What it covers
Review correlated alerts, assignment and immutable investigation history, then create a governed service incident.
Intelligence and security
Triage supported endpoint protection signals against customer and service context.
How it works
Review correlated endpoint protection alerts alongside customer and service information. Assign an investigation, preserve its history and create a governed service incident when appropriate.
Review correlated alerts, assignment and immutable investigation history, then create a governed service incident.
Public beta scope is defined; broad log collection and automated containment are not included.
When to use it
A working path
Review the normalized detection available to the enabled beta workspace.
Assign the alert and preserve the investigation history.
Create a service incident when the reviewer decides follow-up is warranted.
Illustrative scenario
A security reviewer checks a correlated endpoint signal, connects it to the affected customer and creates a service incident for the assigned team. The investigation history captures who reviewed the alert and what they decided, while the resulting service incident gives the responsible team a normal accountable follow-up path.
Before you start
No. The beta covers a defined set of endpoint posture and normalized detections.
No. Investigation and escalation remain human-governed.
Get started
Start with the core CRM for free, then add the tools your team needs.