Use when the user asks to investigate WideField findings, audit identity threat coverage, build remediation packets, or validate OAuth/NHI/AI-agent identity risks without destructive remediation. Diagnose WideField identity threat coverage for OAuth token abuse, rogue or over-privileged apps, non- human identity ownership, MFA and credential posture, AI-agent identities, and anomalous sessions using read-only Splunk, Okta, and evidence checks.