Elora turns bounded AI threat detections into evidence-backed findings, governed investigations, defence analysis, and assurance-ready Case Reports while keeping final execution authority with Governance.
Threat Intelligence detects, interprets, recommends, correlates, and records. It cannot authorize execution, rewrite a Governance decision, activate a detector through investigation activity, or convert missing evidence into a claim of safety.
The current 0.2.6 architecture preserves atomic evidence while giving operators a coherent case-level view.
Prompts and final outputs can be reviewed by a bounded deterministic detector. Semantic and learned interpretation provide additional evidence-only context after governed repair activity has completed.
A finding records what was detected, where it occurred, available provenance, confidence dimensions, likely risk, Elora's recommendation, and the action that actually occurred.
Findings sharing the same evidenced Governance Session can be grouped without inventing provenance. Evidence with no session identifier remains visibly ungrouped.
A governed Case brings related findings, detections, controls, risks, decisions, evidence, and append-only investigation activity into one operational review boundary.
Threat Findings, Elora Decisions, Governance Replay, Observer reports, policy records, guardrails, and Worker Host evidence remain separately owned. Exact identifiers and bounded trace context connect them through deep links rather than copied records.
The bridge distinguishes attack assessment, recommendation, Governance evaluation, recommendation disposition, final runtime action, commit reason, operator authority, effective permissions, and any separately recorded residual-risk acceptance.
Authorized operators can create time-bounded, revocable acceptance evidence for a Threat Case. Acceptance is append-only and cannot retroactively approve a runtime commit, remove a finding, or replace Replay.
Case Reports can map available evidence to assurance frameworks while showing where support is partial or absent.
Current public-safe mappings cover the EU AI Act, NIST AI RMF, UK AI principles, and ICO AI/data-protection guidance using evidence-present, partial, and not-evidenced states.
These mappings support operational assurance and audit preparation. They do not establish legal compliance, conformity, legal advice, or independent certification.
This page describes system capability, evidence relationships, and authority boundaries. It intentionally excludes detector rules, exact schemas, thresholds, internal routes, private evidence payloads, and deployment controls.