> ## Documentation Index
> Fetch the complete documentation index at: https://docs.myrmex.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Enrichment

> Turn one alert — or a whole cluster of them — into an enriched investigation: choose the context, attach documents, add the assets in play, look indicators up in Google Threat Intelligence, then send it all to the chat.

**Enrichment** is the bridge between triage and response. Starting from one alert or several, you assemble everything the AI team needs to work — the context it belongs to, supporting documents, the devices and integrations involved, and threat intelligence on its indicators — and then hand the whole package to the chat in a single step.

## Where It Starts

Open **Case Management** from the [Directory](/documentation/ai-workspace/overview#the-directory) and go to the **Alert Management** tab. Choose a scope first — all integrations, an integration type, or one specific integration. Nothing is fetched until you choose, which avoids querying every integration at once.

<CardGroup cols={2}>
  <Card title="From one alert" icon="magnifying-glass">
    Use **Enrich** on the alert's own row.
  </Card>

  <Card title="From many alerts" icon="layer-group">
    Tick the checkboxes on a cluster. The selection bar at the bottom shows how
    many are selected and offers a single **Enrich** for all of them.
  </Card>
</CardGroup>

<Note>
  Each row also carries **Send to Chat**, which drops the alert straight into the
  conversation without the enrichment step. Use **Enrich** when you want to
  attach context first.
</Note>

## What You Assemble

**Enrich** opens an **Enrichment** panel. It isn't a sequence of steps — every section is on screen at once, already filled in where the platform can infer something, and yours to adjust before you send.

| Section | What it holds |
| - | - |
| **The selected alerts** | Each one expandable, with its provider, severity, risk score, status, host and timestamp. |
| **Context** | The organisation and [context](/documentation/getting-started/concepts#how-your-account-is-organized) the investigation belongs to. |
| **Documents** *(optional)* | Reference material from **SharePoint**, **Google Drive** or **Myrmex**. |
| **Environment** *(optional)* | The devices and integrations in play — pre-filled with the hosts named in the alerts, and searchable for more. |
| **Threat Intel** | Indicator lookups via **Google Threat Intelligence**. IOCs found in the alert data are surfaced automatically; you can also search an IP, domain, hash or URL yourself. |

<Tip>
  When the alerts carry no indicators, the panel says so plainly — *"No IOCs
  detected in this alert data"* — rather than leaving you guessing whether the
  lookup ran.
</Tip>

## Sending It to the Chat

The footer counts the assets you've attached and offers **Send to Chat**. From there the enriched alert runs like any other conversation: [Centurion](/documentation/ai-agents/centurion) coordinates the specialists — [Orion](/documentation/ai-agents/orion) to work the indicators, [Perseus](/documentation/ai-agents/perseus) to inspect or act on an affected host — and you watch the reasoning and tool calls stream in live.

<Card title="Centurion, in SOC mode" icon="shield-halved" href="/documentation/ai-agents/centurion">
  How the orchestrator runs a detection-and-response investigation end to end.
</Card>

<Note>
  Enrichment prepares and hands over; it doesn't act on your environment by
  itself. Any response — isolating a host, blocking an indicator — is proposed in
  chat for you to approve. See
  [AI proposes, you approve](/documentation/getting-started/concepts#ai-proposes-you-approve).
</Note>

## From Investigation to Record

Once the picture is clear, ask [Scribe](/documentation/ai-agents/scribe) to write the investigation up as a report you can share, or keep the conversation as your working record.
