In this section

Module Summary

Module 0
01

What this module established

Seven sections, in one line each
WHERE EACH TAKEAWAY CAME FROM
 
  0.1   translation collapses, reasoning does not
        reliability tracks how much you already hold
  0.2   the failure is not a diligence problem
        plausibility and correspondence are different checks
  0.3   the six modes, each with its own check
  0.4   the estate, and the four kinds of context
  0.5   your calibration, and scoring the request first
  0.6   automated language arrives with no policy attached
  0.7   passing a correct artifact is half the skill
 
GO BACK TO THE SECTION, NOT THE LINE. THE LINE IS THE
CONCLUSION AND THE SECTION IS WHY IT HOLDS.

An assistant collapses translation, not reasoning. The hours in a shift go on turning a question you already understand into a query language you use often enough to be competent and not often enough to be fluent. That is what gets faster. Choosing the question, knowing the estate, making the decision and owning the outcome do not move.

Reliability tracks how much of the answer you already hold. Ask for expression of something you understand and you will catch an error, because you know what the answer should look like. Ask it to determine something you do not understand and you have no way to check, which is when it is most likely to be confidently wrong.

The failure is not a diligence problem.

WHY THE COLLEAGUE HEURISTIC STOPS WORKING
 
  latency          gone. Everything arrives at the same speed.
  hedging          gone. Nothing is qualified.
  register         gone, in the sense that matters: the
                   confident register is the only one.
  track record     gone. There is no history to draw on.
 
YOUR HEURISTIC WORKED BECAUSE HUMAN CONFIDENCE AND HUMAN
ACCURACY CORRELATE. THESE FOUR SIGNALS ARE HOW YOU READ IT,
AND ALL FOUR ARE ABSENT.

Plausibility and correspondence are different checks. Reading an artifact attentively and finding nothing malformed feels like verification. It is not. Correspondence means asking what would have to be true for this to answer your question, and confirming it.

Plausible field, silent window, wrong join key, confident absence, right answer to the wrong question, invented precision.

Those six cover the practical ground. Each carries a check, and running them in cost order means the ones you abandon under pressure are the ones that overstate a figure rather than the ones that close an incident wrongly.

Automated judgment is already in your estate. What is new is automated language: action has been policy-governed for years, and language arrives in an analyst's hands with no policy attached.

The assistant supplies fluency with the language. You supply everything about the place.

The estate is the point. Every fact about Northgate is absent from any model's training data, and most wrong answers are a general truth applied to a specific estate where it does not hold.

Your own calibration is measurable, and it is about you rather than the tool. Your hit rate on plausible artifacts is lower than it feels, your false-positive rate is not zero, and both vary by table in ways you can predict. Scoring the request before the answer moves the check earlier, where it is cheaper.

Passing a correct artifact is half the skill. The drill includes a sound query for that reason. An analyst who flags everything is slower than one who writes their own queries, and a habit that costs more than it returns is dropped inside a fortnight.

02

The one question to carry forward

The check that costs least and catches most
What would have to be true for this answer to be correct?

Everything in the modules that follow is a variation on it. The six failure modes exist so that the question has a short, finishable answer rather than an unbounded one.

03

Your first step

One thing, this week
hands on

Not a summary of the module. What to do on your next shift.

First step What to do on your next shift
THIS WEEK
 
[ ] Pin the pre-flight from 0.5 somewhere you will see it.
 
[ ] Rewrite one request before sending it. Replace "around the
    alert" or "recently" with an absolute time range. Notice
    whether the answer changes.
 
[ ] On the next empty result you get, prove the query could have
    returned rows before you treat the zero as a finding.
 
[ ] Ask your estate one boring question. Daily sign-in volume,
    or which accounts are noisiest. You are building the baseline
    that makes everything else checkable.
 
[ ] Once, write down your judgment of a generated artifact BEFORE
    you check it. Then check it. That number is your calibration.

A thirty-day plan and a team-adoption path are not in this module, and deliberately so. Both are course-level artifacts rather than module-level ones, and the course ends with a specification you complete in your own estate, which is where they belong. What belongs here is the checklist above: five things, this week, none of them needing anybody's permission.

04

What comes next

Where this module stops

Module 1 takes the same habit into triage: what an alert is actually asserting, which half of enrichment hands over, and the queries that answer whether an alert is real. Three accounts are worked and they end differently, because one is nothing, one is a compromise nobody alerted on, and one does not resolve at all.

From there the course moves through the work rather than through the tooling. Detection logic and hunting, then investigation and reporting, then architecture and governance, and it closes with a specification you complete in your own estate rather than a fifth Northgate exercise. Every module ends with something you built.

💬

How was this module?

Your feedback helps us improve the course. One click is enough, comments are optional.

Thank you, your feedback has been received.