The Context Layer

Five Dimensions, Six Approaches

5
evaluation
dimensions
6
architectural
approaches
0
single substrates
strong on all five

Contextual triage is the part of investigation automation no vendor sells out of the box—the data model that answers “is this alert real for this tenant” in under a second. Every serious platform builds some context layer. They do not build the same one. This compares the architectural approaches on a single rubric and shows why no single substrate wins outright.

The Rubric: Five Dimensions

A bare entity store is a wiring diagram. What promotes a knowledge store into a usable context layer is five dimensions layered onto the facts. These are the columns every approach below is measured against.

DimensionThe question it answers
TemporalityWhen was this fact true, and for how long? (maintenance windows, employee tenure, session validity)
ProvenanceWhere did this fact come from? (authoritative CMDB vs user-asserted — weight accordingly)
SemanticsWhat does this relationship mean? (“owned-by,” “administered-by,” “classified-as finance” — not bare host→person)
GovernanceIs policy encoded as a constraint? (“no >1 GB download from finance” surfaces as a fact, not a buried log line)
Decision traceIs the reasoning behind each closed case captured? (why benign, which SOP diverged — today it evaporates at ticket-close)

Rating key: Strong the architecture is built for it • Partial achievable but bolted on or implementation-dependent • Weak not what this shape is for.

The Comparison

Ratings describe the architecture, not any one product. Named exemplars implement variants—treat them as the family, not a scorecard of the vendor.

Approach Temporality Provenance Semantics Governance Decision trace
Vector context-memorye.g. Dropzone Context Memory, Block BIT, Palo Alto AgentiX Weak Weak Partial Weak Strong
Entity / attack-path graphe.g. Microsoft Sentinel entity graph, Vectra Partial Partial Strong Weak Weak
Security data lake + signalse.g. Panther/Iceberg, Snowflake or BigQuery security lake Strong Partial Partial Partial Weak
Bespoke ML + agent-on-anomalye.g. Alpha Level Strong Weak Weak Partial Partial
Context graph (full)e.g. Torq context graph Strong Strong Strong Strong Strong*
Hybrid (graph spine + lake/vector + baselines)the production composite Strong Strong Strong Strong Strong

* The full context graph scores Strong on decision trace only if reasoning is captured, not auto-learned into verdicts — see the caveat below.

The Approaches

Vector context-memory

e.g. Dropzone Context Memory (30-day org learning), Block Binary Intelligent Triage (vector DB, reported 99.9% triage efficacy), Palo Alto AgentiX (dynamic context re-synthesis)

Past investigations are embedded and retrieved by similarity. The strength is decision trace: feed in closed case reports and the reasoning becomes reusable context. The weaknesses are structural—embeddings flatten time (a recency window is not a validity window), erase provenance (similarity can’t tell an authoritative fact from an asserted one), and carry meaning only latently in the text, never explicitly on a relationship. Governance lives outside the store entirely.

Entity / attack-path graph

e.g. Microsoft Sentinel entity graph, Vectra — typically capped around ~100 nodes before the view stops being useful

Nodes are entities, edges are relationships: blast radius, lateral movement, identity→device→asset chains. Semantics is the whole point and scores well. But these graphs are often point-in-time snapshots (temporality partial), leave edges unweighted by source (provenance partial), don’t encode policy as constraints (governance weak), and show structure without recording why a case closed (decision trace weak).

Security data lake + signals layer

e.g. a queryable lake (Iceberg / Snowflake / BigQuery) plus a labelled <1% “signals” layer and behavioural baselines — the Naglieri/Panther model

The dominant practitioner answer for agentic triage, and the strongest on temporality: retention plus baselines are inherently time-aware. Normalized schemas can carry source fields (provenance partial, schema-discipline-dependent), but relationships are resolved at join time rather than held as first-class facts (semantics partial), policy lives in detection rules not in the data model (governance partial), and the lake stores events, not analyst reasoning (decision trace weak) unless a separate case store is added.

Bespoke ML + agent-on-anomaly

e.g. Alpha Level — bespoke models score anomalies, a context filter drops benign-but-rare, only the hot slice reaches an agent

UEBA-style models are temporal by construction (temporality strong) and the context filter encodes some environment policy (governance partial). But the model emits a score, not a sourced fact (provenance weak) and not a relationship meaning (semantics weak); the agent layer can emit reasoning if it’s designed to (decision trace partial).

Context graph (full)

e.g. Torq context graph — the source of this five-dimension rubric

An entity graph with all five dimensions layered onto the edges: validity windows (temporality), source weighting (provenance), typed meaning (semantics), policy-as-constraint (governance), and captured reasoning (decision trace). On paper it passes everything—which is exactly why it is the destination. The caveat is real: a graph that auto-learns its own verdicts from past cases quietly automates anchoring bias. Capture the reasoning; do not let the substrate drift toward its own past conclusions.

Hybrid — the production composite

graph spine for relationships, lake/vector store for recall, baselines for anomaly

No single substrate is strong on all five. Forcing one shape to do all the work is the most common architectural mistake. Production pairs a context graph (relationships, provenance, governance) with a lake/vector store (temporal recall and decision-trace memory) and behavioural baselines (anomaly). The graph answers “what is connected”; the baseline answers “is this normal”; the store answers “have we seen this before, and what did we decide.”

What the Matrix Says

Read down the columns and the picture is clear: every approach has a column it owns and columns it cannot serve. Vector memory owns decision trace; the graph owns semantics; the lake owns temporality; bespoke ML owns anomaly. None of them—alone—answers all five.

The conclusion is hybrid, not a winner. The right question is not “graph or lake?” but “which substrate carries which dimension?” A context graph is the natural spine for relationships, provenance, and governance; a lake or vector store is the natural memory for temporality and decision trace; baselines carry anomaly. Picking one shape for everything forces the model to compensate with expensive guesswork—and produces a system that demos well and fails at 3 AM.

The five-dimension rubric is drawn from David Melamed’s context-graph framing (Torq AI SOC webinar, 2026). The ratings here are an architectural assessment of each approach—not a certified scorecard of any named product; vendors implement variants and move quickly.

Capability
Investigation Automation
The parent framework: context assembly over playbook execution, the three-layer build-vs-buy model, and why the context layer (Layer 2) is where the intellectual property lives.
Read capability →