Triage an identity alert where the directory is read at volume or with tooling — tenant or directory enumeration bursts, user-list or workflow exports, attack-tool fingerprints, and sensitive admin reads via scripting or CLI. Reads the directory audit trail and the actor's baseline cadence to tell sanctioned automation reading at its normal rate apart from a scripted enumeration burst staging an attack, and decides escalate or dismiss. Boundary — this skill owns the act of reading; a follow-on privilege change or app/device registration is cited only as chaining evidence.