Reviewing and acting on alerts
- Open Portal -> Alerts (or the notification tray).
- Sort by severity; SEV-1/2 first.
- For each alert: Acknowledge, Assign, or Escalate.
- Add a short note explaining your decision - this is your audit trail.
| Severity | Meaning | Your SLA to first action |
| SEV-1 | Active breach / critical | Immediate |
| SEV-2 | Critical exposure | Within 1 hour |
| SEV-3 | High / suspicious | Same business day |
| SEV-4 | Compliance drift | Within 30 days |
| SEV-5 | Informational | None |
Handling an approval request
When someone requests a gated action you will see it in Portal -> Approvals.
- Read the context (what, who, why, blast radius).
- Check the evidence attached to the request.
- Choose Approve, Reject, or Request more info - always leave a reason.
- Approvals are single-use and time-boxed; an approval for one action does not cover the next.
⚠️ Four-eyes rule: you may never approve your own request. The platform blocks self-approval.
Filing a risk, incident, or exception
Use the guided forms; each asks for a title, an impact statement, and a suggested owner.
- Risk -> register a new risk with likelihood x impact.
- Incident -> open an incident; pick a severity.
- Exception -> request a time-boxed deviation from a policy or control.
The platform suggests a CVE mapping when your title contains a CVE id.
Reporting phishing
Forward suspicious email to the phishing mailbox or use Report phishing in the portal.
Never click links in a suspected phish; report and delete.