Quick Links

Using Artifacts in Hearth

Overview

Hearth saves every answer that Hestia produces as an artifact. An artifact is a structured, re-openable record of the request and the result. An investigation write-up, a hunt query, a detection rule, a dashboard, a timeline, and an OSINT profile are all artifacts.

Artifacts appear in the Artifacts index. On this page, you can filter artifacts, reopen them, move them through a triage workflow, export them, discuss them with Hestia, and delete the ones that you no longer need.

About artifacts and conversations

A conversation is the exchange that you have with Hestia. An artifact is the durable deliverable that a run produces. Conversations appear on the Conversations page, and artifacts appear on the Artifacts page. Many artifacts come from a conversation and link back to that conversation.

When a run finishes, Hearth saves the result as an artifact and scopes it to your workspace. Each artifact has a kind, and the kind determines how Hearth renders the artifact. An investigation reads as an analyst write-up, a dashboard reads as pinned widgets, and a hunt query reads as runnable query text.

Hearth produces the following kinds of artifacts:

  • investigation and investigation digest
  • hunt query and detection
  • dashboard, timeline, and entity graph
  • coverage scorecard and compliance report
  • tabletop scenario and runbook
  • OSINT profile and storyline
  • data table, posture drift, automation summary, and behavior alert

The audit record

Investigations, hunt queries, dashboards, timelines, entity graphs and coverage scorecards carry an audit record. The audit record shows the information that Hestia consulted to build the artifact: the tools that Hestia used and a sample of what each one returned. Other kinds of artifacts, and runs where Hestia used no tools, have no audit record.

The body of an artifact doesn't change after the run. The exception is dashboards: refreshing updates widget data, and the Dashboards page lets you remove or tune widgets. Hearth tracks your triage state separately, so that a status change never rewrites the output of the agent.

Elements of the Artifacts index

The following table describes the elements of the Artifacts index:

ElementDescription
Type chipsFilter the list by artifact kind. Hearth displays a chip for every kind that the list contains.
Source chipsFilter the list by origin. From a conversation contains the artifacts that a conversation produced. Standalone contains the artifacts that a schedule or a briefing produced.
Date groupsGroup the list into Today, This week, and Older.
Artifact rowOpens the artifact in the detail panel when you click it.
Row ⋯ menuContains Delete.

Elements of the artifact detail panel

The following table describes the elements of the detail panel:

ElementDescription
Triage statusMarks the artifact as Acknowledged, Dismissed, or Resolved. You can reopen the artifact later. Hearth removes dismissed and resolved artifacts from the "needs attention" surfaces by default, but it never deletes them.
AssignmentAssigns the artifact to a teammate.
Export reportDownloads the write-up and its conversation as HTML, Markdown, or JSON. A separate full-dataset CSV option routes through the Hearth export lane.
PDF and printOpens a printable version of the artifact.
DiscussOpens a chat thread that is attached to the artifact, where you can ask Hestia follow-up questions.
DigestConsolidates the artifact and its discussion thread into a single investigation digest artifact.
Save as briefingConverts the prompt behind the artifact into a reusable briefing that you can run on a schedule.
Data Hestia consultedDisplays the audit record for the artifact and lets you download the evidence. The downloads contain a sample of the data, up to 50 rows per step, not the full data. This section appears only on artifacts that have an audit record.

Reviewing and acting on an artifact

To act on an artifact, do the following:

  1. Navigate to Artifacts.
  2. (Optional) Click the type and source chips to narrow the list, or scroll through the list grouped by timeframe.
  3. Click an artifact to open it.
  4. In the detail panel, set the status to [Acknowledged | Dismissed | Resolved].
  5. (Optional) Click Select a teammate then select a user to assign the artifact to.
  6. In the detail panel, do any of the following:
    • Click Export report to produce a write-up that you can attach to a ticket or share.
    • Click Discuss to ask Hestia a follow-up question.
    • Click Save as briefing to run the same analysis again later.
    • From an investigation, create a propose-only action plan for the items that need remediation.

To schedule an artifact to re-run as a scheduled briefing, create a new automation on the Automations page and select the artifact you saved as a briefing in Step 6 above.

Deleting an artifact

To delete an artifact that you no longer need:

  1. On the row of the artifact, click the ⋯ menu. You can also delete the artifact from the detail panel.
  2. Click Delete.
  3. (Optional) If the artifact has connected action plans, confirm whether Hearth deletes those plans as well.

Troubleshooting common issues

IssueWhat to do
The index displays the message "Nothing produced for this tenant yet."The workspace contains no artifacts. Ask Hestia a question, and the first artifact appears here.
You cannot delete an artifactOnly the creator of the artifact or a role with the Delete artifacts permission (administrator or owner) can delete it. Ask an administrator to delete the artifact. Any member can delete a legacy artifact that has no recorded creator.
A message about connected plans blocks the deletionThe artifact has action plans that Hearth built from it. Confirm the cascade to delete the plans together, or delete each plan first.
The Save as briefing button has no effectThe artifact has no saved prompt to convert into a briefing. Some scheduled artifacts and system-produced artifacts do not carry a prompt.
The raw queries do not appear in Data Hestia consultedHearth displays a plain-English summary of each step to customer users, and the warehouse queries to Blumira staff. This behavior is expected, and Hearth retains the full record.
Data Hestia consulted doesn't appearThe artifact has no audit record. Only investigations, hunt queries, dashboards, timelines, entity graphs and coverage scorecards have one, and only when Hestia used tools to build them.