buyer
Treat missing independent validation as NONE_FOUND, not proof of ineffectiveness.
Microsoft · soc-agent
LLM-based alert classification and resolution for supported Defender workloads.
Deterministic executive summary
Security Alert Triage Agent has 1 confirmed capability assertion(s) and 1 confirmed control assertion(s). Evidence maturity is EARLY; autonomy is UNKNOWN; action authority is UNKNOWN. No qualifying independent validation is recorded.
The documented boundary is UNKNOWN with UNKNOWN operation. This describes authority and initiation, not effectiveness. No qualifying independent validation is recorded.
buyer
Treat missing independent validation as NONE_FOUND, not proof of ineffectiveness.
competitive
Compare documented action authority, trigger model, lifecycle, and evidence breadth; do not compare vendor outcome claims as equivalent measurements.
confidence
EARLY under ASI-1.0; No qualifying independent validation is recorded.
governance
Control evidence covers 1 scoped control assertion(s); verify local policy configuration before enabling write actions.
operational
Plan operating procedures around UNKNOWN initiation and UNKNOWN action authority.
technical
Current evidence establishes 1 scoped capability assertion(s); undocumented capabilities remain UNKNOWN.
UNKNOWN — no named agent is established by current evidence.
AFFIRMED
UNKNOWN — no architecture assertion is established.
The Security Alert Triage Agent classifies supported alerts using contextual LLM analysis.
AFFIRMEDHIGH under ASI-1.0:Recomputed at publication semantic_as_of with current freshness and unresolved-contradiction state.
VENDOR DOCUMENTATION EV-MS-TRIAGE-CAPABILITY · E1
The Phishing Triage Agent uses large language model based analysis to assess reported emails, determine intent, and classify each submission as a real threat or a false positive.Canonical source →
No human-confirmed conflict is published for this system.
NO_MATERIAL_CHANGE is recorded for this profile.
Any evidence-panel row marked UNKNOWN is not a negative capability claim. Any NONE_FOUND row means the current governed corpus contains no qualifying evidence.