Use when the user asks how Cisco Secure Workload (CSW/Tetration) maps to MITRE ATT&CK, which adversary techniques CSW mitigates or detects, ATT&CK coverage/heatmap, "what techniques are we covered for", or technique-level defensive coverage. Reports CSW mitigation/detection COVERAGE against live cluster state…
Use when the user asks for compliance evidence, control mapping, "are we PCI/NIST/CIS compliant", framework coverage, audit evidence, or "prove control X holds" against Cisco Secure Workload (CSW/Tetration). Runs per-framework control mappings against the live cluster and reports four-state evidence…
Use when the user asks for posture, drift, top-N noisy workspaces, onboarding gaps, "what's not enforced", "what's stale", "where to look next", or focused single-question operator reports against Cisco Secure Workload (CSW/Tetration). All read-only — never proposes writes.