Orion IA (OIA) is the artificial intelligence built into OrionEye. It is not a chat window bolted onto a map: it is the layer that coordinates the platform's specialised agents — access control, network topology, cyber threat — and explains what they find, in the operator's language, at the moment it matters.
A cyber and geospatial operator does not lack data. They lack the minute in which to read it. OrionEye already gathers accesses, devices, network topology, satellites, incidents and threat feeds; the difficulty is noticing the one thing, among thousands, that requires a decision now.
That is the job OIA does. It watches continuously, stays silent when there is nothing to say, and when something does not add up it says so — with the facts that led to the conclusion and the action worth taking first.
One core, several specialised agents, one inference engine that can run in the cloud or entirely on the customer's premises. The operator talks to the core; the core decides which agent answers and which model narrates.
OIA's security audit agent reads the account's own history — logins, devices, addresses, programs — and looks for facts that are anomalous by definition, not for patterns it has learned. That is a deliberate choice: it works from day one, on an account with no history at all.
A device key reached the login but matches no device on the account. The clearest signal there is: someone got in from a machine the operator never associated.
Two accesses too far apart for the time between them. Works with two events and no baseline — nobody travels at 900 km/h.
A country that had never appeared. Stays silent on a short history: the first country an account uses is not new, it is the starting point.
Repeated rejected attempts from one address. Failed logins are recorded for exactly this reason — an agent that cannot see the attempts it repels watches half the problem.
The first time OmniAgent OS, SentraLink or the USB agent uses this account. Usually nothing to do — a note in the record of when it began.
Each located finding becomes a pulsing red reticle on the globe, with the response actions in its card: block the device, force sign-out, archive.
Both are the operator's choice, in the Access panel.
| Cadence | When it runs | Suited to |
|---|---|---|
| On event | At every new handshake or session, right after the response is sent | Small teams, immediate reaction |
| Scheduled | Hourly, daily, weekly or monthly | Fleets, periodic review |
| Plan | Inference | Where the analysis runs |
|---|---|---|
| Free | — | Not available — unless a Pro USB key raises the session |
| Pro | Cloud, Gemini by default or your own API key | Platform backend |
| Enterprise | Local models only, containerised on OmniAgent OS | The operator's own machine |
OIA keeps working. Every rule carries its own written explanation, and that is what the operator reads when an API quota runs out or the local container is down — the findings are all there, the wording is simply less tailored. A security agent that falls silent because a key expired would be worse than no agent, because people rely on it.