elastic / elastic/docs-content
Docs fix — page openings: path /solutions/security/ai — 18 pages
- Dominant language
- No language data
- Stars
- 47
- Forks
- 261
- Avg merge
- 3d 12h
- Merged PRs (30d)
- 116
Description
Generated by `gh-aw-docs-openings-sweep` for `elastic/docs-content` on 2026-W25.
Path /solutions/security/ai · 18 total in scope · subtree corpus 18 pages.
## Findings (7)
```yaml
- file: solutions/security/ai/ease/ease-value-report.md
line: 16
category: vague-h1
severity: high
evidence: "H1 is '# Value report' — no product or feature context; could belong to any product"
suggested_fix: |
# {{elastic-sec}} value report [value-report]
- file: solutions/security/ai/triage-alerts.md
line: 14
category: vague-h1
severity: high
evidence: |
H1 is '# Triage alerts' — no feature context for a page specifically about
AI Assistant-assisted triage. A sibling page (ease/ease-alerts.md) uses
'# Triage alerts in EASE', making the disambiguation problem concrete.
suggested_fix: |
# Triage alerts with AI Assistant [triage-alerts-with-ai-assistant]
- file: solutions/security/ai/use-cases.md
line: 14
category: vague-h1
severity: high
evidence: |
H1 is '# AI use cases' — 'AI' is ambiguous across Agent Builder, AI
Assistant, Attack Discovery, and other features; page covers specifically
AI Assistant and Attack Discovery workflows.
suggested_fix: |
# AI Assistant and Attack Discovery use cases [security-ai-use-cases]
- file: solutions/security/ai/ease/ease-alerts.md
line: 11
category: weak-opening
severity: medium
evidence: |
Opening is one sentence: "Once you've ingested your alerts to Elastic AI
SOC Engine (EASE), you can view, track, and analyze them from the Alert
summary page." It names the destination page but does not explain the
purpose of alert triage in EASE, what makes this workflow distinct, or
the value to the analyst.
suggested_fix: |
The **Alert summary** page is the central triage hub for all alerts in
your Elastic AI SOC Engine (EASE) project. From here you can review
AI-generated insights, collaborate with AI Assistant, add alerts to cases,
and apply tags — without leaving the page.
- file: solutions/security/ai/ease/ease-upgrade.md
line: 13
category: weak-opening
severity: medium
evidence: |
Opening is one sentence that restates the H1: "This page describes how to
upgrade an {{sec-serverless}} project from the Elastic AI SOC Engine
(EASE) feature tier to the Security Analytics Essentials or Security
Analytics Complete feature tiers." The value of upgrading is buried in the
next section ("## Why upgrade?") rather than front-loaded in the opening.
suggested_fix: |
EASE is a streamlined project type that adds AI-powered alert triage
features on top of your existing SOC stack. When you need broader
capabilities — such as prebuilt detection rules, response actions, threat
intelligence, and runtime protection — you can upgrade to the Security
Analytics Essentials or Security Analytics Complete feature tier. This
page walks you through the upgrade steps and describes what to expect
afterward.
- file: solutions/security/ai/identify-investigate-document-threats.md
line: 26
category: missing-before-you-begin
severity: medium
evidence: |
The guide's steps require Attack Discovery to be configured with an LLM
connector and to have at least one discovery generated, and AI Assistant
to be configured with an LLM connector. None of these prerequisites appear
in the first 50 lines; the first task section starts at line 26 with no
prior requirements section.
suggested_fix: |
## Before you begin
- [Attack Discovery](/solutions/security/ai/attack-discovery.md) is
configured with an LLM connector and at least one discovery has been
generated.
- [AI Assistant](/solutions/security/ai/ai-assistant.md) is configured
with an LLM connector.
- file: solutions/security/ai/triage-alerts.md
line: 23
category: missing-before-you-begin
severity: medium
evidence: |
The page's two triage workflows each require setup that is not mentioned
before the task sections: the multi-alert path requires Knowledge Base
enabled with the Alerts setting on (line 23+); the single-alert path
requires AI Assistant configured with an LLM connector. No prerequisites
section appears before line 23.
suggested_fix: |
## Before you begin
- [AI Assistant](/solutions/security/ai/ai-assistant.md) is configured
with an LLM connector.
- To triage multiple alerts simultaneously,
[Knowledge Base](/solutions/security/ai/ai-assistant-knowledge-base.md)
is enabled and the **Alerts** setting is turned on.
```
## Done when
- All listed pages have a specific, contextual H1; an opening paragraph that conveys purpose and value; and (where applicable) a prerequisites section.
- A PR addressing this issue is merged.
## Notes
- `ease-value-report.md` opening body is sourced from a snippet include (`/solutions/_snippets/value-report-intro.md`); only the H1 and `navigation_title` were audited directly.
> Generated by [Docs page-openings sweep agent](https://github.com/elastic/docs-content/actions/runs/27855797990) · 261.4 AIC · ⌖ 13.5 AIC · ⊞ 27.2K · [◷](https://github.com/search?q=repo%3Aelastic%2Fdocs-content+is%3Aissue+%22gh-aw-workflow-call-id%3A+elastic%2Fdocs-content%2Fgh-aw-docs-openings-sweep%22&type=issues)
Contributor guide
No contributing guide indexed for this repository
Research direction
Review the findings in solutions/security/ai/ease/ease-value-report.md, triage-alerts.md, use-cases.md, ease/ease-alerts.md, ease/ease-upgrade.md, and identify-investigate-document-threats.md. Start by comparing the named openings and prerequisites with nearby pages in the same subtree. Done means all listed pages have contextual H1s, purpose-and-value openings, and the required Before you begin sections, with navigation_title updated where noted.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation
- Issue type
- Documentation
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Quiet
- Clarity
- Clearly specified
- Newbie friendliness
- 75/100