Source versus conclusion
Keep source events, detector results, investigator notes, approvals, contradictions, and unknowns as distinct evidence layers.

Endpoint, identity, cloud, network, and disk evidence still matter. KAIDAN adds source-attributed model, agent, tool, retrieval, gateway, guardrail, and custody metadata without treating a vendor verdict as proof of what happened.
Keep source events, detector results, investigator notes, approvals, contradictions, and unknowns as distinct evidence layers.
Record stable agent identity, MCP server, tool grant, handoff, observed outcome, collection time, and each source's visibility ceiling.
Bind manifests, member digests, ledger links, signatures, and timestamp receipts so an authorized reviewer can check technical consistency outside Briard-AI.
Texas DIR says covered state agencies and local governments must report a qualifying security incident within 48 hours after discovery, or notify the secretary of state when election data is involved. DIR also states that incident details and a cause analysis are due within 10 days after eradication, closure, and recovery.
An event involving AI is not automatically reportable merely because AI was present. The affected entity and its authorized legal and incident leaders must apply the actual facts and governing law.
Read current DIR guidanceThis material supports technical documentation. It is not legal advice and does not decide whether an event is reportable.