SATIE / Incident Arcade / Next direction / August 17, 2026
SATIE Training: Bringing the Analyst Workstation to the Arcade
Instead of forcing public Arcade users into operational SATIE, we are taking the SATIE workstation experience to the public scenarios.
The original SATIE integration created an interesting realization.
We were trying to move Incident Arcade users into SATIE.
Maybe the better answer is to move the SATIE experience into the training environment.
That is the direction of the next iteration: a separate public training application built from the SATIE analyst-workstation experience and the existing Incident Arcade scenario engine.
The architecture matters.
We are not making operational SATIE public.
Operational SATIE remains authenticated and protected through HDJames.
Instead, the public training application can reuse the appropriate SATIE presentation components — case workspace, timeline, entities, evidence views, ATT&CK context, investigation workflow, and triage controls — while connecting them to a completely separate simulation data provider.
Conceptually:
SATIE interface + Incident Arcade scenarios + Arcade scoring = public SOC simulator.
The existing 77 Arcade scenarios remain the canonical scenario library.
They are adapted into simulated SATIE cases rather than copied into another manually maintained question bank.
A scenario involving suspicious AWS credentials might appear as a case containing an identity, source context, event timeline, evidence artifacts, and related API activity.
Instead of reading one large block of text, the analyst sees the information the way an investigation naturally unfolds.
A chained incident becomes an evolving timeline.
A Boss Incident can contain multiple entities, competing signals, and unrelated noise.
Evidence Economy becomes more natural because requesting additional context feels like investigating a case instead of clicking a hint button.
The scoring engine remains Incident Arcade.
The analyst still needs to decide:
- malicious, suspicious, or benign
- appropriate severity
- confidence
- appropriate response
SATIE provides the workstation.
Arcade evaluates the judgment.
There is also a hard safety requirement.
A simulated Disable Access Key decision must remain exactly that: a decision in a training scenario.
The public training application will not receive operational SATIE credentials or response capabilities. Simulation and operational functionality remain structurally separate.
For now, the existing Incident Arcade will remain available alongside the new experience.
That gives us an interesting comparison.
Arcade Classic can remain the fast, lightweight way to work security scenarios.
SATIE Training can become the immersive analyst-workstation version of the same cases.
Because both experiences use the same scenario IDs and scoring model, we can eventually compare how each interface affects investigation behavior, completion, evidence use, and engagement.
Then we can make the replacement decision based on evidence rather than preference.
That feels like the right way to evolve the project.