Decision Primitives

Decision Primitives

Live catalog of the operators Signal Fabric uses to turn firehose evidence into governed Signal Decisions and Agent Task Packet candidates. This list refreshes from the runtime registry — newly promoted primitives appear automatically.

Primitives do not invent evidence. They operate only on observed Signal Fabric firehose rows, normalized fields, timestamps, provenance, and configured thresholds.

Total primitives
35
Static
31
Promoted
0
Runtime bindings
1,619

Source: https://examples.signal-fabric.com/api/predictive-ops/api/decision-primitives · Generated 2026-08-24T03:49:07.003Z

Catalog

Primitive library

Group by
Source

Eligible Packet Candidate

32 primitives
ot_public_exposure

OT/ICS Public Exposure

staticproductionruntime_available

Detects private OT/ICS or industrial protocol endpoints communicating with public IP space.

Runtime executor
sfOtPublicExposurePacketCandidates
Packet task type
investigate_ot_public_exposure
Dispatch behavior
eligible_packet_candidate
Runtime bindings
24 firehoses

Semantic capabilities

  • network_boundary_exposure
  • ot_protocol_context
  • public_private_ip_classification
  • network_relationship_context

Evidence roles

  • network_relationship_evidence
  • application_protocol_context
  • asset_exposure_evidence
asset_proximity_risk

Asset / Weather / Disaster Proximity

staticproductionruntime_available

Correlates customer reference assets or locations with nearby weather, disaster, seismic, water, wildfire, climate, emergency, or other geo-coded operational events.

Runtime executor
sfAssetProximityRiskPacketCandidates
Packet task type
investigate_asset_proximity_risk
Dispatch behavior
eligible_packet_candidate
Runtime bindings
115 firehoses

Semantic capabilities

  • geo_proximity_context
  • customer_reference_context
  • environmental_hazard_context
  • asset_location_context

Evidence roles

  • customer_asset_context
  • external_event_context
  • geo_proximity_evidence
boundary_exposure_repeated

Repeated Boundary Exposure

staticproductionruntime_available

Detects repeated relationships crossing private/public network boundaries, including repeated exposure of the same private asset.

Runtime executor
sfUniversalSemanticPacketCandidates
Packet task type
investigate_boundary_exposure
Dispatch behavior
eligible_packet_candidate
Runtime bindings
32 firehoses

Semantic capabilities

  • relationship_recurrence
  • boundary_exposure_context
  • asset_exposure_ranking
  • public_private_ip_classification

Evidence roles

  • relationship_evidence
  • boundary_classification
  • recurrence_context
rare_relationship_observed

Rare Or First-Seen Relationship

staticproductionruntime_available

Detects low-occurrence or first-seen relationships suitable for novelty, emergence, and route discovery workflows.

Runtime executor
sfUniversalSemanticPacketCandidates
Packet task type
investigate_rare_relationship
Dispatch behavior
eligible_packet_candidate
Runtime bindings
37 firehoses

Semantic capabilities

  • novelty_detection
  • relationship_rarity
  • route_emergence
  • first_seen_context

Evidence roles

  • relationship_evidence
  • rarity_context
first_seen_relationship_operator

First-Seen Relationship Operator

staticproductionruntime_available

Detects the first observed relationship, route, counterparty, location, entity pairing, or categorical relationship in any typed event stream.

Runtime executor
sfUniversalSemanticPacketCandidates
Packet task type
investigate_first_seen_relationship
Dispatch behavior
eligible_packet_candidate
Runtime bindings
22 firehoses

Semantic capabilities

  • first_seen_context
  • relationship_rarity
  • route_emergence
  • novelty_detection

Evidence roles

  • relationship_evidence
  • first_seen_context
  • rarity_context
numeric_delta_movement_operator

Numeric Delta / Movement Operator

staticproductionruntime_available

Computes movement, delta, rate, or threshold crossing over a numeric measure in a typed event stream.

Runtime executor
sfUniversalSemanticPacketCandidates
Packet task type
investigate_numeric_delta_movement
Dispatch behavior
eligible_packet_candidate
Runtime bindings
88 firehoses

Semantic capabilities

  • network_movement_context
  • numeric_movement
  • delta_movement
  • threshold_crossing
  • rate_of_change

Evidence roles

  • numeric_measurement_context
  • movement_evidence
  • threshold_context
forecast_curve_material_shift

Forecast Curve Material Shift

staticproductionruntime_available

Detects a material change in a forecast curve horizon or tenor, expressed in basis points, and emits a governed packet candidate when the configured threshold is crossed.

Runtime executor
sfForecastCurveMaterialShiftPacketCandidates
Packet task type
investigate_forecast_curve_shift
Dispatch behavior
eligible_packet_candidate
Runtime bindings
23 firehoses

Semantic capabilities

  • forecast_curve_context
  • prediction_context
  • delta_movement
  • threshold_crossing
  • rate_forecast_validation_context

Evidence roles

  • forecast_curve_context
  • prediction_state_context
  • threshold_context
  • rate_forecast_validation_context
recurrence_dedupe_window_operator

Recurrence / Dedupe Window Operator

staticproductionruntime_available

Detects repeated occurrences of a signal inside a bounded time window and emits a stable dedupe key for governed decisions.

Runtime executor
sfUniversalSemanticPacketCandidates
Packet task type
investigate_recurring_signal
Dispatch behavior
eligible_packet_candidate
Runtime bindings
64 firehoses

Semantic capabilities

  • relationship_recurrence
  • dedupe_context
  • signal_repetition
  • bounded_window_state

Evidence roles

  • recurrence_context
  • dedupe_context
  • signal_object_context
fanout_expansion_operator

Fan-Out / Expansion Operator

staticproductionruntime_available

Detects one entity expanding across many counterparties, resources, ports, facilities, regions, prefixes, or other distinct targets.

Runtime executor
sfUniversalSemanticPacketCandidates
Packet task type
investigate_fanout_expansion
Dispatch behavior
eligible_packet_candidate
Runtime bindings
51 firehoses

Semantic capabilities

  • fanout_expansion
  • distinct_counterparty_count
  • cluster_context
  • entity_ranking

Evidence roles

  • cluster_context
  • relationship_evidence
  • entity_ranking_context
sequence_correlation_operator

Ordered / Unordered Sequence Correlation Operator

staticproductionruntime_available

Correlates ordered or unordered event steps for the same entity, region, route, or asset inside a bounded time window.

Runtime executor
sfUniversalSemanticPacketCandidates
Packet task type
investigate_sequence_correlation
Dispatch behavior
eligible_packet_candidate
Runtime bindings
83 firehoses

Semantic capabilities

  • sequence_correlation
  • time_window_correlation
  • multi_signal_correlation
  • entity_context

Evidence roles

  • time_window_correlation
  • sequence_context
  • entity_context
threat_observable_extraction_operator

Threat Observable Extraction Operator

staticproductionruntime_available

Extracts security observables such as source IP, destination IP, domain, JA4, JA4T, TLS fingerprint, or other fingerprints from event streams without claiming a registry or threat-intel match.

Runtime executor
sfUniversalSemanticPacketCandidates
Packet task type
investigate_threat_observable
Dispatch behavior
eligible_packet_candidate
Runtime bindings
10 firehoses

Semantic capabilities

  • threat_observable_context
  • indicator_context
  • network_observable_context
  • fingerprint_context

Evidence roles

  • observable_context
  • indicator_context
  • entity_context
registry_indicator_match_operator

Registry / Indicator Match Operator

staticproductionruntime_available

Matches event values against an external registry, reference dataset, threat list, asset list, watchlist, or domain-specific catalog with provenance and confidence.

Runtime executor
sfUniversalSemanticPacketCandidates
Packet task type
investigate_registry_indicator_match
Dispatch behavior
eligible_packet_candidate
Runtime bindings
2 firehoses

Semantic capabilities

  • registry_match
  • reference_dataset_match
  • indicator_context
  • provenance_context

Evidence roles

  • reference_context
  • indicator_context
  • provenance_context
spatial_proximity_operator

Spatial Proximity Operator

staticproductionruntime_available

Correlates entities, assets, facilities, regions, or observations by distance, radius, containment, or shared geographic context.

Runtime executor
sfUniversalSemanticPacketCandidates
Packet task type
investigate_spatial_proximity
Dispatch behavior
eligible_packet_candidate
Runtime bindings
66 firehoses

Semantic capabilities

  • spatial_proximity
  • geo_proximity_context
  • asset_location_context
  • regional_correlation

Evidence roles

  • geo_proximity_evidence
  • location_context
  • asset_location_context
psps_threshold_decision_operator

PSPS Threshold Decision Operator

staticproductionruntime_available

Evaluates public-safety power shutoff risk from fire-weather observations, red-flag warnings, sustained wind, wind gust, relative humidity, temperature, wildfire proximity, and bounded regional context.

Runtime executor
sfUniversalSemanticPacketCandidates
Packet task type
investigate_psps_threshold_decision
Dispatch behavior
eligible_packet_candidate
Runtime bindings
69 firehoses

Semantic capabilities

  • psps_threshold_decision
  • fire_weather_surface_observation
  • weather_hazard_context
  • wildfire_context
  • threshold_crossing
  • multi_signal_correlation

Evidence roles

  • fire_weather_context
  • weather_hazard_context
  • wildfire_context
  • threshold_context
  • regional_operational_risk_context
baseline_deviation_operator

Baseline Deviation Operator

staticproductionruntime_available

Detects a numeric, categorical, or count signal departing from historical, rolling, seasonal, peer, or configured baseline expectations.

Runtime executor
sfUniversalSemanticPacketCandidates
Packet task type
investigate_baseline_deviation
Dispatch behavior
eligible_packet_candidate
Runtime bindings
87 firehoses

Semantic capabilities

  • baseline_deviation
  • anomaly_context
  • threshold_crossing
  • rate_of_change

Evidence roles

  • baseline_context
  • numeric_measurement_context
  • threshold_context
lead_lag_correlation_operator

Lead / Lag Correlation Operator

staticproductionruntime_available

Detects when one signal leads, follows, predicts, or reacts to another signal across a defined lag window and shared entity, region, asset, or relationship key.

Runtime executor
sfUniversalSemanticPacketCandidates
Packet task type
investigate_lead_lag_correlation
Dispatch behavior
eligible_packet_candidate
Runtime bindings
89 firehoses

Semantic capabilities

  • lead_lag_correlation
  • time_window_correlation
  • multi_signal_correlation
  • prediction_context

Evidence roles

  • time_window_correlation
  • multi_signal_context
  • prediction_context
multi_source_confirmation_operator

Multi-Source Confirmation Operator

staticproductionruntime_available

Requires two or more independent firehoses, sources, providers, or evidence classes to confirm the same entity, region, event, or risk condition.

Runtime executor
sfUniversalSemanticPacketCandidates
Packet task type
investigate_multi_source_confirmation
Dispatch behavior
eligible_packet_candidate
Runtime bindings
85 firehoses

Semantic capabilities

  • multi_source_confirmation
  • source_agreement
  • evidence_fusion
  • provenance_context

Evidence roles

  • source_confirmation_context
  • provenance_context
  • multi_signal_context
source_disagreement_operator

Source Disagreement Operator

staticproductionruntime_available

Detects when two or more sources disagree, diverge, conflict, or materially differ for the same entity, region, measurement, or assertion.

Runtime executor
sfUniversalSemanticPacketCandidates
Packet task type
investigate_source_disagreement
Dispatch behavior
eligible_packet_candidate
Runtime bindings
55 firehoses

Semantic capabilities

  • source_disagreement
  • evidence_conflict
  • provenance_context
  • quality_control_context

Evidence roles

  • source_disagreement_context
  • provenance_context
  • quality_control_context
confidence_weighted_evidence_fusion_operator

Confidence-Weighted Evidence Fusion Operator

staticproductionruntime_available

Combines multiple pieces of evidence using confidence, severity, provenance, recency, and source weighting to produce a ranked decision strength.

Runtime executor
sfUniversalSemanticPacketCandidates
Packet task type
investigate_confidence_weighted_evidence
Dispatch behavior
eligible_packet_candidate
Runtime bindings
53 firehoses

Semantic capabilities

  • confidence_weighted_evidence_fusion
  • confidence_context
  • severity_context
  • provenance_context
  • decision_strength

Evidence roles

  • confidence_context
  • severity_context
  • provenance_context
  • decision_strength_context
suppression_allowlist_operator

Suppression / Allowlist Operator

staticproductionruntime_available

Applies governed suppressions, allowlists, known-benign references, maintenance windows, or policy exclusions before automation dispatch.

Runtime executor
sfUniversalSemanticPacketCandidates
Packet task type
apply_suppression_allowlist
Dispatch behavior
eligible_packet_candidate
Runtime bindings
69 firehoses

Semantic capabilities

  • suppression_context
  • allowlist_context
  • governance_override
  • policy_exclusion

Evidence roles

  • suppression_context
  • governance_context
  • policy_context
severity_escalation_operator

Severity Escalation Operator

staticproductionruntime_available

Detects worsening severity, score, confidence, risk level, or impact class over time and projects when escalation should occur.

Runtime executor
sfUniversalSemanticPacketCandidates
Packet task type
investigate_severity_escalation
Dispatch behavior
eligible_packet_candidate
Runtime bindings
58 firehoses

Semantic capabilities

  • severity_escalation
  • risk_level_change
  • score_trend
  • impact_worsening

Evidence roles

  • severity_context
  • score_context
  • escalation_context
entity_cluster_ranking_operator

Entity Cluster Ranking Operator

staticproductionruntime_available

Ranks top entities, regions, assets, routes, principals, prefixes, or counterparties by count, score, movement, exposure, severity, or grouped evidence strength.

Runtime executor
sfUniversalSemanticPacketCandidates
Packet task type
investigate_entity_cluster_ranking
Dispatch behavior
eligible_packet_candidate
Runtime bindings
72 firehoses

Semantic capabilities

  • entity_cluster_ranking
  • top_n_ranking
  • cluster_context
  • entity_aggregation

Evidence roles

  • entity_ranking_context
  • cluster_context
  • aggregation_context
lateral_escalation_pressure

Lateral Escalation Pressure

staticproductionruntime_available

Ranks internal entities by investigator escalation pressure using escalation outcomes, severity, recurrence, and detection volume.

Runtime executor
sfUniversalSemanticPacketCandidates
Packet task type
investigate_lateral_escalation_pressure
Dispatch behavior
eligible_packet_candidate
Runtime bindings
5 firehoses

Semantic capabilities

  • cyber_network_detection_response
  • investigator_outcome_context
  • severity_escalation
  • entity_ranking

Evidence roles

  • investigator_outcome_context
  • detection_context
  • escalation_context
investigator_detection_cluster

Investigator Detection Cluster

staticproductionruntime_available

Groups investigator detections by internal entity, route, category, or risk type and ranks the strongest clusters for charts and packet candidates.

Runtime executor
sfUniversalSemanticPacketCandidates
Packet task type
investigate_detection_cluster
Dispatch behavior
eligible_packet_candidate
Runtime bindings
5 firehoses

Semantic capabilities

  • cyber_network_detection_response
  • investigator_outcome_context
  • entity_cluster_ranking
  • detection_context

Evidence roles

  • investigator_outcome_context
  • detection_context
  • entity_ranking_context
missing_evidence_to_adapter_request_operator

Missing Evidence To Adapter Request Operator

staticproductionruntime_available

Turns an unsatisfied capability or missing source into a governed adapter/source-integration request with provenance, field contract, and readiness state.

Runtime executor
sfRecordPrimitiveGap
Packet task type
prepare_adapter_request
Dispatch behavior
eligible_packet_candidate
Runtime bindings
0 firehoses

Semantic capabilities

  • missing_evidence_detection
  • adapter_request_context
  • firehose_acquisition_context
  • governance_context

Evidence roles

  • missing_evidence_context
  • adapter_request_context
  • governance_context
attribute_drift_observed

Entity Attribute Drift

staticproductionruntime_available

Detects an entity or relationship changing important contextual attributes such as protocol, category, severity, family, or event type.

Runtime executor
sfUniversalSemanticPacketCandidates
Packet task type
investigate_attribute_drift
Dispatch behavior
eligible_packet_candidate
Runtime bindings
37 firehoses

Semantic capabilities

  • entity_attribute_change
  • protocol_drift
  • category_drift
  • contextual_identity_change

Evidence roles

  • entity_context
  • attribute_history
  • drift_context
portfolio_operating_threshold_packet

Portfolio Operating Threshold Packet

staticproductionruntime_available

Detects investor-relevant company operating thresholds such as runway compression, ARR deceleration, churn pressure, margin compression, outage pressure, or forecast slip.

Runtime executor
sfUniversalSemanticPacketCandidates
Packet task type
investigate_portfolio_operating_threshold
Dispatch behavior
eligible_packet_candidate
Runtime bindings
0 firehoses

Semantic capabilities

  • portfolio_company_context
  • financial_operating_context
  • sales_pipeline_context
  • customer_concentration_context
  • product_usage_context
  • threshold_crossing

Evidence roles

  • portfolio_company_context
  • financial_operating_context
  • sales_pipeline_context
  • customer_concentration_context
  • product_usage_context
portfolio_market_news_correlation

Portfolio Market News Correlation

staticproductionruntime_available

Correlates attributed market/news events with portfolio companies, sectors, competitors, funding rounds, regulatory events, pricing pressure, and sentiment.

Runtime executor
sfUniversalSemanticPacketCandidates
Packet task type
investigate_portfolio_market_news_correlation
Dispatch behavior
eligible_packet_candidate
Runtime bindings
0 firehoses

Semantic capabilities

  • private_market_event_context
  • technology_news_context
  • sector_news_context
  • market_sentiment_context
  • portfolio_company_context
  • multi_signal_correlation

Evidence roles

  • private_market_event_context
  • technology_news_context
  • portfolio_company_context
  • market_sentiment_context
portfolio_weekly_change_detection

Portfolio Weekly Change Detection

staticproductionruntime_available

Identifies material week-over-week portfolio changes for LP reporting, IC memo updates, operating partner follow-up, and investor review.

Runtime executor
sfUniversalSemanticPacketCandidates
Packet task type
prepare_portfolio_weekly_change_packet
Dispatch behavior
eligible_packet_candidate
Runtime bindings
0 firehoses

Semantic capabilities

  • portfolio_change_detection_context
  • weekly_change_context
  • investor_impact_context
  • lp_reporting_context
  • delta_movement

Evidence roles

  • portfolio_change_detection_context
  • investor_impact_context
  • lp_reporting_context
network_first_seen_route

Network First SEEN Route

staticpromotedruntime_available

Promoted Signal Fabric primitive contract for Network First SEEN Route.

Runtime executor
sfUniversalSemanticPacketCandidates
Packet task type
investigate_network_first_seen_route
Dispatch behavior
eligible_packet_candidate
Runtime bindings
26 firehoses

Semantic capabilities

  • network_observability_relationship
  • first_seen_context

Evidence roles

  • network_observability_relationship
  • first_seen_context
protocol_category_drift_after_first_seen_public_route

Protocol Category Drift After First SEEN Public Route

staticpromotedruntime_available

Promoted Signal Fabric primitive contract for Protocol Category Drift After First SEEN Public Route.

Runtime executor
sfUniversalSemanticPacketCandidates
Packet task type
investigate_protocol_category_drift_after_first_seen_public_route
Dispatch behavior
eligible_packet_candidate
Runtime bindings
24 firehoses

Semantic capabilities

  • relationship_recurrence
  • boundary_exposure_context
  • asset_exposure_ranking
  • public_private_ip_classification
  • novelty_detection
  • relationship_rarity
  • route_emergence
  • first_seen_context
  • network_observability_relationship
  • first_seen_context
  • protocol_drift
  • category_drift
  • relationship_recurrence
  • boundary_exposure_context
  • asset_exposure_ranking
  • public_private_ip_classification
  • novelty_detection
  • relationship_rarity
  • route_emergence

Evidence roles

  • network_observability_relationship
  • first_seen_context
  • protocol_drift
  • category_drift
  • relationship_recurrence
  • boundary_exposure_context
  • asset_exposure_ranking
  • public_private_ip_classification
  • novelty_detection
  • relationship_rarity
  • route_emergence
threat_ioc_network_correlation

Threat IOC Network Correlation

staticpromotedruntime_available

Promoted Signal Fabric primitive contract for Threat IOC Network Correlation.

Runtime executor
sfUniversalSemanticPacketCandidates
Packet task type
investigate_threat_ioc_network_correlation
Dispatch behavior
eligible_packet_candidate
Runtime bindings
12 firehoses

Semantic capabilities

  • cyber_ioc_indicator_context
  • cyber_network_detection_response
  • cyber_ioc_indicator_context
  • cyber_network_detection_response

Evidence roles

  • cyber_ioc_indicator_context
  • cyber_network_detection_response

Decision Lifecycle Only

3 primitives
prediction_deduped

Prediction Deduped

staticproductionruntime_available

Lifecycle decision emitted when Fabric recognizes an already-seen eligible detection or prediction inside the dedupe window.

Runtime executor
sfIntentEvaluateWatch
Packet task type
none
Dispatch behavior
decision_lifecycle_only
Runtime bindings
115 firehoses

Semantic capabilities

  • decision_lifecycle
  • dedupe_context

Evidence roles

  • dedupe_context
  • signal_object_context
agent_packet_created

Agent Task Packet Created

staticproductionruntime_available

Lifecycle event emitted when Fabric creates a governed Agent Task Packet from an eligible primitive candidate.

Runtime executor
sfIntentWatchMaybeCreatePacket
Packet task type
lifecycle
Dispatch behavior
decision_lifecycle_only
Runtime bindings
115 firehoses

Semantic capabilities

  • packet_lifecycle
  • governed_agent_task_packet

Evidence roles

  • packet_context
  • signal_object_context
public_private_direction_classification

Public Private Direction Classification

staticpromotedruntime_available

Promoted Signal Fabric primitive contract for Public Private Direction Classification.

Runtime executor
sfAtpNetworkRelationshipFromAny
Packet task type
investigate_public_private_direction_classification
Dispatch behavior
decision_lifecycle_only
Runtime bindings
26 firehoses

Semantic capabilities

  • network_observability_relationship

Evidence roles

  • network_observability_relationship

Lifecycle

Agent Task Packet lifecycle

  1. 01

    Firehose Evidence

  2. 02

    Primitive Evaluation

  3. 03

    Signal Decision

  4. 04

    Packet Candidate

  5. 05

    Draft Packet

  6. 06

    Agent Dispatch