Guardian Managed Defence

Know which sources are healthy, what was investigated and what still needs action.

Guardian Security Operations provides the customer and provider workspace for source health, alerts, investigations, vulnerability context, escalation, actions and operational reporting. Compatible connectors provide the underlying security data and Aegis can add Damocles managed operations.

Synthetic Guardian Security Operations workspace showing source health, alerts, investigations and customer actions.
Synthetic Security Operations demonstration data using the Guardian business-workspace style. No customer information.
Agent, collector and source healthAlert and investigation lifecycleVulnerability and asset contextAegis managed operations
The operational problem

Customers should not need to visit several specialist consoles to learn whether monitoring is working or an investigation requires their response.

A security operation depends on healthy agents, collectors, integrations and log sources. It also depends on a clear alert lifecycle, documented investigation, response ownership and customer action. A quiet console can mean there are no alerts, or it can mean the expected data is missing.

Guardian Security Operations presents those operational facts in one customer and provider workflow. The selected compatible monitoring and vulnerability connectors remain behind the product. Aegis is the optional Damocles service that performs contracted monitoring, triage, investigation and escalation.

01

Know the monitoring coverage

See which expected agents, collectors and sources are healthy, stale, zero-data, degraded or unavailable.

02

Understand the investigation

Follow customer-scoped alert priority, investigation status, evidence, disposition and linked context.

03

Drive the required response

Move confirmed activity into escalation, risk, incident or All Actions with ownership and evidence.

Product capability

The common customer operating layer across selected security sources and managed services.

The exact source types, fields and service coverage depend on the compatible connectors and package schedule.

OV

Operations overview

Current source health, alerts, investigations, vulnerability posture, actions and approved reports.

SH

Source-health register

Expected agents, collectors, APIs and log sources with last-seen and operational state.

AL

Alert lifecycle

Normalised severity, priority, source, status, affected scope and linked investigation.

IV

Investigation records

Customer-readable summary, timeline, evidence, disposition, owner and required response.

VC

Vulnerability context

Use supported asset and vulnerability information to improve investigation and remediation priority.

AR

Actions and reporting

Connect response to risks and All Actions and report material activity and unresolved gaps.

What the customer sees

Customers see service health and required decisions without operating the underlying platforms.

Authorised operators retain the specialist depth they need while Guardian keeps customer and provider views consistent.

BH

Business health view

Which products and sources are active, degraded, unavailable or not configured for the customer.

AQ

Alert queue

Material customer alerts with severity, priority, source, status and investigation linkage.

ID

Investigation detail

What happened, affected scope, evidence, disposition, next action and current owner.

ER

Escalation record

Priority, contact path, notification, response authority and customer or provider follow-up.

OA

Operational actions

Containment, patching, identity, configuration, user or investigation work in one queue.

SR

Service reports

Coverage, source health, alerts, investigations, escalations and unresolved actions for the selected period.

What Damocles manages

Damocles can manage the connectors, source-health process and Aegis analyst service according to the contract.

Platform capability and managed analyst responsibility remain separate so the customer knows who is doing the work.

CO

Connector onboarding

Configure authentication, customer mapping, field translation, synchronisation and safe source-health checks.

SI

Source inventory

Confirm expected sources, owners, data paths, reporting state, retention and support contacts.

DQ

Data-quality review

Review duplicate or stale records, missing ownership, unsupported fields and customer-scope problems.

AT

Aegis triage

Where selected, Damocles analysts review and prioritise security activity during the contracted window.

IN

Investigation and escalation

Gather authorised context, record disposition and invoke the agreed customer, MSP or incident pathway.

SV

Service improvement

Review source gaps, false positives, investigation quality, customer delays and approved tuning changes.

Operating lifecycle

From connected source to investigated activity, escalation and reviewed closure.

The service schedule defines the sources, coverage, investigation depth, response authority and customer responsibilities.

01

Define scope

Confirm products, sources, customer ownership, contacts, severity model and required operating coverage.

02

Connect and baseline

Onboard compatible connectors and establish expected source state and common activity.

03

Monitor and triage

Track source health and prioritise supported security activity during the service window.

04

Investigate

Use authorised asset, identity, vulnerability and event context to determine significance.

05

Escalate and act

Notify the agreed party and create the required action, risk or incident response pathway.

06

Review and improve

Track closure, source health, service quality, tuning and recurring reporting.

Common use cases

Common Security Operations models.

Guardian can support customer-operated, provider-operated and Damocles-managed security operations using compatible connectors.

CT

Customer-operated team

Use Guardian for source health, customer workflow, actions and reporting while the internal team performs triage and investigation.

MS

MSP first-line operations

Allow an external MSP to manage authorised customers and retain first-line response under an agreed escalation model.

AE

Aegis Managed Defence

Add Damocles source-health monitoring, triage, investigation, escalation and service reporting.

HY

Hybrid source estate

Use supported connectors across different security technologies while retaining one customer workflow.

TR

Technology transition

Preserve customer actions and reporting while the underlying security platform or connector changes.

IR

Incident-readiness linkage

Use approved incident contacts, playbooks and response authority when an investigation crosses the escalation threshold.

Onboarding and implementation

Onboarding starts with the expected sources and responsibility model—not the number of events.

Damocles documents the customer and provider relationship, compatible connectors, agents, collectors, log sources, source owners, data paths, retention, assets, identities, service contacts and escalation levels. Each source is mapped to the correct customer before operational data is exposed.

Sample source-health, alert and investigation records are reviewed to confirm field mapping, severity, status, disposition, evidence, customer-safe presentation and action linkage. Unsupported fields and source limitations are recorded before go-live.

Where Aegis is selected, onboarding also defines coverage hours, triage rules, investigation depth, communication, response authority, incident boundary, service reporting and handoff between the customer, MSP and Damocles.

Connector and integration model

Compatible connectors keep the Guardian product stable as the customer technology changes.

A Security Operations connector must provide explicit customer ownership, source health, stable identifiers, supported alerts or investigations, lifecycle state and safe error information. Browser-controlled tenant identifiers or fuzzy names are not used as customer authority.

The implementation can use a supported customer platform, provider-operated system, self-hosted option or Damocles-selected technology. The proposal identifies the connector, licences, fields, source types, ingestion and retention without turning that vendor into the public product name.

New connector requests are assessed for API maturity, tenant isolation, source-health capability, data quality, event volume, investigation fields, evidence handling, rate limits, retention, support and engineering effort.

Data, evidence and reporting

Guardian preserves the operational record without exposing unsafe platform or analyst detail.

Supported source references, source state, alert and investigation lifecycle, timestamps, disposition, linked assets or identities, evidence, escalation, actions and review history remain traceable. Customer views expose only approved fields.

Credentials, raw upstream payloads, unrelated tenant data, restricted detection logic and analyst-only notes remain role restricted. Reports explain the customer outcome without disclosing unsafe implementation detail.

A failed connector, stale agent or missing source remains visible. Guardian does not convert missing telemetry into a healthy zero-alert result.

Commercial unit and responsibilities

Commercial scope separates connected technology, source capacity and managed analyst service.

The package schedule identifies endpoints, users, agents, collectors, log sources, compatible connectors, ingestion, retention, platform operations, coverage hours, triage, investigation, escalation, reporting and the provider relationship.

A connected monitoring product does not automatically include Aegis. Aegis coverage is separately contracted, and 24×7 service is included only in an approved tier that supports it.

The customer or MSP owns access, source deployment, response authority and remediation allocated to them. Damocles owns connector and Aegis activities listed in the service schedule. Incident response and engineering remain separate unless included.

Frequently asked questions

Questions buyers ask about Guardian Security Operations.

The exact answer is confirmed in the proposal and package schedule, but these points should be understood before activation.

Q1

Can Guardian connect to our existing security platform?

Yes where a supported connector provides the customer mapping, source-health and lifecycle fields required.

Q2

Does Guardian replace the underlying platform?

No. The platform performs source-specific collection and analysis. Guardian provides customer operations, actions, evidence and reporting.

Q3

Can Damocles monitor it for us?

Yes through Aegis with the sources, hours, triage, investigation and escalation stated in the service agreement.

Q4

Can an MSP remain first-line?

Yes. The provider and Damocles responsibilities and customer communication path are defined before onboarding.

Q5

What happens if a source stops reporting?

Guardian shows stale, zero-data, degraded or unavailable state and the operational process follows up the gap.

Q6

Is incident response included?

Only where expressly contracted. Monitoring and escalation do not automatically include unlimited forensics, containment or recovery.

Scope and boundaries

Security Operations coverage follows the compatible connectors and contracted service responsibilities.

Guardian does not imply unlimited sources, ingestion, retention, rule development, monitoring hours, investigation, incident response or detection of every malicious event.

Unsupported sources, incomplete customer authority, unavailable evidence and unlicensed technology features remain explicit limitations.

The public product remains vendor neutral, but the commercial schedule identifies the selected implementation, quantities, coverage and support boundaries.

Take the next practical step

Review the sources, customer views and operating responsibilities required for a useful Security Operations service.

We will map the expected sources, current technologies, compatible connectors, source health, investigation workflow, escalation and Aegis coverage.