This document explains how we work with you to connect a new detection source to Qevlar, what we'll need from your team at each stage, and what you can expect from us in return.
To follow along and track progress, your integration team will use the Connector Integration Workbook → [Link to workbook]
To make that connection reliable and predictable, we follow a structured four-phase process:
- Discovery & Requirements — understand your environment before touching any configuration
- Integration & Configuration — establish the live connection and load your environmental context
- Observation & QA — run a structured validation period and measure investigation quality
- Go-Live Gate & Approval — confirm all thresholds are met before moving to production
4 phases — typical duration 3–6 weeks
Phase 1* — Discovery & Requirements
*This phase applies to non-native connectors. If your product has a native Qevlar template, we move directly to Phase 2.
Before configuration, we must document your alert landscape. Your team provides the context; we document it in the project workbook.
Key Requirements
Product Details: Exact vendor, name, and version (crucial for API schema mapping). Define its role: a primary source (EDR/Email) or an aggregator (SIEM/SOAR).
Detection Catalog: A list of active rules, 30-day historical volumes (by severity), and known false-positive rates.
Note: Flag "noisy" rules early to exclude them from initial scope.
Custom Rules: Provide sample payloads to account for non-standard field names.
Connectivity & Access: Define the ingestion path (Direct API, Webhook, or SIEM/SOAR) and address IP allowlisting, firewalls, and rate limits.
Technical Owner: You must designate a lead to provide credentials and explain detection logic.
Goal: Establishing these technical guardrails prevents architectural rework and ensures high data fidelity during integration.
Phase 2 — Integration & Configuration
With discovery complete, we establish the live connection and configure the context that allows Qevlar to investigate alerts in your environment — not just process them generically.
To complete Integration, the following requirements must be met and documented in the workbook.
Key Requirements
Validated Connector: Establish a functional link using native templates or new connector;
Payload Alignment: Verify that live alert schemas match Phase 1 samples to prevent schema drift.
Latency Sync: Configure ingestion and latency for high volume if needed
Data Flow Confirmation: Success is gated by a live alert successfully appearing in the Qevlar queue.
Goal: Establishing a secure, live data connection and calibrate Qevlar AI with your environment’s specific context.
Phase 3 — Observation & QA
The Observation phase is a structured validation period — we recommend two weeks — during which we measure Qevlar's investigation quality against a pre-agreed benchmark before making any production decision.
Key Requirements
Validation Framework: Define start/end dates, performance benchmarks (e.g., triage time or AI-human alignment), and assign a named analyst reviewer for each alert category.
Independent Review: Analysts must peer-review Qevlar’s conclusions to build the Quality Scorecard used for final approval.
QA Tracker: Log all discrepancies in the project workbook, documenting the resolution and "before vs. after" verdicts for every re-run.
Note: The observation period may be extended to reach required alert volumes, but it cannot be shortened; statistical significance is required for the Go-Live Gate.
Goal: Conduct a structured validation period (typically two weeks) to measure Qevlar’s investigation quality against human benchmarks before production approval.
Phase 4 — Approval & Go-Live
You can find below an example of success metrics for Go-Live Approval. If a category does not meet the thresholds, it is not approved for production — it moves to a follow-up validation sprint. Partial go-live is a valid and common outcome.
Quality scorecard thresholds:
| Metric | Threshold |
|---|---|
| Investigation completion | 100% of in-scope alerts investigated |
| Time to investigation (p90) | Under 10 minutes across all alert types |
| Missed Critical true positives | Less than 1% — any miss is an immediate no-go |
| Not Harmful / low-risk alignment with SOC | 70% or higher |
| Inconclusive rate | Within agreed bounds per category |
| Analyst override rate | Within agreed bounds |
After go-live, we run a two-week hypercare period with daily check-ins. Any investigation quality issues that arise in the first two weeks are treated as integration findings and addressed by the Qevlar team — not your SOC team's responsibility to diagnose.
Going forward, we track weekly metrics against your Observation baseline: total alert volume, investigation completion rate, auto-close rate (if deployed), analyst override rate, and inconclusive rate.
Goal: The aim of this final step is to ensure we've hit our shared success targets, giving both teams the confidence that every alert category is performing at production-grade quality.
Your Integration Workbook
Every step above is tracked in the Connector Integration Workbook →[Link to workbook]
The workbook contains one tab per phase, each with the full list of items to complete, a space for your team's answers and notes, and a status field for each item. Your Qevlar TAM will guide you through it — but your team's input is what makes it useful. The more detail you provide, the smoother every phase that follows will be.
If you have any questions about the process or what to prepare, reach out to your Qevlar CSM at any time.