The Relevance Doctrine, Part 3: How Priority Intelligence Requirements Operationalize Relevancy

Chief Product Officer, Cyware

This is the third in a multiple part series, The Relevance Doctrine. Part 1 made the case that relevancy, not volume, is what determines whether a threat intelligence program actually works. Part 2 showed how relevancy becomes a calculation the platform runs continuously rather than a judgment call an analyst makes at hour six of a triage shift. This part is about what turns that calculation into a discipline.
Priority Intelligence Requirements are not a Cyware invention. They come from intelligence doctrine and have become core CTI tradecraft because they solve the exact problem this series is about. A PIR is a specific, decision-linked, time-bound and collectable question. As practitioners put it, without PIRs, intelligence teams collect everything and answer nothing.
They map cleanly onto the risk we opened with. A well-formed supplier PIR reads like this: "Are any of our Tier-1 suppliers currently being targeted by [actor] for credential theft?" That is a real example of an intelligence requirement elevated to a priority that guides where resources go. That is relevancy with an owner and a decision attached.
The discipline is right, the manual practice fails
Done by hand, PIRs decay. They get written in analyst language no stakeholder recognizes, they proliferate past the point where prioritization means anything, they drift as the business changes, and they die in a spreadsheet nobody revisits. The discipline is sound. The manual practice simply cannot keep up with the volume this series opened with. So we built PIR into the product to move a program from passive intel ingestion to intent-driven, outcome-led monitoring, and to make the requirement a living thing rather than a document.
Five capabilities that make PIRs run themselves
Intent: natural-language creation. Describe what you care about in plain language. AI extracts the threat actors, TTPs (MITRE-mapped), sectors, geographies and asset types, and scores the quality of your requirement, so a vague PIR is rewritten before it produces noisy results.
Overlap: pre-creation detection. Before a new PIR is saved, semantic similarity checks it against existing ones and flags heavy overlap, recommending a merge or a sharper scope. This directly fixes the "too many PIRs" failure that quietly kills programs.
Matching: continuous and dual-source. Every inbound advisory, alert, threat object and IOC is scored against your active requirements at ingest, via both semantic similarity and precise IOC matching. Top-of-list becomes automatic. Triage stops being a manual sort.
Health: one score, seven signals. Each requirement carries a composite health score (coverage, freshness, confidence, velocity) and fires compound signals rather than single-threshold alerts, across three tiers: emerging threat, actor attribution and vulnerability; pattern and activity-spike; and the ones humans miss under load, intelligence-gap and escalating-risk.
Governance: audit-ready by design. TLP handling, notifications and an append-only, tamper-evident audit trail. The result is a defensible answer to the question every board eventually asks: "Are we actually monitoring X?"
Compound signals fire on real conditions, not thresholds, which is why they cut false positives instead of adding to them. And gap signals catch a blind spot before an incident exposes it.
The agents doing the CTI grunt work
Under the hood, PIR is run by a small set of purpose-built Cyware AI agents, each mapped to a job an analyst would recognize, consistent with our multi-agent approach of decomposing a CTI team's duties into functional agents. A Strategist handles genesis: extracting entities, mapping to MITRE, scoring intent quality and detecting overlap the moment a requirement is created. An Analyst continuously matches new intelligence against every active requirement, and is fine-tuned by analyst thumbs-up and thumbs-down feedback, so relevancy compounds over time. An Auditor watches for coverage gaps and escalating risk, and raises them proactively. This is agentic AI applied to the high-volume, unglamorous work that burns analysts out, and it augments the human rather than replacing the judgment.
Three personas, three results
Analyst Less triage, more analysis. Advisories scored against requirements at ingest, with an indicative 40 to 60% reduction in triage time. | Leadership Posture you can defend. Coverage, freshness and confidence for board-priority requirements in a single view. | Operations Faster signal-to-action. An indicative sub-hour path from ingest to a PIR signal on a high-severity match. |
Those figures are indicative targets, not guarantees. They depend on your feeds, tuning and workflow. But the direction is the point: the program gets sharper the longer it runs.
Where it runs
PIR is available within the Cyware Intelligence Suite and Cyware Intel Exchange. As it evolves with open APIs and MCP support, your requirements and their matched intelligence would be available to your own agents and workflows.
Relevancy and PIR tell you what matters and why. Part 4 is about what you do about it, before the incident.
SEE PIR LIVE
Watch a Priority Intelligence Requirement go from a sentence of plain English to continuous, scored, audit-ready monitoring, with the AI agents that keep it healthy.
About the Author

Sachin Jade
Chief Product Officer, Cyware