Knowledge base
Your knowledge base is free-form context you write in your own words, so L1 triage reasons with what only you know about your estate. Before the model classifies an alert, Mobius retrieves the most relevant entries and adds them to the prompt.
Think of the facts a new analyst would need on day one: what a host does, who owns it, which maintenance windows are normal.
Write an entry
Open the knowledge page in the console and use the New knowledge entry form: a short title, the content in plain language, then Create entry. There is no template — a sentence or a short paragraph is enough.
Pick a scope
- An Organization entry applies to every environment of your tenant — for example, we are a hospital; patient-data hosts are the crown jewels.
- An Environment entry applies to one environment only — for example, bkp-01 runs the nightly backup at 02:00, so heavy disk and network use then is expected.
Triage always reads your organization entries plus the ones for the alert's own environment.
Wait for Embedded
After you save, the status chip shows Pending embed for a moment while Mobius computes the entry's embedding, then flips to Embedded. Editing the content re-embeds it automatically; if an entry shows Embed failed, use Re-embed to retry.
See what triage would use
On any alert, the Context considered by triage panel lists the knowledge entries that would be retrieved for it — a preview of the same context the L1 workflow injects into the model.
Any member of your team (admin or user) can author knowledge. Entries are private to your tenant.
For patterns you have already investigated and want handled automatically, use known behavior rules instead — a rule can close a match without spending any tokens, where knowledge only informs the model's judgement.