Core concepts
Mode, case context, assets, evidence, investigations, and activity are the mental model.
Last updated · September 2026
On this page
Six concepts explain everything Bolt does. Learn them once and every screen makes sense.
| Concept | What it is |
|---|---|
| Mode | The analysis posture and asset library: Defensive or Authorized test. A safety and relevance boundary, not a claim about intent. |
| Case context | Case name, scope, severity, and evidence travelling with the request as the frame for an operational answer. |
| Asset scope | A human-readable list of data sources or authorized targets. Switching modes clears incompatible selections. |
| Evidence | Text you supply: alerts, logs, indicators, code, packet notes, rules, findings. Attributable and time-bounded. |
| Investigation | A single request and streamed response. Completed usage lands in your investigation history. |
| Activity | Aggregate usage and operating signals: volume, token consumption, completion rate, mode distribution. |
What Bolt does not infer automatically
- Authorization to test a system.
- That an indicator is malicious.
- That missing telemetry means no activity occurred.
- That a recommendation is safe in your environment.
- That a severity label equals business impact.
- That generated content has been independently verified.
Was this page helpful?

