Work in progress · updated 30 Sep 2026 · notes, not conclusions
Analyst Circle
What do the people who investigate alerts actually need from an AI's verdict before they trust it?
For exampleBefore a vendor ships "AI explains this alert", five analysts try the prototype on realistic cases and point to where they'd trust it and where they'd double-check.
- A prototypebefore it ships
- Five analyststry realistic cases
- One change, one numberpublished without names
- The next versionbetter for it
Every month, the next version goes back to the Circle.
Why it matters
Most AI-in-security features are designed without the analysts who will live with them. My own verdict study has no analysts tested yet. The Circle is how that stops.
What I'm trying
- Small groups, 45 minutes a month, working on prototypes rather than slides.
- No vendor logos and nothing recorded without consent; what's learned is published without names.
- Each session ends with one change to a prototype and one number.
What would show it works
Every verdict study on this site shows real analyst reactions, not n = 0.
Next step
Invite the first five analysts. If you investigate alerts for a living, email me with "Circle" in the subject.