Auditing the AI's Dismissed Alerts
4 min read · Last updated · Page version 4
Burrow auto-hides alerts the Triage AI judged not real from the Active and Open tabs on the Alerts page. The intent is to keep your work queue focused on what still needs an operator. The AI is not always right, though - this article covers the two spot-audit toggles and the cadence we recommend for reviewing the AI's calls.
Why AI-dismissed alerts auto-hide from Active
Without the auto-filter, every shift starts with the operator wading past AI verdicts they have no intention of overriding. With the filter on (the default), the Active and Open tabs only show things that genuinely need a human decision. Faster triage, lower fatigue.
The trade-off: if the AI dismisses something it should not have, the operator might never see it. That is what the audit chips are for.
Two audit chips: silent vs emailed
On the Alerts page, at the right end of the severity-band chip row, sit two toggle chips:
- + AI-dismissed (silent) - includes AI-dismissed alerts that were never emailed. The AI decided "not real" before any email was sent, so you were never told. Flipping this on lets you spot-check that the AI has not been silently dismissing signal you should have seen.
- + AI-dismissed (emailed) - includes AI-dismissed alerts that were emailed. In these, the email was sent first and the AI's "not real" verdict landed later. You got the email; the dashboard normally still shows the alert on Active for a reason (see the note below). Flipping this on lets you see that bucket independently.
Both default off. Each chip controls its own bucket. When a chip is on it flips its label to − AI-dismissed (silent) or − AI-dismissed (emailed) to show it is active. Both are per-session - a browser refresh resets them to off so you do not accidentally leave them on forever.
Note: emailed alerts are already visible
There is one important quirk of the emailed bucket: an emailed alert stays visible on Active by default anyway, even after the AI dismisses it. That deliberate exemption stops the "operator got an email but cannot find the alert" credibility gap during the short race window between the email being sent and the AI finishing its verdict.
So most of the time, flipping the emailed chip on will not show many new rows - the alerts you got emails for are already in the queue. The chip is there for the case where you want to spot-audit the bucket as a set, distinct from the ones that were also mixed into Active.
When to use each chip
A reasonable cadence:
- Silent chip - flip on once per shift, work top-down through the AI-dismissed entries for whatever lookback window you care about (24 h is fine on a busy tenant; widen to 7 d on a quiet one), then flip off and continue with the focused queue. The goal is to confirm the AI's pattern of judgement is matching your own.
- Emailed chip - needed less often. Useful when reviewing a specific past incident and you want the AI's dismissal history for a user + category grouped in one view.
If you ever find a real alert the AI dismissed, override it (see below) and raise a support ticket so the engineering team can look at the verdict. Repeated misses on a specific category are the strongest signal for tuning the underlying rule.
The Dismissed tab as the persistent home
Whether or not the audit chip is on, the Dismissed tab on the Alerts page always shows the full set - both operator-dismissed and AI-dismissed alerts together. Filter, sort, and search work normally there.
The two kinds are distinguished visually on the row:
- AI-dismissed - empty status select plus the AI · NO verdict badge.
- Operator-dismissed - "Dismissed" shown in the status select (no AI badge needed; the operator's identity is in the audit history).
Overriding the AI
The operator override always wins. If you disagree with an AI dismissal, open the alert and set the status to Acknowledged, Investigating, or Escalated in the drawer or via the inline status select. The alert leaves the Dismissed tab, leaves the AI-dismissed pile, and stays visible under the tab matching the disposition you chose until you close it yourself.
The history of that override is logged on the History page with your operator identity, the original AI verdict, and your new disposition.
See also
- Quick tour of the Burrow dashboard - the Alerts page in context.
- Investigating an alert - the canonical SOC workflow.
- Reading the evidence box - what the AI verdict is and how it is generated.
- Burrow FAQs - including "Where did my AI-dismissed alerts go?"
Need help? support@smikar.com.