Skip to main content
Kyberis responses are designed for machine consumers. Agents should branch on stable fields, preserve correlation IDs, and avoid hiding uncertainty. Use response fields to separate facts, ranking rationale, evidence support, and inference in final answers.

Trust model

  • Treat resolution.status and candidates as entity-match provenance.
  • Treat priority_score, environment_match_reasons, suppression_reasons, and what_changed as ranking rationale.
  • Treat confidence_score as support for the result, not business impact by itself.
  • Hydrate important evidence IDs before high-impact reporting.
  • Preserve caveats and unresolved gaps instead of smoothing them into certainty.

Always preserve

  • request_id or X-Request-ID
  • run_id and step_id when present
  • evidence IDs and report refs
  • confidence values
  • caveats and unresolved gaps
  • response status for each batch item

Core response families

Resolution

Evidence

Relationships

Prioritize

Hunt pivots

Assessments

Batches

Errors