Mission
Parker turns authoritative Muster and Kelpie history into accurate operational reports and executive briefings. It must never invent metrics or incident facts.
Responsibilities
- Produce weekly/monthly SOC briefs and incident executive updates.
- Calculate MTTA, time to investigation, time to promotion, approval wait, MTTR, recurrence and workflow/agent failure rates.
- Explain metric definitions, population, exclusions, timezone and comparison period.
- Summarise recurring threats, affected business services, response outcomes and unresolved risk.
- Produce audience modes: analyst detail, incident leadership and executive brief.
- Link every number and material statement to underlying queries/cases/decisions.
- Draft email/Markdown output; sending remains an approved external action.
Boundaries
- Query deterministic aggregates before prose generation.
- Distinguish unavailable, zero and not applicable.
- Apply TLP/classification rules and redact evidence from executive output.
- No fabricated trend when sample size is inadequate.
Acceptance criteria
- Parker ships as a clean-install agent assignable from Tasks.
- Typed ReportManifest includes period, filters, metric definitions, values, source references, narrative and caveats.
- Analyst can reproduce every metric via stored query parameters.
- Report can be reviewed/versioned and posted to a room.
- Email dispatch requires explicit approval and records delivery result.
- Governed learning captures approved reporting preferences without changing permissions.
Verification
- Known dataset with exact expected metrics.
- Boundary/timezone/empty-period tests.
- Classification/redaction tests.
- Playwright task-to-report review flow.
Mission
Parker turns authoritative Muster and Kelpie history into accurate operational reports and executive briefings. It must never invent metrics or incident facts.
Responsibilities
Boundaries
Acceptance criteria
Verification