TL;DR
- A large portion of the daily security alert queue is made up of alerts that look almost exactly like cases our analysts have already investigated and closed.
- Our new Ruxie precedent engine feature acts as a long-term memory for the Expel SOC, using AI to instantly recognize when a new alert matches previously triaged historical cases.
- By automatically surfacing this historical context, our analysts bypass redundant research to work significantly faster—meaning you get quicker threat resolutions and zero wasted time, while ensuring human experts stay squarely in control of every single disposition.
When an Expel SOC analyst investigates a fresh Cloud or Endpoint alert, speed is everything. If an alert triggers a sense of ‘déjà vu’, proving that intuition traditionally required digging through closed tickets, parsing raw logs, and cross-referencing multiple tools to find the answer to a simple question: Have we handled this exact pattern before, and if so, what did we do about it?
Amplifying our experts with AI-powered precedent engine
Manually gathering and parsing disparate historical data creates severe friction; it bogs down response times and forces analysts to treat every single alert as brand-new work.
That’s why we gave Ruxie a new AI power up we call the precedent engine—a native capability that immediately stops our analysts from having to hunt for past context. The system automatically transforms raw alert data into a clear, human-readable narrative right at the start of the workflow.
Before the manual investigation even begins, the system provides a plain-language summary that surfaces the most similar historical cases— and how they were dispositioned — as decision support. Analysts can use this as further context in relation to the alert decision, rather than falling victim to trusting AI or accepting a historical disposition. Having this information lets the SOC team make faster, more accurate decisions for your security based on how a similar alert was handled before, and what happened the last time.
How it works
The system operates by extracting high-signal features directly from the alert’s content, which includes the alert name, vendor, severity, vendor message, device or org context, and a prose narrative.
It then embeds this information into a vector space to deeply understand the context of the alert.
Finally, the AI matches this embedding against a store of previously-triaged alerts using a similarity search to instantly pull the most relevant historical data. The system outputs a suggested read (BENIGN, MALICIOUS, or UNKNOWN), a neighborhood summary, the nearest historical matches, and counterfactuals that explain what would change the call.
From there, when the new alert closely matches prior benign cases above a calibrated per-vendor threshold, Ruxie flags it and shows the similar cases and suggested reading. When the match is weak, absent, or drawn from unverified history, it defaults to escalation. A safety gate ensures known true-positive patterns are never called benign (maintaining a <1% suppressed true-positive rate). The analyst always makes the disposition.
How this delivers a better defense for you
Giving our analysts better tools directly results in better security for you. Here is how the precedent engine protects your environment:
- Enhanced triage and prioritization. We use the outputs from the precedent engine as inputs to our rapid alert triage agent, giving additional context to enable the agent to escalate or deescalate alerts leading to a faster MTTT and MTTR for customers. We are able to improve the performance of the agent by taking advantage of years of historical data to improve triage and analyst decisions.
- Speed up threat resolution: By immediately presenting our analysts with the most similar previously-triaged alerts, similarity scores, and exactly how they were closed, we drastically lower our Mean Time to Decision. When our analysts spend less time digging through logs, we identify and stop threats in your environment faster.
- Higher signal, less noise: We use AI to automatically separate false alarms from real threats. The system safely identifies repeat benign alerts, scaling toward an initiative target of a 10% or greater overall queue reduction with less than a 1% change in recall. This means we only escalate the things that actually require your immediate attention.
- Full transparency and trust: Clear answers, not black boxes. The system provides plain-language explanations for its similarity matches (e.g., “9 of 10 nearest neighbors were benign”) and transparently shows counterfactuals. This ensures you see the same facts our analysts used to make their decision, with zero guesswork.
The bottom line
While others use AI to cut corners, we use it to sharpen our tools and amplify human intuition. The precedent engine handles the monotonous, repetitive work of cross-referencing historical queues so our analysts have immediate access to historical context, letting human judgment drive the final outcome backed by verified evidence.
What’s next
The precedent engine is just one of many AI implementations under our broader umbrella. As we continue to refine this long-term memory feature—including planned rollout phases for alert mutation to automatically route repeat noise out of the primary queue—our AI Engineering team is cooking up more power-ups that will be released in the coming weeks.

