Alerts and Incident Triage
Alerts identify events that need operator attention. Use them to understand the finding, affected agent, related session, and the policy or detection context that produced it.
Triage an alert
- Filter by severity, status, time range, agent, or owner.
- Open the alert and review the evidence, detection context, and related session.
- Confirm the agent and tenant before taking action.
- Decide whether the alert is expected behavior, requires policy tuning, or should become an incident.
- Record the disposition and preserve links to relevant session evidence.
Escalate thoughtfully
Create an incident when the work needs coordination across people, agents, or systems. Use the incident timeline to keep investigation notes and containment actions together. Do not weaken a control globally just to clear a single alert; first narrow the policy scope or verify whether an approved exception applies.
See Incidents for the coordinated response workflow and Policy authoring for safe control changes.