A risk field mapping is an account-authored rule: match kept normalized events, extract Work-Input or Work-Output, write an Asset series.
· Enable only the mappings you need. Unused mappings can be disabled from the tenant Admin Console.
· OCSF and other schemas work when your mapping paths match the fields you actually send. There is no automatic “OCSF certified” switch.
· `last_observed_at` on a mapping means live apply has seen matches. Missing observation is Unknown, not zero risk.
Mappings never copy raw ciphertext into reports or chat tools.