01
Alert Triage & Escalation
The core loop: every incoming alert is triaged, whether it matches a known pattern or has never been seen, and only significant cases are escalated to a human.
“eliminating up to 98% of noise and escalating only significant cases to your team” radiantsecurity.ai
Mapped capabilities
4 capabilities
Known-alert plan reuse
Recognizing an alert type it has handled before and applying the existing investigation plan rather than starting over.
Novel-alert plan generation
Generating an investigation plan from scratch for alert types with no prior playbook, instead of deferring or dropping them.
Escalation threshold and noise suppression
Distinguishing cases worth an analyst's time from the large majority that should be closed without escalation.
Verdict statement and severity
Producing a clear disposition for each alert rather than an inconclusive summary.
Illustrative example
- Input
- A detection type Radiant has never seen before fires on a production host at 2am. Walk me through how it gets triaged.
- Expected behavior
- States that an investigation plan is generated from scratch for the unseen alert type, that the alert is still fully triaged rather than parked or passed straight to a human, and that it escalates only if the case is significant.





