Aegisify company logo
Aegisify Digital Intelligence – Digital Intelligence Administration & Governance2026-08-20T01:52:22+00:00
Aegisify Digital Intelligence — Administration

Operate the Intelligence Service Without Mixing Administration With Security Conclusions

Digital Intelligence Administration brings service readiness and governance into one control area. It answers the operational questions behind the security workspace: Is the service entitled and provisioned? Which application domains are enabled? How is evidence retained? Who receives material security notifications? And what privacy boundaries apply to sensitive context and AI-assisted explanation?

Administration establishes the operating contract.It does not replace sensor coverage, evidence-pipeline health, investigation evidence, or response authorization.

Digital Intelligence Control PlaneService + Governance
01EntitlementService authority
02Application ScopeEnabled domains
03Evidence StoreTenant readiness
04GovernanceRetention + alerts

Service state ≠ coverage stateGovernance ≠ response automation

Two Administrative Responsibilities

Service Operations and Governance Belong Together—but They Answer Different Questions

Putting both under Administration keeps customer navigation clean while preserving the distinction between platform readiness and policy control.

Service Operations

Can Digital Intelligence run for this account and application?

Review entitlement, application-domain enrollment, dedicated tenant evidence-store readiness, provisioning state, service health, effective retention, and recent storage activity.

Governance

How should evidence and notifications be governed?

Review effective retention, Root Account retention authority, evidence holds, security notification recipients, incident-severity alerts, operational security signals, privacy boundaries, and AI evidence minimization.

Service Readiness

Entitlement Is a Service State—not a Security Verdict

Digital Intelligence keeps administrative readiness separate from live evidence health so an active service cannot be mistaken for complete visibility.

Not entitledNo currently effective Digital Intelligence entitlement is assigned to the account.
Pending activationA service request or future entitlement exists, but live Digital Intelligence authorization is not yet active.
SuspendedRuntime authorization is inactive until the entitlement is restored or replaced.
ProvisioningThe entitlement is active while the dedicated evidence service is still becoming operational.
Licensed / ActiveEntitlement and dedicated tenant evidence-store readiness are active; live confidence still depends on coverage and ingestion health.
DegradedEntitlement exists, but provisioning, database readiness, or an operational dependency is degraded and security silence must not be overinterpreted.

Operational boundary: an active license can coexist with missing, stale, degraded, or incomplete runtime evidence. Administration proves service readiness; Coverage & Evidence Health proves visibility readiness.
Application Enrollment

Bind Digital Intelligence to the Applications That Are Actually in Scope

The service operates at the account and application-domain boundary rather than assuming every eligible domain is automatically enrolled.

01Account entitlementDefines whether the organization has authority to use the Digital Intelligence service and the application capacity associated with that entitlement.
02Eligible domainsEstablishes which application domains belong to the account and can be considered for Digital Intelligence.
03Enabled application domainsOnly explicitly enabled application domains enter the Digital Intelligence routing and customer intelligence workflow.
04Domain-specific evidenceEvidence, service state, Agent identity, coverage, incidents, and response stay tied to the correct application context.

Tenant Evidence Store

Keep Service Storage Readiness Visible

Digital Intelligence uses a dedicated tenant evidence-store model for customer intelligence data. Administration exposes the operational state of that store without treating database availability as a security finding.

Operational readiness can include provisioning state, storage binding state, schema readiness, latest successful tenant write, recent accepted batch/event activity, telemetry volume, and any provisioning or storage failure that prevents the evidence layer from being queried safely.

If the evidence store is unavailable, Aegisify should say that visibility cannot be verified. It should not translate storage failure into “no incidents.”

Illustrative service architecture

Account LicenseEntitlement authority
Enabled ApplicationExplicit customer scope
Tenant Evidence StoreDedicated evidence service
IngestionAccepted application evidence
Intelligence / ResponseInvestigation, evidence, approved response, recovery

Evidence Retention

Make Retention an Explicit Governance Decision

The active subscription establishes the normal retention authority. Governance then makes the effective customer policy visible and auditable.

Subscription authority

Plan-defined retention

The active entitlement establishes the normal evidence-retention window for the account.

Root Account authority

Shorter customer override

The primary Root Account owner can choose a shorter effective retention window. The customer override cannot extend storage beyond the active subscription authority.

Evidence preservation

Active evidence holds

Evidence placed on an active hold remains preserved beyond normal expiry until the hold is released.

CollectRetainNotifyHold when required
Security Notification Governance

Choose Which Material Security Signals Should Generate Customer Email

Notification policy changes email behavior—not whether Digital Intelligence continues collecting evidence, creating investigations, or showing security state in the application.

Investigation severity

Severity-based case notifications

Customers can govern whether material investigation changes at selected severities should trigger Digital Intelligence email notification.

Response workflow

Approval required

Notify accountable recipients when a deterministic containment proposal is waiting for the required owner decision.

Recovery workflow

Related recurrence

Notify when monitored evidence shows related activity returning after a containment action.

Visibility workflow

Coverage degraded

Notify when implemented telemetry-health conditions indicate stale or degraded evidence visibility.

Configured recipients are customer-controlled within the product’s administrative rules, and the primary account authority remains part of the governance model. Invalid recipient data is rejected instead of silently turning a security notification policy into an unknown delivery configuration.

Administrative Authority

Keep High-Impact Governance With the Root Account Owner

Digital Intelligence distinguishes ordinary access from the authority to change customer-wide retention and notification policy.

Root AccountPrimary governance authority

Controls the customer retention override, configured notification recipients, and selected Digital Intelligence email alert signals.

Other authorized usersVisibility without customer-wide policy authority

Can use permitted Digital Intelligence views according to account access, while customer-wide governance remains protected from casual or unintended changes.

Separate control planes: the Administration page does not replace the authorization and policy engine that governs consequential response actions. Governance policy and response execution remain separate security boundaries.
Privacy Boundaries

Use Context Without Turning Security Enrichment Into Raw Customer-Data Collection

Administration makes the data-handling intent visible because sensitive context and AI-assisted explanation need explicit boundaries.

01

Sensitive Data context

The Sensitive Data Map is designed around classification/context metadata and one-way resource fingerprints rather than copies of raw customer records merely for enrichment.

02

High-risk values stay outside the enrichment goal

The implementation explicitly states that raw payment-card data, CVV values, secrets, and entire customer records should not be collected simply to enrich Digital Intelligence context.

03

AI evidence minimization

Evidence-constrained AI explanation uses minimized, sanitized deterministic incident context under a strict redaction profile rather than treating the entire tenant evidence store as a prompt.

04

AI remains interpretation

AI output is explanatory context. It is not immutable evidence, it does not overwrite the evidence record, and it is not independent remediation authority.

Administration vs. Security Operations

Know Which Page Should Answer Which Question

AdministrationIs the service licensed, provisioned, enrolled, retained, notified, and governed correctly?
Coverage & Evidence HealthCan Aegisify see the required application evidence, and is the feed current and continuous?
InvestigationsWhat happened, what evidence supports the case, and could persistence remain?
Response & RecoveryWhat should be contained, who must approve it, did the state change, and did related activity return?

Digital Intelligence Administration FAQ

Common Questions About Service and Governance

Does an active Digital Intelligence license mean telemetry is healthy?

No. Entitlement and provisioning establish service authority and storage readiness. Sensor coverage and evidence-pipeline health are separate operational facts and can still be degraded or unavailable.

Can the customer extend retention beyond the active subscription?

The current governance model allows the primary Root Account owner to choose a shorter retention override. It does not use that override to extend retention beyond the active subscription authority. Active evidence holds can preserve held evidence beyond normal expiry until release.

Do notification settings stop evidence collection?

No. Notification policy governs selected Digital Intelligence email signals. Evidence collection, investigation creation, and in-product visibility continue according to the service and evidence controls.

Who can change Digital Intelligence governance?

The current implementation reserves retention, notification recipients, and alert selections for the primary Root Account owner rather than treating every logged-in user as a governance administrator.

Does Administration control all automated response?

No. Response execution is governed by its own implemented authorization, policy synchronization, target validation, and response-level controls. Administration should not become a UI-only bypass around those enforcement points.

Run the Intelligence Service With Clear Boundaries

Make Readiness, Governance, and Evidence Policy Explicit.

Aegisify Digital Intelligence Administration keeps service authority, application enrollment, tenant evidence storage, retention, security notifications, and privacy boundaries visible without confusing them with security verdicts.