> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cotool.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Operate and Tune Detections

> Manage scheduled runs, understand alert output, and control detection tuning.

## Control scheduled execution

Open a detection from [Detections](https://app.cotool.ai/detections/overview), then select its **Settings** tab. A detection needs a published version before scheduled execution can be enabled.

Use **Enabled** to start or pause scheduled runs. **Run cadence** offers no schedule, every 10 minutes, every 30 minutes, hourly, every 6 hours, or every 24 hours. Check both the enabled state and cadence when a detection is not running.

Disabling a schedule does not erase the published version. Draft edits do not affect scheduled execution until they are published.

## Inspect executions

Open **Executions** and select a run to inspect its status, error, and emitted rows. Distinguish an execution failure from a successful run with no findings.

If expected alerts are missing:

1. Verify the detection has a published version and an enabled schedule.
2. Confirm its required integrations and log streams are available.
3. Check ingestion freshness for the time window being evaluated.
4. Inspect the scheduled execution's output and any errors.
5. Check the minimum severity and existing alert activity before assuming every emitted row should create a new alert.

Manual production runs provide execution output without creating hits or alerts. Use them to investigate behavior; they do not exercise the complete scheduled alert pipeline.

## Hits, severity, and triage

Scheduled detection results are recorded as hits. **Minimum severity** controls which hits can create alerts: rows below the threshold are still recorded as hits, but do not create alerts. The available thresholds are Low, Medium, High, and Critical.

Repeated findings can be correlated with existing hits, so emitted-row counts, hit counts, and alert counts are not interchangeable.

Configure the organization default response route in [Alerts > Triggers & Routing](https://app.cotool.ai/alerts/triggers-and-routing). Routing determines whether detection-created alerts go to a response agent or remain unassigned. See [Alert Routing](/alerts/routing) for the routing workflow.

## Review tuning proposals

Use **Tune detection** to begin refining an existing detection. When a tuning proposal is available, review the proposed changes and supporting evaluation before approving or rejecting it. Approval publishes the proposed revision; inspect the live logic and subsequent executions to confirm the behavior.

The **Auto-apply tuning proposals** setting can inherit the organization default or explicitly be set to On or Off. When enabled, Cotool can publish tuning proposals automatically. Set it to Off when you require manual review for that detection.

Review **Overview** and version history after tuning to understand what changed. Recheck the schedule, data freshness, and alert volume as part of evaluating the revised logic.

[Back to Detections Platform](/detections-platform/overview)
