Context
The current finding key intentionally keeps different detector categories separate, even when they concern the same device and observable. This protects explanation and lifecycle semantics but can show adjacent cards for one incident.
Desired outcome
Group related findings into a higher-level incident view without collapsing or obscuring detector evidence.
Acceptance criteria
- Define deterministic correlation rules using stable device identity, typed observables, time windows, and detector relationships.
- Keep each detector result and source provenance independently inspectable.
- Distinguish primary evidence from corroboration.
- Define incident priority, outcome, recurrence, suppression, and lifecycle semantics.
- Prevent community-only evidence from independently creating or escalating an incident.
- Preserve raw findings and make fusion reversible/auditable.
- Add false-merge, DHCP-change, unresolved-device, recurrence, and concurrency tests.
- Measure cards-per-incident and operator dismissal/suppression outcomes before broadening rules.
Boundary
No opaque ML grouping in the first implementation.
Context
The current finding key intentionally keeps different detector categories separate, even when they concern the same device and observable. This protects explanation and lifecycle semantics but can show adjacent cards for one incident.
Desired outcome
Group related findings into a higher-level incident view without collapsing or obscuring detector evidence.
Acceptance criteria
Boundary
No opaque ML grouping in the first implementation.