Investigations
Every run is pinned to a repository revision, scoped by a threat model, and retained as a read-only investigation record.
Only runs authorized for the current workspace are shown.