Keep the lesson. Not just the alert.

Every meaningful response should improve what the organisation knows about itself.

Innate and adaptive stay separate.

Innate knowledge covers security principles, known weaknesses, excessive privilege, weak authentication, and dangerous exposure. Adaptive knowledge describes this organisation: deployment patterns, critical services, trusted workflows, and the context behind previous decisions.

Learning that behaviour is common does not make it secure. A business exception can change prioritisation and ownership while the underlying weakness and compensating-control requirements remain visible.

Antibodies must earn their place.

An antibody represents a learned detection or defensive understanding tied to prior evidence and memory. Supported CI/CD matches can first run in shadow mode without changing production policy.

Before owner-approved activation, historical positive and negative cases are rerun and recorded. Matching a later mutation is observable in the audit trail. This is a bounded learning mechanism, not permission for an LLM to rewrite controls or a claim of general autonomous improvement.