Contextual triage is the part of investigation automation no vendor sells out of the box—the data model that answers “is this alert real for this tenant” in under a second. Every serious platform builds some context layer. They do not build the same one. This compares the architectural approaches on a single rubric and shows why no single substrate wins outright.
The Rubric: Five Dimensions
A bare entity store is a wiring diagram. What promotes a knowledge store into a usable context layer is five dimensions layered onto the facts. These are the columns every approach below is measured against.
| Dimension | The question it answers |
|---|---|
| Temporality | When was this fact true, and for how long? (maintenance windows, employee tenure, session validity) |
| Provenance | Where did this fact come from? (authoritative CMDB vs user-asserted — weight accordingly) |
| Semantics | What does this relationship mean? (“owned-by,” “administered-by,” “classified-as finance” — not bare host→person) |
| Governance | Is policy encoded as a constraint? (“no >1 GB download from finance” surfaces as a fact, not a buried log line) |
| Decision trace | Is the reasoning behind each closed case captured? (why benign, which SOP diverged — today it evaporates at ticket-close) |
Rating key: the architecture is built for it • achievable but bolted on or implementation-dependent • not what this shape is for.
The Comparison
Ratings describe the architecture, not any one product. Named exemplars implement variants—treat them as the family, not a scorecard of the vendor.
| Approach | Temporality | Provenance | Semantics | Governance | Decision trace |
|---|---|---|---|---|---|
| Vector context-memorye.g. Dropzone Context Memory, Block BIT, Palo Alto AgentiX | |||||
| Entity / attack-path graphe.g. Microsoft Sentinel entity graph, Vectra | |||||
| Security data lake + signalse.g. Panther/Iceberg, Snowflake or BigQuery security lake | |||||
| Bespoke ML + agent-on-anomalye.g. Alpha Level | |||||
| Context graph (full)e.g. Torq context graph | |||||
| Hybrid (graph spine + lake/vector + baselines)the production composite |
* The full context graph scores Strong on decision trace only if reasoning is captured, not auto-learned into verdicts — see the caveat below.
The Approaches
Vector context-memory
Past investigations are embedded and retrieved by similarity. The strength is decision trace: feed in closed case reports and the reasoning becomes reusable context. The weaknesses are structural—embeddings flatten time (a recency window is not a validity window), erase provenance (similarity can’t tell an authoritative fact from an asserted one), and carry meaning only latently in the text, never explicitly on a relationship. Governance lives outside the store entirely.
Entity / attack-path graph
Nodes are entities, edges are relationships: blast radius, lateral movement, identity→device→asset chains. Semantics is the whole point and scores well. But these graphs are often point-in-time snapshots (temporality partial), leave edges unweighted by source (provenance partial), don’t encode policy as constraints (governance weak), and show structure without recording why a case closed (decision trace weak).
Security data lake + signals layer
The dominant practitioner answer for agentic triage, and the strongest on temporality: retention plus baselines are inherently time-aware. Normalized schemas can carry source fields (provenance partial, schema-discipline-dependent), but relationships are resolved at join time rather than held as first-class facts (semantics partial), policy lives in detection rules not in the data model (governance partial), and the lake stores events, not analyst reasoning (decision trace weak) unless a separate case store is added.
Bespoke ML + agent-on-anomaly
UEBA-style models are temporal by construction (temporality strong) and the context filter encodes some environment policy (governance partial). But the model emits a score, not a sourced fact (provenance weak) and not a relationship meaning (semantics weak); the agent layer can emit reasoning if it’s designed to (decision trace partial).
Context graph (full)
An entity graph with all five dimensions layered onto the edges: validity windows (temporality), source weighting (provenance), typed meaning (semantics), policy-as-constraint (governance), and captured reasoning (decision trace). On paper it passes everything—which is exactly why it is the destination. The caveat is real: a graph that auto-learns its own verdicts from past cases quietly automates anchoring bias. Capture the reasoning; do not let the substrate drift toward its own past conclusions.
Hybrid — the production composite
No single substrate is strong on all five. Forcing one shape to do all the work is the most common architectural mistake. Production pairs a context graph (relationships, provenance, governance) with a lake/vector store (temporal recall and decision-trace memory) and behavioural baselines (anomaly). The graph answers “what is connected”; the baseline answers “is this normal”; the store answers “have we seen this before, and what did we decide.”
What the Matrix Says
Read down the columns and the picture is clear: every approach has a column it owns and columns it cannot serve. Vector memory owns decision trace; the graph owns semantics; the lake owns temporality; bespoke ML owns anomaly. None of them—alone—answers all five.
The five-dimension rubric is drawn from David Melamed’s context-graph framing (Torq AI SOC webinar, 2026). The ratings here are an architectural assessment of each approach—not a certified scorecard of any named product; vendors implement variants and move quickly.