← Back to blog

Coverage is a ceiling on confidence, and that is arithmetic

A customer running one EDR agent, who wants confident verdicts and fewer questions, is asking for something the evidence arithmetic cannot produce. Not difficult, not expensive — structurally unavailable. This is the most uncomfortable thing that fell out of working on the evidence calculus, and it is uncomfortable because it is not an opinion about service quality.

How belief actually accumulates

In the evidence framework this system uses, each source of evidence commits some amount of belief to an explanation and leaves the rest uncommitted. Uncommitted belief is not distributed to the other explanations. It sits on "I do not know", explicitly, as a first-class quantity.

That has a consequence people find counterintuitive: a single source cannot push belief past its own strength. One sensor family reporting strongly in favour of an explanation leaves you at roughly that source's strength, with the remainder as ignorance. The only operation that moves belief higher is corroboration — a second, independent source committing belief to the same explanation. Two independent sources agreeing produce more belief than either alone. That is the entire mechanism by which confidence is built.

So the maximum belief reachable in any investigation is a function of how many independent sources can speak to the question. Not how good the analyst is. Not how good the model is. How many genuinely separate witnesses exist.

The rule that makes this bite

"We looked and found nothing" is evidence. "We could not look" is not.

If an explanation predicts a trace, and you queried the right place, and it was clean — that argues against the explanation. If the source does not exist in the tenant at all, its silence says nothing whatsoever, and treating it as reassurance would convert a blind spot into a clean bill of health.

This is not a design preference. It is the single most important safety property in the system, and getting it backwards is how an agent confidently closes an intrusion it was never able to see. So a missing sensor contributes ignorance. There is no operation, in this framework or any honest one, that converts absence of capability into evidence of innocence.

Put the two together. Belief rises only through corroboration from independent sources, and a source you do not own contributes nothing to corroborate with. Coverage is therefore a hard ceiling on achievable confidence, and it is arithmetic rather than an argument about diligence.

What that looks like against a real threshold

This system closes a case benign at belief 0.60 and reports a harmful verdict at 0.70. Both are chosen values, not fitted ones, which matters for the exact figures below and not at all for the shape.

Independent sources able to speakAchievable beliefCan it close at 0.60?
One, reporting stronglyBounded by that source's strengthNo — and no incident will change that
One strong, one unavailableUnchangedNo — the absent one adds ignorance, not support
Two independent, corroboratingMaterially higher than either aloneYes
Two, disagreeingConflict, which routes to a questionNo — and more of the same telemetry will not fix it

Read the first row again. It does not say confident verdicts are rare on a single-source tenant. It says a certain class of them is unreachable, for every incident, forever, regardless of how clean the evidence is or how carefully anyone reasons about it.

The correction that makes this survive scrutiny

The strong version of this claim — "you cannot reach high confidence on a thin tenant" — is too broad, and anyone in the industry will find the hole in about four seconds. So here is the scoped version, which is the true one and is also sharper.

A single-sensor tenant can reach high confidence about explanations whose predicted traces are entirely visible to that sensor. An EDR-only tenant can conclude a great deal about process execution on a managed endpoint, with real confidence, because everything the competing explanations predict is visible in the one place it can see.

What it cannot do is refute a harmful explanation that predicts traces across several domains. And that is the whole problem, because harmful explanations are almost always the multi-domain ones. "The account was compromised and used for data access" predicts an anomalous sign-in, a token issued to a new device, follow-on control-plane activity, a mailbox rule, process activity on the workstation that held the token. To argue that explanation down, you have to look in each of those places and find them clean. A tenant that can only look in one of them can never accumulate enough disbelief to eliminate it.

The benign explanation and the harmful one are not symmetric. Confirming ordinary activity often needs one source. Ruling out a compromise needs several, because a compromise leaves traces in several places and its absence has to be established in each.

Which is why the two complaints are the same complaint

Customers who buy minimal telemetry tend to raise two objections, usually in the same conversation, without noticing they are connected.

"Why are you asking us so many questions?" Because when the available telemetry cannot close the gap, the only remaining source of evidence is a human who knows what was supposed to happen. The question rate is not a measure of how thorough or how lazy the analysis is — it is mechanically downstream of how much the sensors could settle. Fewer sensors, more questions. This is the one I find most instructive, because the agent exhibits it too: the less telemetry a tenant has, the more it leans on asking the customer, which is exactly the opposite of where you would want that reliance to fall.

"How did you miss this?" Because an attack that leaves traces in five places, observed in one of them, is visible only if it happened to touch that one. Coverage determines what is detectable before any analysis happens at all.

Same root cause, two symptoms, and both land on the service provider as a quality complaint.

The fair version of the customer's position

Budgets are real. Telemetry licensing is genuinely expensive, and every vendor saying "you need more signal" has an obvious financial interest in that sentence, including me. A small business deciding that endpoint detection is what it can afford is making a legitimate decision, and being condescended to about it is not useful.

So the honest formulation is narrower than "buy more telemetry", and it is this: a customer is fully entitled to accept the risk that comes with limited coverage. What does not follow is attributing the consequence to the quality of the analysis.

You can choose the coverage or you can choose the confidence. You do not get to choose both, and the gap between them is not a service failure.

The constructive version

Stated as a complaint this is just venting. Stated as a property, it is useful — because the ceiling is computable in advance.

Given a tenant's actual sensor inventory, and given the explanations a class of alert typically generates, you can work out before deploying anything which verdicts are reachable and which are not. That produces a genuinely useful artefact: a per-alert-class statement of what this tenant's telemetry can and cannot conclude, handed over at the start rather than argued about after an incident.

It reframes the conversation from "your analysts keep asking questions" to "with these sensors, this alert class resolves to a question roughly this often — here is what adding identity telemetry would change." That is a procurement discussion with arithmetic in it instead of a blame discussion with impressions in it. It is also, incidentally, a far better sales conversation than insisting the product is good.

Where I am implicated

My own lab tenant is the thin customer in this story.

Two of seven evidence groups have produced zero findings across 769. There are zero interactive sign-in records in thirty days. The scenario the product was imagined around cannot be tested there at all. Every constraint described above, I have been running into for months — on my own environment, with nobody to blame for the licensing decision.

That is part of why I believe the argument rather than merely finding it convenient. It arrived as an explanation for why my own numbers would not go where I wanted them to, and only later as a description of a customer conversation.

The limits of the claim

Three, stated plainly, because a provocative argument with unstated caveats is just a slogan.

The thresholds are chosen, not fitted, so the specific figure where "cannot close" begins is a preference. The direction is structural — more independent sources permit more belief, always — but the exact cliff edge is a decision someone made, and on this system that someone was me.

The argument assumes sources are genuinely independent, and counting independent sources is much harder than counting agents or products. Two tools reading the same underlying table are one witness. A tenant that buys three products on top of one sensor family has not bought three sources.

And this is about confidence in a verdict, not about the value of the work. A thin-coverage investigation that ends in a well-posed question to the right person is a good outcome. The failure is not being unable to close automatically. The failure is closing anyway, on evidence that could not support it, because someone wanted a clean report more than they wanted a true one.

Who is writing this

I am Ivan Melekhin. Twenty-five years in cybersecurity, most of the last decade running security operations — building and operating distributed SOC and MSSP teams across Asia-Pacific, with a long detour through OT and maritime environments. This log is the build record for an autonomous SOC investigation agent I started in January 2026, written as the decisions happened rather than tidied up afterwards. I am on LinkedIn if you want to argue with any of it.