Each string is one rule-based signal raised on one employee. Detection and Triage are fully automated and always shown; Evaluation is where an analyst decides false positive vs. true positive; Closure only unlocks after that decision, and its content depends on which way the case was decided.
Confirmed (can reach a definite True in this export): AWOL (0 Hours), Group Risk.
Candidate (the export can only ever partially confirm these): Fake Security Guard, Robbery w/ Internal
Informant.
Loonbeslag (Wage Garnishment) has no real data source in this export and is shown as "cannot evaluate" for nearly every employee (1,849 of 1,885) — that isn't a signal, it's an absence of data, so turning it into an individual case per employee would create noise rather than insight. It remains visible only as a caveat inside each employee's full profile.
Dennis Rule and Heist have partial month-level signal in the underlying data but aren't yet rolled up into a per-employee case in this export, so they are not shown as strings here. Vacation Rule, Employee Damage, Complaints, Duty Free Theft, Unauthorized Crossing, Favoritism, "Not to Work with Someone", and LMS/Identity Swap have no data source at all in this export.
There are two separate feedback signals in this console, shown in the counter top right. Marking a string "false positive" or "true positive" records the ground-truth outcome of the case — the mechanism by which Iveron's rule thresholds and anomaly baselines get retuned over time. The 👍/👎 buttons inside Evaluation and Closure are a separate, lighter-weight signal: they rate whether the automatically generated guidance text at that stage was accurate and useful, independent of how the case itself turned out — that's what would be used to improve the guidance-generation model itself. This preview does not persist either signal between sessions.
Full pipeline detail: analysis/README.md
and CLAUDE.md in the project repository.