Investigation and response

Follow the agent from alert to outcome.

Pavri correlates the available session, tool, endpoint, process, policy, and evidence context so analysts can understand what happened and what response followed.

Pavri investigations connect an alert to the implicated agent or assistant, session, user, endpoint, workspace, prompt, model, tool, process, policy decision, evidence source, and response record where the integration exposes those events.

Evidence chain

Direct evidence, decisions, response, and correlation stay distinct.

Analysts should not have to infer whether an event is a direct observation, policy decision, human decision, response record, or analytical correlation.

Direct evidence

Prompt, model, tool, endpoint, process, file, network, Git, browser, MCP, and session observations available from the integration.

Decision record

Matched policy, reason, outcome, control point, timestamp, and evidence link.

Response record

Notification, containment, revocation, ticketing, policy change, or investigation action initiated after a decision or detection.

Pavri evidence source categories.
Text equivalent: Evidence comes from framework sessions, endpoint observations, local MCP broker decisions, policy records, human approvals, response actions, and analytical correlation.
Workflow

From alert to session trajectory.

A Pavri investigation deep-links from an alert into the agent or assistant, user, endpoint, workspace, action chain, tool calls, policy decisions, detections, outcomes, and response history.

Next step

Make agent incidents reconstructable.

Use available evidence to understand what an agent did before, during, and after the alert.