AI security & operations for MSPs

Noise Tuning and Silencing

Mute a source under maintenance

If a source is under maintenance or has a known collection problem, an admin can mute it from the Sources page in the portal. Muting stops Hal alerting you that the source has gone quiet and keeps it from counting against overall health; its logs keep flowing in, stay searchable, and Hal still triages them, so you don’t lose any history while it’s muted. To quiet a noisy source, tell Hal what’s normal (below). To stop ingestion entirely, ask the Hal team to disable the source.

The portal’s Sources view, where each source can be muted or silenced

Tell Hal what’s normal

The most direct way to cut noise for a client is a note. Tell Hal in chat what’s expected: a scanner that signs in nightly, an executive who travels to the EU, a service account on a fixed IP. He saves it against your login, and the portal’s Memories page lists every note in force, who added it and when. Hal reads a client’s notes before he escalates, so a pattern you’ve marked as normal stops surfacing as an alert.

A note belongs to one client unless you say otherwise. For a fact that holds everywhere, your own staff’s home addresses, a tool every client runs, say so, for all clients, our RMM signs in from 203.0.113.0/24, and Hal saves it as a global note, read before every client’s triage. The Memories page lists it as global. Notes are never copied client by client, so a new client inherits every global note the day you add it.

Let Hal do the whitelisting

You don’t have to work out which patterns deserve a note, noticing them is part of Hal’s job. Every night, on his night shift, Hal reviews the last two weeks of his own conclusions, picks out the patterns that keep resolving benign with the same explanation, and drafts a whitelist recommendation for each, never more than five a night. They wait for you on the portal’s Health page and in chat; nothing takes effect until you accept one there, and a decline is remembered so the same pattern is never proposed again. The full loop, what is and isn’t eligible, and how decisions are recorded and reversed are on Hal’s night shift.

You can also start the same review yourself. Ask in chat, “what keeps generating noise for this client?”, “help me get my AI cost down”, and Hal goes through the history, drafts the notes, and waits for your confirmation.

Whitelist entries state facts; they don’t mute alerts. A note records what’s true, the named host, service account, IP range, or app, and what it’s expected to do, never “ignore these alerts for this client.” Every new occurrence is still judged against the facts: the sync server’s nightly logons stop surfacing, but the same activity from a different host or an unexpected IP still escalates. An approved app exemption works the same way, it’s bound to the exact app and the scopes you approved, so the same app suddenly asking for more still escalates. New entries take effect on the next triage pass, Hal watches every client every few minutes, and the recurring pattern stops costing you attention, and investigation spend, every day.

Repeats fold into the report

When a detection has already been investigated and delivered and it recurs no worse, Hal records the recurrence against the original report instead of opening a duplicate investigation. The Repeating section of the portal’s Events page lists every active pattern: the client, the founding report, how many times it has recurred and when it was last seen, with each recurrence and anything that differed. A pattern quiet for a day drops off the list. High-severity findings are never folded.

How the built-in filter is tuned

Ahead of all that, the first stage of triage is a blacklist that drops known-safe, high-volume events before they cost anything. That blacklist is maintained for you, if a benign pattern keeps surfacing across clients, ask Hal or reach out and it gets tuned. You never have to write or maintain detection rules yourself.

See what Hal surfaces on your own clients.

No deck. Ask us anything first. When you want to see Hal on your own tenants, we sign a short evaluation agreement and stand up your instance; you connect one tenant, Hal watches it for 14 days, and we walk you through what he found.

  1. 01You ask us your questions. No deck, no demo dataset.
  2. 02You sign a short evaluation agreement, and we stand up your own instance.
  3. 03You connect one tenant from your own admin console. Hal watches it for 14 days.
  4. 04We walk through what he found. Keep going month to month, or revoke the scopes yourself and stop.