Threat Intelligence

Elora turns bounded AI threat detections into evidence-backed findings, governed investigations, defence analysis, and assurance-ready Case Reports while keeping final execution authority with Governance.

Authority Boundary

Threat Intelligence detects, interprets, recommends, correlates, and records. It cannot authorize execution, rewrite a Governance decision, activate a detector through investigation activity, or convert missing evidence into a claim of safety.

From Detection to Governed Case

The current 0.2.6 architecture preserves atomic evidence while giving operators a coherent case-level view.

1. Detection

Prompts and final outputs can be reviewed by a bounded deterministic detector. Semantic and learned interpretation provide additional evidence-only context after governed repair activity has completed.

2. Atomic Finding

A finding records what was detected, where it occurred, available provenance, confidence dimensions, likely risk, Elora's recommendation, and the action that actually occurred.

3. Governance Session

Findings sharing the same evidenced Governance Session can be grouped without inventing provenance. Evidence with no session identifier remains visibly ungrouped.

4. Threat Case

A governed Case brings related findings, detections, controls, risks, decisions, evidence, and append-only investigation activity into one operational review boundary.

Canonical Evidence Remains Separate

Threat Findings, Elora Decisions, Governance Replay, Observer reports, policy records, guardrails, and Worker Host evidence remain separately owned. Exact identifiers and bounded trace context connect them through deep links rather than copied records.

Current Capabilities

Live Threat Detection

  • Bounded pre-inference and final-output review.
  • Independent resource admission and terminal release.
  • Versioned deterministic behaviour and conformance evidence.
  • Evidence capture that remains independent of Trial Rail activation.

Learned Threat Interpretation

  • Combines bounded semantic observations with eligible governed lexical risk evidence.
  • Produces explicit hypotheses rather than authoritative classifications.
  • Cannot intervene, promote itself, modify Governance, or become detector authority.

Guardrail Defence

  • Separates model adherence from Elora interception and escaped outcomes.
  • Qualifies comparisons by recorded execution environment.
  • Supports attack-vector and evidence-type breakdowns.
  • Avoids treating incomparable runtime conditions as one model ranking.

Case Reports

  • Overview, attack map, runtime timeline, evidence, controls, related records, and case activity.
  • Bounded printable and machine-readable evidence views.
  • Projection checksums for report consistency.
  • Atomic findings retained beneath the grouped Case.

Decision and Authorization Bridge

The bridge distinguishes attack assessment, recommendation, Governance evaluation, recommendation disposition, final runtime action, commit reason, operator authority, effective permissions, and any separately recorded residual-risk acceptance.

Governed Residual-Risk Acceptance

Authorized operators can create time-bounded, revocable acceptance evidence for a Threat Case. Acceptance is append-only and cannot retroactively approve a runtime commit, remove a finding, or replace Replay.

Operational Assurance, Not Certification

Case Reports can map available evidence to assurance frameworks while showing where support is partial or absent.

Evidence Mapping

Current public-safe mappings cover the EU AI Act, NIST AI RMF, UK AI principles, and ICO AI/data-protection guidance using evidence-present, partial, and not-evidenced states.

Disclosure Limit

These mappings support operational assurance and audit preparation. They do not establish legal compliance, conformity, legal advice, or independent certification.

Public Disclosure Boundary

This page describes system capability, evidence relationships, and authority boundaries. It intentionally excludes detector rules, exact schemas, thresholds, internal routes, private evidence payloads, and deployment controls.