StackPilot / Occupation guides / Manual 025

Occupation manual 025 · review-only workflow

AI can organize security-signal evidence. Security decisions stay human.

Use AI to preserve approved reference labels, owners, times, stated purpose, and unknowns. Do not let it access systems, validate an alert, investigate, determine severity or impact, change controls, notify anyone, or take external action.

For: information-security teamsOutput: security-signal evidence packetReviewed: 2026-07-31
Answer-first field map

Build a review packet, not a security operation.

Information Security Analysts plan, implement, upgrade, or monitor measures that protect networks and information; the occupation may include vulnerability assessment and response to security breaches.1 Those consequential activities require authorized evidence, policy, human judgment, and system control. A safe AI workflow organizes fictional or organization-approved minimum-necessary labels and hands the unknowns to named authorities.

InputApproved labels only: supplied reference, owner, time/version, stated purpose, and known gaps.
OutputA Security Signal Evidence Packet ending in needs_review.
Not an outputNo console query, alert validation, analysis, incident decision, ticket, notification, system change, or message.
Standards-source limit: NIST incident-response and AI-risk materials are guidance context. They are not your incident plan, a severity rubric, an evidence-handling rule, or permission for an AI tool to see security data.
  1. Set a strict scope before any AI work.

    Give the packet a fictional or approved scenario label, stated purpose, and named authority owner. Exclude all live alert/log content, hostnames, IP addresses, identities, credentials, ticket text, security-console output, customer data, and system identifiers.

  2. Register supplied labels without drawing a conclusion.

    For each supplied label, record the reference, owner, time/version, stated purpose, and status: approved, unknown, or conflicting. Never ask the model whether an alert is real or what it means.

  3. Let AI organize, not access or investigate.

    AI may format supplied labels, flag blank fields, group duplicate labels, and draft neutral questions. It must not connect to a system, retrieve evidence, interpret telemetry, validate an alert, correlate events, or infer an incident.

  4. Turn missing facts into reviewer questions.

    For every missing owner, time, source, policy, data-handling condition, or approval, preserve the gap as unknown. Ask the authorized security or incident-response owner which current process governs it.

  5. Route authority to the right owner.

    Security/incident response owns technical assessment and response; legal and privacy own obligations; communications owns messaging; business/data/system owners control impact, access, and implementation; records owners control evidence retention.

  6. Stop at the review handoff.

    Issue a local needs_review receipt. Do not open a console, update a ticket, create an alert, change a control, investigate, notify, report, or communicate.

Narrow agent roles

Three bounded roles. One human control point.

Label stewardNormalizes supplied reference labels and flags blank owner, time, stated-purpose, or scope fields. No retrieval, correlation, or validation.
Unknown clerkGroups duplicate or contradictory labels and marks them unknown or conflicting. No technical or risk conclusion.
Handoff assemblerFormats neutral reviewer questions and a local receipt from approved labels. No system connection, ticket, notification, or external output.

The NIST AI RMF is voluntary guidance for incorporating trustworthiness considerations into AI systems.3 Use it as a governance lens, not as a security control or an approval to put security data into a model.

Safe versus approval-required

Let AI prepare labels. Let authorized people control security work.

AI may prepareNamed human approval is required
Format supplied fictional or approved minimum-necessary labels.Access, query, upload, retrieve, or analyze data from any security system, ticket, or environment.
Preserve supplied reference, owner, time/version, stated purpose, and unknown/conflict labels.Validate an alert; investigate; or determine incident, severity, priority, scope, impact, materiality, risk, or evidence meaning.
Draft neutral questions about missing authority or contradictory labels.Contain, eradicate, recover, remediate, notify, disclose, report, communicate, or change any control, credential, configuration, system, ticket, or record.
Produce a local review-only receipt.Approve a vendor/tool, make legal/privacy/compliance conclusions, or take any external action.
Stop immediately if the request contains a live alert/log, identity, endpoint, IP address, hostname, credential, customer data, ticket, security-console output, or requires an assessment, decision, change, notification, or response.
Failure modes

Five ways evidence prep quietly becomes unauthorized security work.

MistakeWhy it failsRepair
“Tell me if this is a real alert.”Validation is a security judgment that can set an incident path.Preserve only the supplied label and route validation to an authorized analyst in an approved environment.
“Summarize these logs.”Logs can be sensitive and interpretation can become investigation.Do not enter logs. Use a label register and request a separately authorized evidence-handling path.
“Rate this critical.”Severity and priority may drive actions, commitments, and notifications.Mark the rating as unknown and route the question to the current authorized rubric and owner.
“Open a ticket for the team.”Creating or updating a ticket is a system write and may trigger workflow or disclosure.Generate only a local receipt; an authorized human decides whether and where to record it.
“Send the incident summary.”Communication can create legal, privacy, contractual, and reputational effects.Stop at reviewer questions; human owners approve content, audience, channel, and timing.
Runnable local artifact

Security Signal Evidence Desk

Enter only fictional or organization-approved, minimum-necessary labels. This form stays in the browser and creates a review-only receipt; it does not send, save, query, or connect to anything.

Primary sources

What this manual is built on.

Sources are evidence context, not permission to use private material, assess a security event, or take security/system action. Recheck them and the controlling organization rules before any non-fictional use.

Related guides

Where this guide fits.

Proposed links: the Computer Network Architect Change Evidence Desk for controlled network changes, the Computer Systems Engineers and Architects Evidence Desk for architecture decisions, the Web Administrator Operations Manual for site operations, and the Occupation AI Workflow Guide Directory for the broader shelf. Use these related guides to keep each workflow's authority boundary clear.