Overview
Hearth saves every answer that Hestia produces as an artifact. An artifact is a structured, re-openable record of the request and the result. An investigation write-up, a hunt query, a detection rule, a dashboard, a timeline, and an OSINT profile are all artifacts.
Artifacts appear in the Artifacts index. On this page, you can filter artifacts, reopen them, move them through a triage workflow, export them, discuss them with Hestia, and delete the ones that you no longer need.
About artifacts and conversations
A conversation is the exchange that you have with Hestia. An artifact is the durable deliverable that a run produces. Conversations appear on the Conversations page, and artifacts appear on the Artifacts page. Many artifacts come from a conversation and link back to that conversation.
When a run finishes, Hearth saves the result as an artifact and scopes it to your workspace. Each artifact has a kind, and the kind determines how Hearth renders the artifact. An investigation reads as an analyst write-up, a dashboard reads as pinned widgets, and a hunt query reads as runnable query text.
Hearth produces the following kinds of artifacts:
- investigation and investigation digest
- hunt query and detection
- dashboard, timeline, and entity graph
- coverage scorecard and compliance report
- tabletop scenario and runbook
- OSINT profile and storyline
- data table, posture drift, automation summary, and behavior alert
The audit record
Investigations, hunt queries, dashboards, timelines, entity graphs and coverage scorecards carry an audit record. The audit record shows the information that Hestia consulted to build the artifact: the tools that Hestia used and a sample of what each one returned. Other kinds of artifacts, and runs where Hestia used no tools, have no audit record.
The body of an artifact doesn't change after the run. The exception is dashboards: refreshing updates widget data, and the Dashboards page lets you remove or tune widgets. Hearth tracks your triage state separately, so that a status change never rewrites the output of the agent.
Elements of the Artifacts index
The following table describes the elements of the Artifacts index:
| Element | Description |
|---|---|
| Type chips | Filter the list by artifact kind. Hearth displays a chip for every kind that the list contains. |
| Source chips | Filter the list by origin. From a conversation contains the artifacts that a conversation produced. Standalone contains the artifacts that a schedule or a briefing produced. |
| Date groups | Group the list into Today, This week, and Older. |
| Artifact row | Opens the artifact in the detail panel when you click it. |
| Row ⋯ menu | Contains Delete. |
Elements of the artifact detail panel
The following table describes the elements of the detail panel:
| Element | Description |
|---|---|
| Triage status | Marks the artifact as Acknowledged, Dismissed, or Resolved. You can reopen the artifact later. Hearth removes dismissed and resolved artifacts from the "needs attention" surfaces by default, but it never deletes them. |
| Assignment | Assigns the artifact to a teammate. |
| Export report | Downloads the write-up and its conversation as HTML, Markdown, or JSON. A separate full-dataset CSV option routes through the Hearth export lane. |
| PDF and print | Opens a printable version of the artifact. |
| Discuss | Opens a chat thread that is attached to the artifact, where you can ask Hestia follow-up questions. |
| Digest | Consolidates the artifact and its discussion thread into a single investigation digest artifact. |
| Save as briefing | Converts the prompt behind the artifact into a reusable briefing that you can run on a schedule. |
| Data Hestia consulted | Displays the audit record for the artifact and lets you download the evidence. The downloads contain a sample of the data, up to 50 rows per step, not the full data. This section appears only on artifacts that have an audit record. |
Reviewing and acting on an artifact
To act on an artifact, do the following:
- Navigate to Artifacts.
- (Optional) Click the type and source chips to narrow the list, or scroll through the list grouped by timeframe.
- Click an artifact to open it.
- In the detail panel, set the status to [Acknowledged | Dismissed | Resolved].
- (Optional) Click Select a teammate then select a user to assign the artifact to.
- In the detail panel, do any of the following:
- Click Export report to produce a write-up that you can attach to a ticket or share.
- Click Discuss to ask Hestia a follow-up question.
- Click Save as briefing to run the same analysis again later.
- From an investigation, create a propose-only action plan for the items that need remediation.
To schedule an artifact to re-run as a scheduled briefing, create a new automation on the Automations page and select the artifact you saved as a briefing in Step 6 above.
Deleting an artifact
To delete an artifact that you no longer need:
- On the row of the artifact, click the ⋯ menu. You can also delete the artifact from the detail panel.
- Click Delete.
- (Optional) If the artifact has connected action plans, confirm whether Hearth deletes those plans as well.
Troubleshooting common issues
| Issue | What to do |
|---|---|
| The index displays the message "Nothing produced for this tenant yet." | The workspace contains no artifacts. Ask Hestia a question, and the first artifact appears here. |
| You cannot delete an artifact | Only the creator of the artifact or a role with the Delete artifacts permission (administrator or owner) can delete it. Ask an administrator to delete the artifact. Any member can delete a legacy artifact that has no recorded creator. |
| A message about connected plans blocks the deletion | The artifact has action plans that Hearth built from it. Confirm the cascade to delete the plans together, or delete each plan first. |
| The Save as briefing button has no effect | The artifact has no saved prompt to convert into a briefing. Some scheduled artifacts and system-produced artifacts do not carry a prompt. |
| The raw queries do not appear in Data Hestia consulted | Hearth displays a plain-English summary of each step to customer users, and the warehouse queries to Blumira staff. This behavior is expected, and Hearth retains the full record. |
| Data Hestia consulted doesn't appear | The artifact has no audit record. Only investigations, hunt queries, dashboards, timelines, entity graphs and coverage scorecards have one, and only when Hestia used tools to build them. |