Breach Dashboard
Explainable by designBreach intelligence and containment
Rule-based anomaly and sensitivity logic can escalate incident packages into breach records, recommend mock containment, and draft a regulator-ready notification.
Breach records
2
Suspected or active breach items produced by deterministic breach intelligence.
High severity
2
Breach items currently rated high or critical after anomaly and sensitivity scoring.
Active workflow
2
Records still moving through suspected, investigating, or contained states.
Breach register
Severity indicators, anomaly scoring, and workflow status across all active breach records.
| Breach signal | Anomaly | Severity | Workflow | Detected |
|---|---|---|---|---|
Suspected unauthorised customer data export Sensitive customer data and a privileged-role anomaly require containment and privacy assessment. Customer data export after Snowflake role misconfiguration | Score 54 Multiple incident indicators crossed the anomaly threshold for potential breach escalation. | HighP1 | Contained | Snowflake Audit Telemetry Jul 10, 2026, 3:24 AM |
Potential sensitive payment operations breach Sensitive payment content combined with anomalous outage behaviour crossed the breach threshold. Payment outage due to API misconfiguration | Score 98 Multiple incident indicators crossed the anomaly threshold for potential breach escalation. | CriticalP1 | Investigating | Breach Intelligence Agent Jul 8, 2026, 8:52 AM |
Suspected unauthorised customer data export
Timeline view of how the breach signal was detected, escalated, and moved through workflow.
Breach signal evaluated
Jul 10, 2026, 3:18 AM
Anomaly score 54 with 3 matched indicators.
Anomalous Export Detected
Jul 10, 2026, 3:18 AM
Connector:Snowflake updated incident inc-data-002.
Sensitive Data Flagged
Jul 10, 2026, 3:20 AM
Agent:Classification updated incident inc-data-002.
Exports Paused
Jul 10, 2026, 3:27 AM
Security Operations updated action action-data-pause.
Breach record active
Jul 10, 2026, 3:24 AM
Suspected unauthorised customer data export is currently contained.
Status workflow
Deterministic workflow progression from suspected through closure.
Containment actions
Mock actions recommended immediately once breach conditions are met.
Revoke active sessions
Force re-authentication for users with access to impacted payment administration surfaces.
Pause exports
Temporarily disable manual and scheduled exports for the affected data path while investigation continues.
OAIC draft notification
Mock regulator-facing draft text generated from current breach intelligence.
Draft OAIC Notification Incident: Customer data export after Snowflake role misconfiguration System: Snowflake Analytics Severity: HIGH Detected: Jul 10, 2026, 3:18 AM Summary: Monitoring identified an unusual export from a payment analytics schema after a privileged Snowflake role was assigned outside the approved access workflow. Why this may be notifiable: The deterministic breach intelligence workflow identified P1 classified content and an anomaly score of 54. Containment actions initiated: - Revoke active sessions for potentially impacted users. - Pause exports while the incident response team validates scope. Next step: Confirm whether personal or regulated information was exposed and escalate for legal and privacy review before external submission.
Potential sensitive payment operations breach
Timeline view of how the breach signal was detected, escalated, and moved through workflow.
Breach signal evaluated
Jul 8, 2026, 8:45 AM
Anomaly score 98 with 5 matched indicators.
Incident Ingested
Jul 8, 2026, 8:45 AM
System updated incident inc-payments-001.
Rca Generated
Jul 8, 2026, 8:47 AM
Agent:RCA updated rca rca-payments-001.
Controls Classified
Jul 8, 2026, 8:49 AM
Agent:Controls updated control control-pay-monitoring.
Breach Record Created
Jul 8, 2026, 8:52 AM
Agent:Breach updated breach breach-payments-001.
Breach record active
Jul 8, 2026, 8:52 AM
Potential sensitive payment operations breach is currently investigating.
Status workflow
Deterministic workflow progression from suspected through closure.
Containment actions
Mock actions recommended immediately once breach conditions are met.
Revoke active sessions
Force re-authentication for users with access to impacted payment administration surfaces.
Pause exports
Temporarily disable manual and scheduled exports for the affected data path while investigation continues.
OAIC draft notification
Mock regulator-facing draft text generated from current breach intelligence.
Draft OAIC Notification Incident: Payment outage due to API misconfiguration System: Payments API Severity: CRITICAL Detected: Jul 8, 2026, 8:45 AM Summary: A production payment release introduced an API configuration mismatch that caused checkout failures for merchants during peak transaction volume. Why this may be notifiable: The deterministic breach intelligence workflow identified P1 classified content and an anomaly score of 98. Containment actions initiated: - Revoke active sessions for potentially impacted users. - Pause exports while the incident response team validates scope. Next step: Confirm whether personal or regulated information was exposed and escalate for legal and privacy review before external submission.