The operating model The platform works the incident. Your team commands it.
Kavach, the analyst on shift, and Argus, the advisor on record, carry the tier-1 and tier-2 load —
triage, correlation, staged response, reporting. Yes, the engine behind them is AI — bounded like
staff, not loosed like a chatbot: nothing acts outside policy, every step is attributable, and the
judgment calls stay with your team. How Praxis™ orchestrates it →
K Kavach
The analyst on shift — works the incident
Triages every alert, connects the clues across email, identity, and endpoints into one incident, proposes the fix with evidence — and executes within the policy you set, then verifies it worked. On shift 24/7, conversational at tenant and fleet scope, with every action reversible and written to a tamper-evident audit trail.
A Argus
The advisor on record — tells the story
Turns incidents into plain-English, client-ready reporting — what was caught, what was fixed, and the evidence behind every claim — answers "was that safe?", and keeps the cyber-insurance readiness story current, in-app or over email, Slack, Teams, and SMS.
Level 0 — Watch Detection and full incident narrative only. Complete visibility, no action taken.
Level 1 — Advise Centeye proposes the exact remediation with evidence. Your team — or the client’s — executes.
Level 2 — Approve Centeye stages the action with the evidence attached; it executes on a one-tap approval from the role you designate.
Level 3 — Pre-authorized Containment pre-authorized per threat class — executed in minutes, verified against live state, and reported.
Response modes, not a black box: each action class carries its own mode, per client.
Destructive actions default to approval, and every decision is logged — who, what, why.