External Signals
External Signals is an inbox of feed articles and manually added notes, matched against your assets. Nothing here becomes risk evidence on its own — only what you triage does.
Queues
Three count chips at the top of the page split the inbox by state; click one to filter the list:
| Queue | Meaning |
|---|---|
| Matched | Open signals matched to at least one asset |
| Unmatched | Open signals that matched no asset yet |
| Resolved | Signals you have explicitly dismissed |
Attaching evidence or raising a risk does not resolve a signal — a signal can match several assets, and acting on one must not close the finding for the rest. A signal only reaches Resolved when you Dismiss it.
Adding a Signal Manually
Click Add signal and fill in:
- Heading (required)
- Summary (optional, multi-line)
- Source link (optional URL)
A manually added signal runs through the same asset-matching and analysis pipeline as a fed-in signal, and lands in the Matched or Unmatched queue accordingly.
The Signal List
Each row shows the signal’s heading, a source chip (Feed, Manual, or VSOC), its status (once resolved), the published date, a chip for each matched asset, and a Beacon’s analysis chip if analysis has run for that signal.
The source chip tells apart where a signal came from: Feed ingestion, a Manual entry, or VSOC — reported by a vehicle security operations centre (your own fleet monitoring), which is a different claim from a person typing it in. Whatever the source, every signal runs through the same asset-matching and analysis pipeline.
Triaging a Signal
Click a row to open the signal on its own page. It shows the full summary, a View source link (if one was provided), and — once linked — which risk(s) it was attached to as evidence.
?item=N) still work — they redirect to the signal’s page automatically.Matched Signals
For each matched asset, the page shows either Beacon’s analysis (with a suggested severity) or the raw matched keywords if analysis hasn’t run yet, plus two actions:
- Attach to risk — pick an existing risk on that asset from the dropdown, then Attach as evidence to record the signal as Monitor evidence on it. If a risk was already raised or attached for this signal on a different matched asset, it appears as an option here too — picking it links this asset to the same risk, so one Monitor risk can span every asset the signal impacts.
- Raise Monitor risk — create a new Monitor-type risk on that asset from this signal. Raising a risk for the same signal and asset again re-uses the existing risk rather than creating a duplicate.
Both actions leave the signal open (still Matched) so you can keep working through its other matched assets — it is never auto-resolved.
Unmatched Signals
If a signal didn’t match any asset, the page explains why (or says no match was found) and lets you match it manually — pick an asset from the autocomplete and click Match manually. It then becomes a matched signal you can triage as above.
Other Actions
- Re-analyze — re-run Beacon’s analysis on demand for a matched signal.
- Dismiss / Reopen — close a signal you don’t need to act on, or bring a dismissed signal back to the open queues.
Beacon’s Analysis
When an Intelligence provider is configured, Beacon runs an AI pass over each matched signal — scoped to just that signal and the assets it matched — and produces a short, plain-language insight (what in the signal touches this asset, and what to check or do next) along with a suggested severity of high, medium, or low. This runs automatically after a signal is ingested or matched, and on demand via Re-analyze.
Beacon’s analysis appears in three places: the signal’s page, a chip on the signal’s row in the inbox, and as the detail text on the matching finding in Findings. If you raise a Monitor risk from a signal, the suggested severity becomes the new risk’s priority.
Without an Intelligence provider configured, Monitor falls back to the deterministic keyword match with no error — analysis is a purely additive layer on top of matching.
Feed Ingestion
Automatic feed ingestion is controlled by the External signals rule on Rules and is off until you turn it on. Manually added signals always work, regardless of this setting.