A few minutes now saves your SOC team a feedback cycle later. SARA learns from these facts on the first incident, not the tenth.
You can skip any step. Re-run anytime from Settings → Memory.
Your IPv4 CIDR ranges. We verify each one against APNIC/RDAP to flag mismatches — if you claim a range that actually belongs to a Japanese ISP (we've seen it), you'll see a warning before pinning.
Glob patterns SARA shouldn't tag as suspicious. Internal = corp-DNS-only (not in public DNS); external = your publicly-resolvable tenant domain. We DNS-check externals so a typo doesn't sneak through.
Hostname prefixes your QRadar / Splunk / etc. use. Hostnames matching these are log sources, not IOCs. Example: corp-siem- or winlog- for wincollect / forwarder host classes.
How much can SARA do without explicit analyst approval? This is a default you can change anytime from Settings.
Asks before any write-side action. Best for first-week onboarding.
Read-side enrichment auto-fires. Write-side actions require a confirm.
Mature SOC. Auto-fires advisory actions. Hard-rails (signed inter-agent tasks, audit log, destructive-action gate) still hold.
Summary of what we pinned to your tenant. You can edit any of these from Settings → Memory.
We'll re-verify your network-perimeter CIDRs against RDAP weekly. If a registration changes (e.g. a CIDR is re-assigned), you'll see a banner on your next sign-in.