It carries two accountabilities. The person who owns the rule answers for the logic doing what was asked of it. The person who approved unattended running answers for that having been an acceptable thing for the organization to decide. Both hold a judgment about risk in one estate. Cortex XSIAM executed the disposition it was configured to reach, which is the platform doing precisely its job, and the instruction it carried out was written in your building, about your estate, by your people.
Automation moved the decision toward people who were doing other jobs at the time. Handing enrichment, correlation and first pass disposition to a process is worth doing. What your organization can afford to have closed without reading stays where it started. Set the arrangement out and most of it is names and dates.
- The person who owns each rule that can end a case on its own, kept current as people move.
- The person who approved it running unattended, the date, and what they were shown at the time.
- The alert classes a rule may close by itself, and the classes that reach a person whatever the enrichment says.
- The sampling review that tests both of those, with a cadence and a next date in somebody's calendar.
- What happens on a confirmed wrong close: who is told, what gets reopened, and whether the rule keeps running while the change is made.
Assign the name before the first bad close. After it, the room is looking for one.