Each string is one rule-based signal raised on one employee. Detection and Triage are fully automated and always shown; Evaluation is where an analyst decides false positive vs. true positive; Closure only unlocks after that decision, and its content depends on which way the case was decided.
Confirmed (can reach a definite True in this export): AWOL (0 Hours), Group Risk,
Flight-Linked Shift Convergence (Group).
Candidate (the export can only ever partially confirm these): Fake Security Guard, Robbery w/ Internal
Informant.
Every string's Detection tab ends with a metric row and a set of drill-down buttons. Four are available on every rule: the monthly signal timeline (how this rule and every other rule evaluated each month, with the anomaly score alongside), the anomaly stream detail (the unsupervised stream stated separately from the rule hit, since the two are independent), rule condition coverage (which of the rule's catalog conditions this export can actually answer, and which have no data source — this is what decides confirmed vs candidate), and raw shift data where the employee has overlapping shift records that would undermine any hours figure. The group cluster adds three more covering its members, the flight join and the zone reads.
Every string here is one rule on one employee, with a single exception: Flight-Linked Shift Convergence is a cluster detection, so it surfaces as one string covering five employee IDs rather than five separate strings. It is pinned to the top of the list in every sort order — a confirmed multi-person pattern has no meaningful individual anomaly rank to sort on, and the mitigation spans four rosters plus a planning permission rather than one person. Each member's own profile is reachable from the evidence tables inside Detection. Two data limits bound how far this rule can be taken: the flight link is a temporal join against the published hold-baggage screening window (SRIFAL carries no employee-to-flight assignment), and the zone signal is security-tag presence from the attendance feed, not an access-control grant — Access Control is not a connected source in this deployment.
Loonbeslag (Wage Garnishment) has no real data source in this export and is shown as "cannot evaluate" for nearly every employee (1,849 of 1,885) — that isn't a signal, it's an absence of data, so turning it into an individual case per employee would create noise rather than insight. It remains visible only as a caveat inside each employee's full profile.
Dennis Rule and Heist have partial month-level signal in the underlying data but aren't yet rolled up into a per-employee case in this export, so they are not shown as strings here. Vacation Rule, Employee Damage, Complaints, Duty Free Theft, Unauthorized Crossing, Favoritism, "Not to Work with Someone", and LMS/Identity Swap have no data source at all in this export.
There are two separate feedback signals in this console, shown in the counter top right. Marking a string "false positive" or "true positive" records the ground-truth outcome of the case — the mechanism by which Iveron's rule thresholds and anomaly baselines get retuned over time. The 👍/👎 buttons inside Evaluation and Closure are a separate, lighter-weight signal: they rate whether the automatically generated guidance text at that stage was accurate and useful, independent of how the case itself turned out — that's what would be used to improve the guidance-generation model itself. This preview does not persist either signal between sessions.
Full pipeline detail: analysis/README.md
and CLAUDE.md in the project repository.