Blog Post

Which AI Signals Carry a Finding and Which Only Size It

September 30, 2026

Table of Contents

A correlation rule joins several telemetry sources and fires when they agree. Guidance on writing them concentrates on thresholds, ordering and tuning for noise.

‍

The decision that determines whether a rule works is upstream of all of that. Each source in a rule plays one of three roles, and treating them interchangeably is what produces a rule that misses real events or fires on ones nobody can act on.

‍

What Are the Three Roles?

‍

Constitutive, corroborative and descriptive, and the distinction is about what the rule loses when a source is absent.

‍

A constitutive signal is one without which the finding does not exist. Remove it and there is nothing to report. A corroborative signal raises confidence that a finding is real without being necessary to it. A descriptive signal establishes scope or severity after the finding already exists, answering how large rather than whether. Establishing what each source is authoritative for is the prior step.

‍

What Is the Test?

‍

Ask what you would do if that source were silent. Nothing to investigate means constitutive. Investigate with less confidence means corroborative. Investigate the same thing without knowing its size means descriptive. Three answers, and every leg of every rule gives one of them.

‍

How Does That Map Onto Rule Logic?

‍

Directly, and the mapping is what most rules get wrong.

‍

Detection detail listing each contributing source with its own explanation of what that signal established, from identity authentication through volume, destination and an enrichment record
A rule with a stated contribution per source is one where the roles have been decided. Each line says what that leg established rather than that it matched.

Constitutive signals belong in the conditions that gate the alert. Corroborative signals belong in a confidence value rather than a gate, since requiring them turns confidence into a precondition. Descriptive signals belong in enrichment that attaches to the finding and never delays it.

‍

Which Error Is More Expensive?

‍

Promoting a descriptive signal to constitutive, because it produces silence rather than noise. A rule requiring a data classification before it will alert does not fire on an event involving unclassified data, and nobody sees the events it did not raise. The opposite error produces alerts somebody complains about, which at least gets corrected.

‍

Why Does Coverage Change the Answer?

‍

Because a source covering part of the estate makes any rule that requires it a rule that works on part of the estate.

‍

Source coverage graph showing eight telemetry categories with four filled, indicating which carried this event and which contributed nothing
Four categories carrying an event out of eight connected is the figure that decides whether a source can be a required leg at all.

A browser control deployed to managed devices does not observe unmanaged ones. An endpoint agent covers what it is installed on. Making either constitutive scopes the rule to that population silently, so the rule's real coverage is the intersection of every source it requires rather than the union of the sources available.

‍

Which Argues for Fewer Required Legs

‍

Each additional constitutive source multiplies down the covered population. Two sources at eighty percent coverage each produce a rule covering sixty-four percent if both are required, and rather more if one is corroborative instead, which measuring what a control covers sets out as a general problem.

‍

What Happens to Severity?

‍

It inherits the coverage of whatever supplies it, which produces a bias nobody looks for.

‍

Where severity comes from a descriptive source with partial coverage, the severity distribution describes the covered population rather than the estate. A program reporting no critical findings may be describing a classification source that does not reach the critical systems, and the report looks identical either way.

‍

How Would You Detect That?

‍

Count findings with no severity assigned rather than only the ones with severity. A large unsized population is the signal that the descriptive leg is missing where it matters most, and almost no reporting surfaces it.

‍

Should Severity Ever Gate an Alert?

‍

No, and the timing reason is separate from the coverage reason.

‍

Descriptive signals frequently arrive later than constitutive ones. A volume figure, a data classification or a destination reputation lookup may resolve seconds or minutes after the events that establish the finding. A rule that waits for severity before alerting waits for its slowest source on every occasion.

‍

What Is the Alternative?

‍

Alert on the constitutive set and enrich in place as the rest arrives. The finding exists at its earliest defensible moment and gets more informative rather than more likely, which how wide a correlation window should be addresses from the timing side.

‍

Which Role Do Enrichment Sources Play?

‍

Descriptive almost always, and treating a catalogue lookup as corroborative is a common promotion that does not survive examination.

‍

A vendor risk record, an asset criticality tag or a reputation score describes something that was already true before the event. It did not observe the event and cannot confirm it occurred, so it cannot corroborate anything. What it does is tell you how much the event matters, which is the descriptive job.

‍

Which Makes One Case Interesting

‍

A destination already carrying a known risk record is powerful context and contributes nothing to whether the activity happened. Reading it as evidence that something bad occurred confuses a standing fact with an observation, and the useful version is that the risk was known and was not connected to this actor until the rule joined them. What a telemetry claim has to survive applies to each leg separately.

‍

Does a Role Ever Change?

‍

It does, and a rule written once and never revisited carries whatever the roles were when the estate looked different.

‍

A source at partial coverage that becomes near-universal can be promoted from corroborative to constitutive, tightening the rule without losing reach. One that degrades, through a rollout stalling or a platform moving outside its scope, should be demoted before it starts suppressing findings. The trigger for both is a coverage change rather than an incident.

‍

Which Makes Coverage a Rule Input

‍

A rule whose logic references coverage explicitly can be reviewed when coverage moves. One that hard-codes a required source has no signal that its reach has changed, so the review never gets prompted, and verifying continuously rather than annually is the same argument about controls.

‍

What Is the Cheapest Review?

‍

Comparing each constitutive source's current coverage against what it was when the rule was written. Where a source has fallen materially, the rule is quietly narrower than its author intended, and that comparison needs two numbers rather than an investigation.

‍

What Should Be Recorded Per Rule?

‍

Four things, and almost no rule documentation carries them.

‍

Which legs are constitutive, which corroborative and which descriptive. What the rule does when each is absent, stated rather than implied by the logic. The coverage of each constitutive source, since that is the rule's real reach. Then whether severity can be assigned when the descriptive leg is missing, because the answer determines whether unsized findings appear or disappear. An AI Interaction Data Fabric supplies the per-source contribution the first three depend on.

‍

Decide the Role Before the Threshold

‍

Every source in a correlation rule is constitutive, corroborative or descriptive, and the test is what you would do if it were silent. Constitutive legs gate the alert, corroborative legs move a confidence value rather than a gate, and descriptive legs enrich a finding that already exists. Promoting a descriptive leg to constitutive is the expensive error because it produces silence rather than noise, and nobody sees the events a rule declined to raise. Each required leg multiplies down the covered population, so a rule's real reach is the intersection of its constitutive sources. Severity inherits the coverage of whatever supplies it, so a report showing no critical findings may be describing a source that does not reach the critical systems. Kovrr's AI Security and Governance Platform records what each source contributed to each finding.

‍

To see which sources contributed to each finding and which contributed nothing, book a demo mapped to your own estate.

Yakir Golan

CEO

Correlation Rule Design FAQs

Speak to an Expert

Should every source in a correlation rule be required?

How do you decide which signals a detection rule requires?

Why do correlation rules miss real events?

How does telemetry coverage affect a correlation rule?

Should severity gate an alert?

Are enrichment sources corroborating evidence?