ThreatWatch Expansion and Analysis Guardrails
Adding sources was easy. Keeping automated analysis tied to evidence became the more important constraint.
ThreatWatch
I expanded the source set across vulnerability reporting, indicators, regional advisories, and specialist research. Content-based deduplication improved the briefing, but inconsistent availability kept reminding me that volume is not the same as coverage.
Analysis guardrails
Research into long-context model attacks and hallucination in threat analysis shaped an important product rule: automated classification and summarisation must remain advisory. Attribution, severity, and campaign relationships need visible supporting evidence.
I stopped treating source count as the goal and shifted towards analysis quality. A useful briefing should explain why an item matters, show where the claim came from, and remain honest when confidence is limited.