Objective 1.6 · Lesson 1 of 2

Use AI with evidence you can check

AI can help an analyst organise information, compare artifacts, and draft explanations. Its usefulness depends on whether a person can check its output against the underlying evidence.

Choose tasks with a clear verification path

Suitable starting tasks include comparing two configuration snapshots, summarising a bounded log excerpt, grouping related events for review, and drafting a case update from approved facts. Define the question and the evidence boundary. Ask for references to supplied record identifiers and explicit separation of observation, inference, and missing information. An attractive narrative is not a substitute for those distinctions.

For incident investigation and event correlation, use the model’s suggestions to propose checks rather than certify causation. Similar timestamps or repeated names may be coincidental, and missing context can change the interpretation. Keep deterministic checks for details such as counts, identifiers, and time calculations. The analyst remains responsible for deciding whether the evidence supports the proposed conclusion.

Give the model a bounded evidence set

Supply only the material required for the approved task. Prefer synthetic or appropriately sanitised examples when learning a workflow. Explain field meanings, time zones, known omissions, and what the model may not infer. Redaction should protect sensitive content without destroying the relationships needed for the analysis; replacing every identity with the same label can create false correlations.

Require output that can be reviewed systematically: a short claim, supporting record identifiers, uncertainty, and a proposed next check. Preserve the original artifacts outside the model response. For document creation, verify that a generated incident summary does not add affected systems, impact, or actions that were never established. A polished draft can hide unsupported detail more effectively than a rough note.

Measure whether assistance improves the work

Evaluate the workflow using representative tasks with known evidence and review criteria. Check factual accuracy, omitted critical details, unsupported claims, and time spent correcting output. Include ambiguous and incomplete cases, not only easy examples. A tool that writes quickly but requires extensive correction may increase overall work or make important errors harder to spot.

If AI participates in automation or orchestration, constrain its role. It might suggest a search or draft an action request while a policy-controlled system checks permissions, scope, and approval. Log inputs and decisions according to the approved handling policy. Verify the actual result of any authorised action instead of relying on the model’s statement that it completed successfully.

Keep these points in mind

  • Select tasks whose outputs can be checked against evidence.
  • Keep observations, inferences, and missing information separate.
  • Measure correction effort and accuracy, not just generation speed.

Pause and practise

An AI case summary says three servers were compromised, but the supplied log contains one failed login on each. How should the analyst respond?

Show a worked response

Reject the compromise claim as unsupported. The evidence establishes failed authentication attempts on three servers, not successful access or impact. Correct the summary, retain the source identifiers, and request or gather the additional authentication and host evidence needed to evaluate compromise. Record the error when assessing the workflow’s reliability.

Next lesson →
← Module overview