Skip to content
English
  • There are no suggestions because the search field is empty.

User Guide: AI Categorization Agent

Overview

The Categorization Agent determines the category, subcategory, and criticality of a Physical Security Incident (PSI) using Knowledge Base articles and the record's own context. It runs automatically whenever a new PSI is created and can also be invoked on demand from any alert or incident via the Categorize action. Built in AI Agent Studio, it cuts manual triage effort and standardizes categorization regardless of how a PSI originates.

What's New

  • Automatic categorization on PSI creation — when a new PSI is created, the Categorization Agent runs immediately and fills in category, subcategory, and criticality. No manual step required.
  • Categorize action — the manual "Help Me Categorize This Alert/Incident" action remains available on any record, powered by the same agent.
  • Context-aware analysis — the agent uses the record's title and description plus multi-field context: location, involved personnel, time of day, attached assets, and reporter role.
  • KB-driven definitions — category and subcategory definitions come from standardized Knowledge Base articles, with semantic triggers defined per category/subcategory pair. A KB template and AI Search profile are configured for agent access.
  • Confidence scoring — confidence is posted as a percentage in the record's work notes. When semantic matches are weak, the agent recommends rather than applying changes automatically.
  • Transparent updates — every categorization decision is written to the record's activity stream with before/after values, so the reasoning is visible on the record itself.
  • Knowledge Graph support — a knowledge graph is used as a tool to improve categorization reasoning beyond text matching alone.

                How It Works

                Automatic: on PSI creation

                1. A new PSI is created in the Bearing SOC Workspace.
                2. The Categorization Agent reads the record's title and description, then gathers surrounding context — location, involved personnel, time of day, attached assets, reporter role.
                3. It compares that context against category and subcategory definitions in the Knowledge Base, using semantic triggers and the knowledge graph.
                4. It sets category, subcategory, and criticality — or, if confidence is low, posts a recommendation instead.
                5. The result and its confidence score are logged in the PSI's work notes.
                6. Open an uncategorized — or questionably categorized — alert or incident.
                7. Click Categorize to invoke the agent.
                8. Review the result: category, subcategory, and criticality, with the confidence score noted in work notes.
                9. If confidence was low, the agent will have recommended rather than applied. Review the recommendation and set the categorization yourself if appropriate.

                          Manual: "Help Me Categorize This Alert/Incident"

                                  Confidence Scoring & Reviewing Recommendations

                                  Every categorization carries a confidence percentage in the work notes, whether it ran automatically or was triggered manually.

                                  • High confidence — the agent applies category, subcategory, and criticality directly to the record.
                                  • Low confidence — the agent leaves the fields unchanged and posts a recommendation for you to review and apply manually.
                                  • Maintain KB articles — keep category and subcategory definitions current using the standard template.
                                  • Keep semantic triggers distinct — overlapping triggers between categories are the most common cause of low-confidence results and misclassification.
                                  • Review agent output periodically — scan work-notes entries to catch drift, then update KB content accordingly.
                                  • Watch the low-confidence rate — a rising share of recommendations rather than applied categorizations is an early signal that KB definitions have fallen behind how incidents are actually being reported.
                                  • Audit applied categorizations — spot-check high-confidence results as well as low ones, to confirm the agent is drawing category lines where your organization expects.

                                      Low confidence usually means the record's context matched semantic triggers across more than one category, or matched none of them strongly. These are the records worth reading closely: they often point to a KB article that needs sharpening.

                                      Activity & Work Notes Transparency

                                      Each agent action is written to the record's activity stream with before/after field values and a confidence score. Categorization stays auditable — you can always see what the agent set, what it changed from, and how sure it was.

                                      For Admins: Keeping the AI Accurate

                                      • Maintain KB articles — keep category and subcategory definitions current using the standard template.
                                      • Keep semantic triggers distinct — overlapping triggers between categories are the most common cause of low-confidence results and misclassification.
                                      • Review agent output periodically — scan work-notes entries to catch drift, then update KB content accordingly.
                                      • Watch the low-confidence rate — a rising share of recommendations rather than applied categorizations is an early signal that KB definitions have fallen behind how incidents are actually being reported.
                                      • Audit applied categorizations — spot-check high-confidence results as well as low ones, to confirm the agent is drawing category lines where your organization expects.