Skip to main content

Incidents

The Incidents feature helps you track, respond to, and document security incidents within your organization.

Overview

Incident management provides:

  • Centralized tracking of all security incidents
  • Response coordination with assigned responders
  • Timeline documentation for post-incident analysis
  • Automated detection from platform monitoring signals

Incident Lifecycle

Detected → Triaging → Investigating → Containing → Resolved → Closed

Automatic Detection

Some incidents are created automatically based on:

  • Multiple failed login attempts
  • Unusual API activity patterns
  • Policy violations from governance packs
  • SIEM alerts from external integrations

Incident Severity

SeverityDescriptionResponse Time
CriticalActive breach or data lossImmediate
HighPotential breach or major policy violation1 hour
MediumSecurity anomaly requiring investigation4 hours
LowMinor security event24 hours

Feature Availability

FeatureGrowthEnterprise
Incident TrackingYesYes
Automated DetectionYesYes
Response Playbooks--Yes
Integration with SIEM--Yes

Next: Learn about SIEM Integration for security event export.