RiskHeatMap.aiGoverned demo

Breach Dashboard

Explainable by design

Breach intelligence and containment

Rule-based anomaly and sensitivity logic can escalate incident packages into breach records, recommend mock containment, and draft a regulator-ready notification.

Human approval remains required before controls, risks, and actions are finalised.

Breach records

2

Suspected or active breach items produced by deterministic breach intelligence.

High severity

2

Breach items currently rated high or critical after anomaly and sensitivity scoring.

Active workflow

2

Records still moving through suspected, investigating, or contained states.

Breach register

Severity indicators, anomaly scoring, and workflow status across all active breach records.

Breach signalAnomalySeverityWorkflowDetected

Suspected unauthorised customer data export

Sensitive customer data and a privileged-role anomaly require containment and privacy assessment.

Customer data export after Snowflake role misconfiguration

Score 54

Multiple incident indicators crossed the anomaly threshold for potential breach escalation.

HighP1
Contained
Snowflake Audit Telemetry
Jul 10, 2026, 3:24 AM

Potential sensitive payment operations breach

Sensitive payment content combined with anomalous outage behaviour crossed the breach threshold.

Payment outage due to API misconfiguration

Score 98

Multiple incident indicators crossed the anomaly threshold for potential breach escalation.

CriticalP1
Investigating
Breach Intelligence Agent
Jul 8, 2026, 8:52 AM

Suspected unauthorised customer data export

Timeline view of how the breach signal was detected, escalated, and moved through workflow.

Breach signal evaluated

Jul 10, 2026, 3:18 AM

Anomaly score 54 with 3 matched indicators.

Anomalous Export Detected

Jul 10, 2026, 3:18 AM

Connector:Snowflake updated incident inc-data-002.

Sensitive Data Flagged

Jul 10, 2026, 3:20 AM

Agent:Classification updated incident inc-data-002.

Exports Paused

Jul 10, 2026, 3:27 AM

Security Operations updated action action-data-pause.

Breach record active

Jul 10, 2026, 3:24 AM

Suspected unauthorised customer data export is currently contained.

Status workflow

Deterministic workflow progression from suspected through closure.

Suspected
Investigating
Contained
Closed

Containment actions

Mock actions recommended immediately once breach conditions are met.

Revoke active sessions

Force re-authentication for users with access to impacted payment administration surfaces.

Pause exports

Temporarily disable manual and scheduled exports for the affected data path while investigation continues.

OAIC draft notification

Mock regulator-facing draft text generated from current breach intelligence.

Draft OAIC Notification
Incident: Customer data export after Snowflake role misconfiguration
System: Snowflake Analytics
Severity: HIGH
Detected: Jul 10, 2026, 3:18 AM

Summary:
Monitoring identified an unusual export from a payment analytics schema after a privileged Snowflake role was assigned outside the approved access workflow.

Why this may be notifiable:
The deterministic breach intelligence workflow identified P1 classified content and an anomaly score of 54.

Containment actions initiated:
- Revoke active sessions for potentially impacted users.
- Pause exports while the incident response team validates scope.

Next step:
Confirm whether personal or regulated information was exposed and escalate for legal and privacy review before external submission.

Potential sensitive payment operations breach

Timeline view of how the breach signal was detected, escalated, and moved through workflow.

Breach signal evaluated

Jul 8, 2026, 8:45 AM

Anomaly score 98 with 5 matched indicators.

Incident Ingested

Jul 8, 2026, 8:45 AM

System updated incident inc-payments-001.

Rca Generated

Jul 8, 2026, 8:47 AM

Agent:RCA updated rca rca-payments-001.

Controls Classified

Jul 8, 2026, 8:49 AM

Agent:Controls updated control control-pay-monitoring.

Breach Record Created

Jul 8, 2026, 8:52 AM

Agent:Breach updated breach breach-payments-001.

Breach record active

Jul 8, 2026, 8:52 AM

Potential sensitive payment operations breach is currently investigating.

Status workflow

Deterministic workflow progression from suspected through closure.

Suspected
Investigating
Contained
Closed

Containment actions

Mock actions recommended immediately once breach conditions are met.

Revoke active sessions

Force re-authentication for users with access to impacted payment administration surfaces.

Pause exports

Temporarily disable manual and scheduled exports for the affected data path while investigation continues.

OAIC draft notification

Mock regulator-facing draft text generated from current breach intelligence.

Draft OAIC Notification
Incident: Payment outage due to API misconfiguration
System: Payments API
Severity: CRITICAL
Detected: Jul 8, 2026, 8:45 AM

Summary:
A production payment release introduced an API configuration mismatch that caused checkout failures for merchants during peak transaction volume.

Why this may be notifiable:
The deterministic breach intelligence workflow identified P1 classified content and an anomaly score of 98.

Containment actions initiated:
- Revoke active sessions for potentially impacted users.
- Pause exports while the incident response team validates scope.

Next step:
Confirm whether personal or regulated information was exposed and escalate for legal and privacy review before external submission.