Decision inputs
Facts that change the policy answer
The request sits in it and security and connects attack behaviour, existing telemetry and rule syntax with a candidate detection rule. That context distinguishes it from a generic permission to use AI.
- 1Task and owner
- Detection engineer wants to generate a security detection rule. Name who owns the finished a candidate detection rule; ownership should not disappear because AI helped produce it.
- 2Information involved
- Attack behaviour, existing telemetry and rule syntax. Look beyond pasted text: files, integrations and retrieval connections can expose the same material.
- 3Tool and account
- An approved company account. A personal login can handle information differently from the company-managed version of the same tool.
- 4Intended result
- The expected result is a candidate detection rule. Record the audience and the next system in the chain, rather than describing the output only as a draft.
- 5Consequence if it is wrong
- A weak rule can miss attacks or overwhelm analysts with false alerts. Use this consequence to distinguish a routine request from one needing specialist approval.
- 6Human review
- detection engineering owner should inspect, change, reject or stop the result. Their role should include checking source facts, correcting errors and refusing the proposed use.
Possible policy routes
The task name alone cannot decide it.
A published workplace policy can return different answers for the same task. These are the practical branches worth encoding.
A routine policy route may be possible
The request may fit ordinary policy handling once the exact account is approved, only the minimum sensitive security logic is used, a candidate detection rule remains within the stated purpose, and detection engineering owner reviews it before use.
Approval may be required
Specialist approval becomes relevant if the account or data handling is uncertain, a weak rule can miss attacks or overwhelm analysts with false alerts, or a candidate detection rule reaches people or systems beyond the requester’s authority.
The request may need to stop or change
The proposed use should pause if restricted information would enter an unapproved service, the output would act before detection engineering owner can intervene, or test against known benign and malicious data before deployment cannot be maintained. Consider less information, a controlled account or a non-AI process.
Request checklist
Questions to ask before using the tool
- 01
Will generate a security detection rule run inside the approved company environment from start to finish?
- 02
Can any personal, sensitive, confidential or secret part of attack behaviour, existing telemetry and rule syntax be removed?
- 03
Does a candidate detection rule create an external statement, a decision or an automated action?
- 04
What evidence will detection engineering owner use to accept, correct or reject the result?
- 05
Is this genuinely one request, or will repeated use turn it into an embedded process?
Worked request
What the employee should submit
This example supplies decision facts without pasting the underlying material into the approval record.
- requester
- detection engineer
- task
- Use AI to generate a security detection rule.
- information
- attack behaviour, existing telemetry and rule syntax
- tool
- An approved company account
- frequency
- Recurring work
- region
- Where the work and affected people are located
- purpose
- Draft or analyse
- impact
- Security monitoring
- review
- Complete human review
- owner
- detection engineering owner
Useful safeguards
Controls that fit this request
- ✓
Test against known benign and malicious data before deployment
- ✓
Keep whole files, mailboxes and datasets out of the prompt when a short part of attack behaviour, existing telemetry and rule syntax is enough.
- ✓
Set an expiry or review point when recurring work turns into a permanent process.
- ✓
Record the request and reviewer without copying unnecessary parts of attack behaviour, existing telemetry and rule syntax into the audit trail.
Questions people ask
About this AI use
Is using AI to generate a security detection rule automatically allowed?
The company policy supplies the answer after it receives the real tool, data, purpose, impact and review plan. This page only prepares those facts.
When is the request detailed enough to decide?
Describe a candidate detection rule, identify attack behaviour, existing telemetry and rule syntax, name the exact tool and account, explain who will receive or rely on the output, and state how detection engineering owner will review it.
How much of the request should the company retain?
Record the request and reviewer without copying unnecessary parts of attack behaviour, existing telemetry and rule syntax into the audit trail. A classification and controlled reference may be enough when copying attack behaviour, existing telemetry and rule syntax would create unnecessary risk.