1
Intake
Human opens the case
evt-0001
One event stream for humans, AI agents, robots, APIs, approvals, risks, costs, and evidence. This is the shared prototype behind the UiPath, Splunk, FIND EVIL, Google Cloud, and Microsoft hackathon lanes.
Human opens the case
evt-0001
AI agent plans and tests read-only
evt-0002, evt-0005
UiPath robot and APIs gather records
evt-0003, evt-0004, evt-0009
Control plane escalates and blocks risk
evt-0006, evt-0007
Humans ask for evidence and reject release
evt-0008, evt-0010
Report is generated from evidence IDs
evt-0011
CASE-AI-OPS-001
CASE-DFIR-002
CASE-CLOUD-003
| Event | Phase | Actor | Type | Status | Risk | Summary |
|---|---|---|---|---|---|---|
evt-0001 |
intake | human operations-lead |
task_start | info | none | Human opened an AI-agent operations case after a release bot proposed a production change. |
evt-0002 |
planning | ai_agent codex-ops-agent |
plan_update | success | low | Agent created a read-only investigation plan with explicit approval gates before any production action. |
evt-0003 |
evidence_collection | robot uipath-evidence-robot |
robot_task | success | low | Robot gathered the change ticket, linked pull request, deployment window, and service owner. |
evt-0004 |
evidence_collection | api github-api |
api_call | success | low | API confirmed the pull request touches payment retry behavior and has one approving review. |
evt-0005 |
investigation | ai_agent codex-ops-agent |
tool_call | failed | medium | Agent found a failing retry regression test that was not mentioned in the change ticket. |
evt-0006 |
risk_review | ai_agent codex-ops-agent |
risk_signal | warning | high | Case risk escalated because the proposed release affects payments and has failing verification. |
evt-0007 |
execution | ai_agent codex-ops-agent |
tool_call | blocked | critical | Attempted production deployment was blocked by policy before execution. |
evt-0008 |
approval | human operations-lead |
approval_gate | success | medium | Human requested more evidence instead of approving the production deployment. |
evt-0009 |
evidence_collection | robot uipath-evidence-robot |
robot_task | success | low | Robot requested service-owner signoff and attached the failed test evidence. |
evt-0010 |
approval | human service-owner |
approval_gate | success | low | Service owner rejected the release until the retry regression is fixed. |
evt-0011 |
handoff | system agentops-recorder |
handoff_report | success | none | Generated a case handoff report with cited evidence IDs and final rejection decision. |
evt-0012 |
intake | human security-analyst |
task_start | info | none | Security analyst opened a suspicious email investigation with attached endpoint telemetry. |
evt-0013 |
planning | ai_agent dfir-analysis-agent |
plan_update | success | low | Agent proposed an evidence-first DFIR plan: preserve artifacts, list hypotheses, then verify each claim. |
evt-0014 |
evidence_collection | robot sift-collector |
evidence_captured | success | low | Collected email headers, attachment hash, browser download timeline, and endpoint process list. |
evt-0015 |
investigation | ai_agent dfir-analysis-agent |
ai_call | warning | medium | Agent generated an initial hypothesis but flagged one claim as unsupported by current evidence. |
evt-0016 |
risk_review | ai_agent dfir-analysis-agent |
risk_signal | warning | high | System marked the draft finding as provisional because execution evidence was missing. |
evt-0017 |
evidence_collection | api threat-intel-api |
api_call | success | medium | Hash lookup returned low-confidence phishing kit association; raw indicator was redacted in report output. |
evt-0018 |
approval | human security-analyst |
approval_gate | success | low | Human approved containment of the reported message and requested no endpoint isolation. |
evt-0019 |
handoff | system agentops-recorder |
handoff_report | success | none | Generated DFIR report with evidence IDs, unsupported claims, and human containment decision. |
evt-0020 |
intake | human support-manager |
task_start | info | none | Support manager requested an agent that answers customer questions and escalates uncertain cases. |
evt-0021 |
planning | ai_agent gemini-ops-navigator |
plan_update | success | low | Agent created a workflow plan using retrieval, MCP tools, cost guardrails, and human escalation. |
evt-0022 |
evidence_collection | api knowledge-base-mcp |
api_call | success | low | MCP retrieval returned the current refund policy and source URL for citation. |
evt-0023 |
execution | ai_agent gemini-ops-navigator |
ai_call | success | low | Agent drafted a customer answer grounded in the retrieved refund policy. |
evt-0024 |
risk_review | ai_agent gemini-ops-navigator |
cost_signal | warning | medium | Cost guardrail warned that the high-quality model should be reserved for escalations. |
evt-0025 |
approval | human support-manager |
approval_gate | success | low | Human approved the workflow with a rule that expensive model calls are escalation-only. |
evt-0026 |
handoff | system agentops-recorder |
task_end | success | none | Closed cloud-agent workflow case with source citations, cost guardrail, and human approval captured. |