Precision Containment
Resource under threat
The partner resolves the technical surface — the machine, the port, the application. This surface answers the business half: which processes run through the threatened resource, what could be falsified, released or read if the suspicion is correct, what that is worth, and the graded ways to contain it. In an active crisis the decisive question is not "is this suspicious?" but "what is the blast radius if the suspicion is correct?"
Inbound threat signal
simulated feedA threat-intelligence partner lands two facts here: which resourcethe threat is against, and how likely the incident is. Everything below is this side's answer — what that resource can reach, what it would cost, and the graded ways to contain it.
The partner's probability that the threat is real. It scales True Risk and the recommended containment grade; it never changes the blast radius, which is a fact about access alone.
No resource named yet
Pick the resource the threat signal names. The surface then resolves the business processes it serves, what a corruption of it could falsify or release, the blast analysis, and the graded containment options — including what each one would stop.