第 4 层 · ACT · 四层架构
感知与推理只有在产生可问责结果时才算实现价值。第四层将集群的判断转化为客户与监管者可用的行动——在荷兰,按 NIS2 级预期进行。每个行动由智能体提出、由人工把关、并全程留痕。
Detections carry type, severity, confidence and status; the pipeline moves them from new to triaged with a full audit trail. Confidence is a number with a history, not a vibe.
Agents propose actions (block, notify, escalate). Nothing executes without a human approval — approvals, rejections and executions are all logged with timestamps.
Public-source intelligence deepens the picture around a verdict — entities, domains, exposure. Sourced, dated and cited, so the customer can re-verify every claim.
Because every layer logs, a final report isn't assembled after the fact — it is the concatenation of the trail: sensor events, agent correlations, reasoning verdicts, human approvals. That is what NIS2 actually asks for.
Correlated entity intelligence on fraud infrastructure — domains, identities, attack patterns — with evidence attached to every claim.
Dutch organisations under NIS2 need demonstrable process. Continuous detection plus an immutable trail is the posture auditors want to see.
Live, verifiable telemetry (1M+ honeypot events) and an open reasoning architecture — the platform documents itself.