Operate
Console route · /incidents
Incidents
Queue-first case work: prioritized incidents with evidence custody, ownership, deferral, escalation, and approval-gated response. This is the primary analyst case file for the tenant.
Job of this page
Incidents is where cases live. Findings from detections and Hunt Ledger, sync’d Microsoft incidents, and operator-created work all converge here as shared cases with evidence links. The page is queue-first: you triage what is Now versus Later, assign ownership, investigate with custody intact, and request or approve response actions.
Queue model: Now and Later
Incidents are classified into Now and Later so operators can park work without losing it. Later is intentional deferral, not deletion. Filters cover severity, status, assignment, and text search. The shell time range scopes what is visible. Deep links support ?id= and ?tab= so a Hunt Ledger finding, notification, or Automation handoff can open straight into the correct case tab.
Typical row actions include assign analyst, escalate, defer with presets, and suggested next step — gated by incidents:manage, incidents:assign, and related permissions depending on role.
Investigation tabs
Selecting a case opens investigation chrome. Route shows how entities and evidence relate for the case. Evidence lists source-linked events by evidence event ids. Replay supports time-oriented review of the case narrative. Response is where you request and approve containment or ticket actions against this incident. Automation shows playbook runs tied to the case. Custody keeps the provenance story visible.
You should be able to move from a claim on the case header to a specific event payload without leaving the product’s custody model. If evidence ids are empty, the case is incomplete — say so, don’t invent links.
Response from the case
From the Response tab, authorized operators create response actions (request). Approvers with response:approve and the matching action scope approve. Pending actions also appear in broader approval surfaces and can gate Automation runs. This is the same response_actions model used by domain workbenches and Hunt Ledger’s create_ticket proposals.
Capabilities and boundaries
- Now / Later queues and defer presets
- Severity, status, unassigned filters and search
- Assign, escalate, suggested next step under RBAC
- Evidence and custody tabs with linked event ids
- Request/approve response actions
- Live load of incidents and pending actions; evaluation dataset only when enabled
Incidents is not Detection Engineering and not playbook authoring. Shadow detections may evaluate without opening cases. Graph completeness depends on what the control plane has projected for the tenant.