Operations

Day-2 operations. What running Compiled actually looks like.

CISOs buy architecture. Analysts live in it. This is what the operational experience looks like — from a finding landing to a confirmed case in your SIEM.

Managed
Deployment model
you run the platform; Compiled runs itself
Low
Operational burden
no tuning sprints, no rule maintenance
Your stack
Findings destination
SIEM, SOAR, or case management
Staged
Antibody updates
reviewed before applied; rollback available
The analyst experience

Scored findings, ready for triage.

Findings surface in your SIEM or case-management system — or in the Compiled findings console. Each finding carries a score, the specific policy it matched, the channel, a timestamp, and a verdict. Analysts review, confirm, or dismiss. No black-box scores. No mystery.

Findings — today2 open
allopenconfirmeddismissed
IDTimePolicy matchedScoreVerdictStatus
F-284709:14:22
Material non-public information — trading adjacency
Teams DM
0.94Flagopen
F-284609:11:07
Off-channel coordination — third-party account reference
Email — Exchange
0.88Flagopen
F-284509:08:51
Regulated data exfiltration — PII scope violation
Agent action — data pipeline
0.99Blockconfirmed
F-284408:59:33
Market manipulation — coordinated position language
Slack — #trading-desk
0.71Flagdismissed
F-284308:44:12
Unauthorized scope — action outside approved workflow
Agent action — order management
0.96Blockconfirmed
Showing 5 of 5 findings today · All times UTCRouting to Splunk

Stylized representation. Findings layout and fields are configurable. Raw communication content never appears in findings — only scored metadata and policy attribution.

The triage workflow

Confirm, dismiss, escalate. That is the whole loop.

Compiled is designed as a high-recall triage layer. Findings are calibrated to your traffic before go-live, and thresholds are tunable. The analyst workflow is intentionally minimal: each finding is reviewed, confirmed as a real event, or dismissed with a reason. Confirmed findings route automatically to the case management or SOAR tool your team already uses.

01

Finding surfaces

A scored finding arrives in the findings queue — or directly in your SIEM or case-management system via the configured routing rule. It carries: a finding ID, timestamp, channel, the specific policy matched, a score, and a verdict (flag or block). No raw communication content.

02

Analyst reviews

The analyst reviews the finding metadata and, where permitted by policy, the communication excerpt. The score and policy attribution tell the analyst exactly what the engine saw and why. There is no black-box explanation to reconstruct.

03

Confirm or dismiss

Confirm as a genuine event — the finding escalates to case management, a SOAR playbook, or the compliance workflow. Dismiss with a reason code — that signal is recorded and can inform threshold calibration in subsequent review cycles. Every decision is logged.

04

Routed and documented

Confirmed findings route to the destination your team configured — Splunk, Microsoft Sentinel, ServiceNow, or any SIEM or SOAR via the structured findings output. The full evidentiary record — timestamp, score, policy, verdict, analyst action — is in your environment, ready for an examination.

SIEM, SOAR, and case management

Findings go where your team already works.

Compiled outputs structured findings to the tools your SOC and compliance team already use. There is no new home for your data, no new interface to monitor, and no new training burden. Your existing tooling and playbooks handle the escalation.

SIEM
Splunk, Microsoft Sentinel, IBM QRadar

Findings are emitted as structured events to your SIEM. Each event carries the finding ID, timestamp, channel, policy matched, score, and verdict. Correlate with your existing data. Build alerts. No new connector required — findings route via standard log forwarding.

SOAR
Palo Alto XSOAR, Splunk SOAR, Microsoft Sentinel playbooks

High-confidence or block verdicts can trigger SOAR playbooks automatically. Define the threshold and routing rule; Compiled fires the webhook. Your playbook handles the response — notification, ticket creation, escalation, or quarantine.

Case management
ServiceNow, Jira, Relativity, NICE Actimize

Confirmed findings route to your case-management system with full evidentiary metadata attached. The compliance team works the case in the tool they already know. The Compiled finding record provides the audit trail that supports examination response.

Structured finding — output fields
finding_idF-2847Unique identifier — stable across routing systems
timestamp2026-06-24T09:14:22ZUTC; tamper-evident log in your environment
channel"teams_dm"Source surface — email, chat, agent_action, etc.
policy_id"mnpi.trading_adjacency.v3"Versioned policy reference — human-readable name available
score0.94Calibrated confidence score, 0–1
verdict"flag""clean" | "flag" | "block"
policy_name"Material non-public information — trading adjacency"Plain-language policy description for the audit trail

Raw communication content is never included in findings output. Only scored metadata and policy attribution cross the SOC boundary.

Deployment and footprint

A managed application inside your environment.

Compiled is a managed application — not a professional-services engagement. Your team does not tune models, write rules, or run refinement cycles. That operational burden belongs to Compiled.

Deployment
Install pathAzure Marketplace (Managed App); on-prem available
RuntimeRuns inside your Azure tenant or on-prem environment
ComputeCPU-only; no GPU required. Sized to your traffic volume
NetworkInline for agent actions; passive capture for communications
Ongoing operations
Rule maintenanceNone. Antibody library is managed by Compiled
RetrainingNot required. Updates are delivered as signed antibody updates
UpdatesStaged delivery; customer-controlled apply window; full rollback
Analyst effortReview and triage of scored findings in your existing tooling
Antibody update integrity

Signed, staged, and rollback-able.

Antibody updates are the only artifact that crosses the boundary into your environment inbound. Each update is cryptographically signed, carries a version identifier and a human-readable changelog, and is verified by your deployment before it is applied.

SignedCryptographic signature verified before application. Unsigned artifacts are rejected.
Staged deliveryUpdates land in a staging window you control. Review the changelog before applying.
Customer-controlled applyYou choose when the update goes live. No forced same-day application.
Full rollbackAny update can be rolled back to the prior version. Version history is maintained in your environment.
No remote code executionUpdates contain antibody definitions — not executable code that can run arbitrary operations in your environment.
Calibration and alert volume

High recall. Tuned to your base rate.

Compiled operates as a high-recall triage layer, not a zero-false-positive oracle. The honest operational reality: detection is calibrated to your traffic before go-live, thresholds are tunable, and the score on every finding tells you exactly how confident the engine was. Alert fatigue is addressed through calibration, not overclaiming.

Pre-go-live calibration

Before Compiled goes live on your traffic, we run a calibration pass. Thresholds are set against your actual base rates — not a generic benchmark. A score that means "high confidence" for your environment is specific to you.

Tunable thresholds

You control the score threshold at which a finding surfaces to your queue. Raise it to tighten the filter; lower it for more coverage. The tradeoff is explicit and yours to make, not hidden in a black box.

Explainable scores

Every score is backed by a named policy. The analyst knows which policy fired and at what confidence. Dismiss decisions feed back into threshold review — the system gets more precise over time for your traffic.

FAQ

Operational questions

See it in your environment

Walk through the operational experience with our team.

Book a 30-minute session to see the analyst view, the triage workflow, and how findings would route into your existing SIEM or case-management tool. We can tailor the walkthrough to your stack.

Book a walkthroughContact sales

sales@compiled.co