// Generated from the feature catalog
The Four Whys
Knows What’s Wrong Before You Do · Shipped · workstation, home
Every finding explains why now, why care, why so, and why trust — with real detector evidence, not raw error dumps.
Replaces raw discovery alerts with curated Findings. Before Halbert interrupts you, it must justify why the issue matters right now, why you should care, what evidence supports the claim, and why the detection is trustworthy. The FindingStore persists these records with full provenance.
Detector sweeps (acoustic anomaly detection, permissions hygiene checks, and more) aggregate low-level scanner anomalies. When an anomaly breaches thresholds, a Finding record is generated with four justification fields and queued in the attention ledger. Dashboard routes expose the findings list and allow proposing fixes.
Limits and invariants
Section titled “Limits and invariants”Zero vanity notifications: findings respect user-defined quiet hours and the proactivity dial.
Where this lives
Section titled “Where this lives”halbert_core/halbert_core/findings/store.pyhalbert_core/halbert_core/findings/precedence.pyhalbert_core/halbert_core/findings/detectors/halbert_core/halbert_core/dashboard/routes/findings.py