Operational Intelligence
How SentriScope surfaces operational intelligence from canonical data to guide analyst attention and investigation workflows.
Operational Intelligence
Industry Problem
Security operations produce more signal than any team can manually triage. Analysts open multiple consoles—vulnerability management, identity, exposure, threat feeds, ITSM—and mentally correlate which issues matter today for their environment.
Leaders ask a different question: Where should we focus limited people and budget right now? Dashboards that only count open findings without business context, threat relevance, or control coverage fail both operators and executives.
Why the Problem Exists
Data fragmentation creates attention fragmentation. Each tool optimizes its own queue. Risk scores from one product rarely incorporate active threat campaigns, missing controls, and business criticality in a single, explainable ranking.
Without operational intelligence, teams either over-react to noisy alerts or under-react to correlated conditions that no single tool surfaces prominently.
Traditional Approaches
| Approach | Limitation |
|---|---|
| SIEM rule queues | Event-centric; not always business-aligned |
| Vulnerability SLA dashboards | Volume-focused; weak threat and coverage context |
| Executive PDF reports | Static; stale on arrival |
| Manual weekly triage meetings | Does not scale; tacit knowledge |
| Generic BI on security data | Often lacks security-specific explainability |
Mature operational intelligence combines continuous data integration, deterministic prioritization, and explainable reason codes so humans can trust and audit the queue.
SentriScope Perspective
In SentriScope, operational intelligence is the capability that helps teams decide where to focus by aggregating normalized canonical data into ranked, explainable attention surfaces (implemented).
It sits in the intelligence correlation layer described in KID-PLT-0003—above governed ingestion and canonical normalization, and alongside—not replacing—investigation and decision support.
Public-safe framing:
| Concept | Meaning in SentriScope |
|---|---|
| Attention point | A ranked item explaining why something needs focus now |
| Reason codes | Deterministic explanations (for example coverage gap, long-lived exposure, threat relevance) |
| Evidence references | Pointers to canonical entities supporting the attention point |
| Recommended action | Suggested next step—often investigation or remediation—not autonomous execution |
Deterministic prioritization: Critical attention-point computation does not rely on LLM scoring. AI may assist read-only analysis elsewhere; see KID-PLT-0002.
SentriScope also evolves operational intelligence specialists—domain reasoning over platform signals with structured, non-destructive outputs (partial / pilot maturity). These interpret deterministic services; they do not replace risk engines, evidence governance, or analyst approval. Full maturity: KID-PLT-0004.
Operational intelligence feeds KID-INV-0001; it does not define investigation procedures.
Current Product Capability
| Capability | State | Summary |
|---|---|---|
| Global intelligence dashboard | Implemented | Consolidated prioritization entry point for operators |
| Deterministic attention-point ranking | Implemented | Explainable priority with reason codes |
| Technology + threat + coverage context | Implemented | Aggregates canonical vulnerability, asset, and intel data |
| CISO-oriented summaries | Implemented | Executive visibility without replacing detail modules |
| Intelligence insights contract | Implemented | Structured insight emission from attention surfaces |
| Operational intelligence specialists / mission control themes | Partial / progressive | Reasoning layer and advanced mission themes not all generally available |
| Autonomous remediation from attention queue | Not available | Human-in-the-loop decisions required |
| SOAR replacement | Not available | See KID-PLT-0002 |
Current Limitations
- Attention quality depends on connector coverage and data freshness—see KID-INT-0001.
- Operational intelligence does not replace list and detail views for every domain; it prioritizes entry.
- Advanced workforce and mission-control experiences are partially implemented or on progressive rollout.
- No public performance benchmarks (for example triage reduction percentages) are claimed.
- Reason-code catalog and specialist behaviors may evolve;
next_reviewapplies.
Common Questions
Is operational intelligence the same as a SIEM?
No. It prioritizes correlated canonical security context for human decisions. SIEMs focus on log and event detection pipelines. SentriScope may complement SIEM data via integrations.
Does SentriScope automatically fix what the dashboard highlights?
No. Recommended actions suggest next steps; governed decisions and optional integrations handle execution—with analyst validation.
How is this different from threat intelligence?
Threat intelligence emphasizes external CTI lifecycle and indicator correlation—KID-TIN-0001. Operational intelligence consumes threat context among other signals to rank operational attention.
Can executives rely on this instead of detailed reports?
Executives gain a governed summary; due diligence still requires detail modules, maturity context KID-PLT-0004, and investigation where needed.
Related Concepts
Prerequisites
- What is SentriScope? —
KID-PLT-0001 - Platform Overview —
KID-PLT-0003 - Canonical Data Model —
KID-ARC-0001
See also
- Threat Intelligence —
KID-TIN-0001 - Investigation Workspace —
KID-INV-0001 - Attack Graph Overview —
KID-AGR-0001
Planned (Stream B)
KID-CON-0003Operational Intelligence ExplainedKID-GLS-0005Operational intelligenceKID-GLS-0006Attention point