How it works

From noisy signal
to defensible action.

Each stage removes ambiguity without hiding the source: collect, identify, group, prioritise and preflight. Operators can inspect why an incident exists and why it appears where it does.

01

Collect

Agents and connectors observe the environments you place in scope and report their own collection state.

02

Identify

Vendor rule codes and stable condition identity separate recurrence from genuinely new work.

03

Group

Related conditions become incidents without losing member alerts or raw evidence.

04

Prioritise

Severity meets sourced business criticality. Unclassified assets wait for explicit triage.

05

Act safely

A preflight shows target hosts, reachability, criticality and blockers before anything is queued.

Incident reasoning

A chronology of facts.
Not a generated story.

Dunfaire places member alerts, device evidence, agent activity and operator changes into one sequence. It can propose what to inspect without presenting record-only changes as infrastructure causes.

INCIDENT EVIDENCE / FACTUAL SEQUENCEA timeline the operator can challenge
  1. ALERTRepeated authentication failureFirewall · vendor rule 4107 · occurrence 18
  2. AGENTCollector heartbeat receivedReachable · collection active · clock aligned
  3. CHANGEOperator updated asset criticalityTier 2 → Tier 1 · source and actor recorded
  4. VULNERABILITYNew evidence joined the incidentMember event retained · priority recalculated

CAUSE FILTER Changes made only inside Dunfaire’s own records are visible for audit, but are not proposed as infrastructure causes.

ACTION PREFLIGHTREADY FOR REVIEW
TARGETProduction gateway cluster3 hosts · all reachable
  • ReachabilityConfirmed
  • Business criticalityTier 1
  • Service interruptionPossible
  • Blocking checksNone
Explicit operator confirmation required

Safe action

Review the blast radius before the queue.

Preflight makes target hosts, reachability, criticality and blockers explicit. Interruptive work on business-critical systems requires confirmation, and the server replans and rechecks immediately before queueing.

Bring a real incident path. Test every stage.

Book a working session