What the product does
The selected service tier defines coverage hours, included sources, investigation depth, escalation and reporting.
Aegis combines compatible monitoring and protection sources with Damocles source-health review, alert triage, investigation, escalation, action tracking and service reporting.
Guardian for Australian customers is built, operated and hosted in Australia. All Guardian customer and platform data, including backups and recovery copies, is maintained and stored within Australia.
Guardian retains supported source state, alert and investigation lifecycle, timestamps, disposition, linked assets or users, evidence references, escalation, customer action and review history.
The proposal identifies covered endpoints, users, sources, collectors, ingestion, retention, coverage hours, triage, investigation, escalation, reporting, incident-response boundary and the selected compatible platforms.
Aegis does not guarantee detection or prevention of every malicious event and does not imply unlimited sources, ingestion, retention, investigation, incident response or remediation.
The selected service tier defines coverage hours, included sources, investigation depth, escalation and reporting.
The analyst console can vary; the Guardian customer experience remains stable.
Business-hours, extended-hours and 24×7 options remain distinct where supported and contracted.
A security platform can collect events and raise alerts, but a useful service must also know whether the expected sources are reporting, whether the alert belongs to the customer, what evidence supports the conclusion, who must respond and whether the required action was completed.
Aegis is the Damocles operating service. It can work with supported customer, provider or Damocles-selected technologies while Guardian keeps the customer view, investigation, escalation, risk, actions and reporting consistent.
Monitor expected agents, collectors, integrations and log sources so silence is not mistaken for security.
Use approved rules, asset, identity, vulnerability and customer context to prioritise alerts.
Tell the customer or provider what happened, what evidence supports it and what must happen next.
The selected service tier defines coverage hours, included sources, investigation depth, escalation and reporting.
Track expected agents, collectors, APIs and log sources and identify stale, zero-data, degraded and unavailable states.
Review, prioritise, enrich and suppress avoidable noise using approved logic and customer context.
Assess material activity, collect authorised evidence and record customer-scoped conclusions and disposition.
Use agreed severity, contacts, channels and response paths when customer, MSP or Damocles action is required.
Link required containment, remediation, policy or customer work to Guardian risks and All Actions.
Report monitored scope, source health, alerts, investigations, escalations, actions and unresolved gaps.
The analyst console can vary; the Guardian customer experience remains stable.
Current source health, alerts, investigations, vulnerability context, escalations and open actions.
Customer-readable summary, timeline, evidence, disposition, affected scope and required response.
Expected sources, last-seen state, zero-data and unavailable conditions with ownership and follow-up.
Normalised severity, source, status, priority, linked investigation and customer action.
Coverage, tuning, source gaps, investigations, response quality and unresolved customer decisions.
Authorised customer operations, escalation and reporting for MSPs with clearly defined first-line responsibilities.
Business-hours, extended-hours and 24×7 options remain distinct where supported and contracted.
Confirm source inventory, customer mappings, contacts, priorities, response authority and expected evidence.
Establish expected source health, common activity, asset context and approved detection or suppression logic.
Review source state and incoming security activity during the contracted coverage window.
Gather authorised context, determine likely significance and document the customer-facing conclusion.
Invoke the agreed customer, MSP, incident or emergency pathway when action is required.
Review quality, false positives, source gaps, customer delays and approved tuning opportunities.
Aegis can operate compatible security technologies while preserving one Guardian operating model.
Confirm products, sources, customer scope, contacts, severity model, escalation and response authority.
Establish expected source state, common activity, assets, identities and service context.
Review source health and prioritise security signals during the coverage window.
Gather authorised evidence, correlate context and record disposition and confidence.
Contact the agreed party and create the required action, risk or incident pathway.
Track closure, customer response, tuning, source health and service reporting.
The operating responsibility can be adapted for direct customers and external MSP relationships.
Provide managed source health, triage, investigation and escalation during an agreed business-hours window.
Provide continuous contracted monitoring and escalation where the source, staffing and response model support it.
Allow the MSP to retain first-line customer communication while Damocles provides agreed security-operation escalation.
Operate supported sources from different compatible platforms while keeping the customer workflow consistent.
Use supported asset and vulnerability context to improve investigation priority and remediation.
Use the agreed incident contacts, playbooks and response authority when an investigation crosses the escalation threshold.
These details remain explicit before activation, but are grouped into one operating view so buyers can review the responsibilities without working through four separate page sections.
Aegis onboarding defines the sources, coverage, people and response authority before monitoring begins. Damocles confirms customer and provider relationships, expected agents and sources, selected compatible platform, asset and identity context, coverage hours, contacts, severity model, investigation depth, escalation channels, response authority and reporting. The onboarding period validates source ownership, source health, sample alerts, field quality, customer-safe evidence, disposition, action linkage and handoff between the customer, MSP and Damocles. Go-live requires a documented runbook, source register, escalation matrix, service schedule, reporting cadence, customer responsibilities and a process for source failure, major change and incident-response activation.
Aegis is independent of one vendor platform and can operate supported compatible connectors. The selected security technology remains responsible for collection, platform processing and source-specific functionality. Guardian connectors provide explicit customer mapping, source health, supported alert or investigation data and safe failure state. The public product is Aegis Managed Defence. The proposal identifies the selected platform or connectors, licensing, ingestion, retention, source types and support. This allows a customer to retain suitable existing technology or migrate later without changing the managed-service concept. New connector requests are assessed for API maturity, customer isolation, event and investigation quality, source health, evidence, volume, retention, supportability and engineering effort before being added to a service schedule.
Aegis retains a customer-readable operational record while protecting analyst and platform-sensitive information. Guardian retains supported source state, alert and investigation lifecycle, timestamps, disposition, linked assets or users, evidence references, escalation, customer action and review history. Credentials, raw upstream payloads, unrelated customer records, sensitive detection logic and analyst-only notes remain restricted. Customer reports include enough evidence and context to explain the result without exposing unsafe detail. A failed connector or stale source remains visible in source-health reporting. The absence of alerts is not represented as evidence of a healthy monitoring service when expected data is missing.
Commercial scope separates the technology, connector, capacity and managed analyst service. The proposal identifies covered endpoints, users, sources, collectors, ingestion, retention, coverage hours, triage, investigation, escalation, reporting, incident-response boundary and the selected compatible platforms. Aegis does not automatically include unlimited source onboarding, rule engineering, 24×7 response, forensics, containment, recovery or remediation engineering. Those responsibilities must be expressly listed. The customer or MSP owns timely access, source deployment, response authority and remediation assigned to them. Damocles owns the Aegis activities stated in the service schedule.
The exact answer is confirmed in the proposal and package schedule, but these points should be understood before activation.
Yes where supported connectors exist and the technology provides the source health, alerts and investigation context required.
Only in a contracted 24×7 service tier with the required source, staffing, escalation and response model.
Yes. The MSP and Damocles responsibilities, customer communication and escalation are defined before onboarding.
Monitoring and escalation do not automatically include unlimited containment, forensics or recovery. Incident services are separately defined.
Analysts record disposition and approved tuning opportunities. Material detection or suppression changes follow the agreed change process.
Guardian shows the source-health gap and Damocles follows the contracted operational process rather than treating the service as healthy.
Aegis does not guarantee detection or prevention of every malicious event and does not imply unlimited sources, ingestion, retention, investigation, incident response or remediation.
Unsupported sources, incomplete customer authority, unavailable evidence and unlicensed technology features remain explicit limitations.
Customer, MSP and Damocles responsibilities are recorded before service activation and reviewed when the technology or operating model changes.
We will map the sources, compatible technology, coverage window, analyst duties, escalation, incident boundary and Guardian customer experience.