Reviewing and acting on alerts

  1. Open Portal -> Alerts (or the notification tray).
  2. Sort by severity; SEV-1/2 first.
  3. For each alert: Acknowledge, Assign, or Escalate.
  4. Add a short note explaining your decision - this is your audit trail.
SeverityMeaningYour SLA to first action
SEV-1Active breach / criticalImmediate
SEV-2Critical exposureWithin 1 hour
SEV-3High / suspiciousSame business day
SEV-4Compliance driftWithin 30 days
SEV-5InformationalNone

Handling an approval request

When someone requests a gated action you will see it in Portal -> Approvals.

  1. Read the context (what, who, why, blast radius).
  2. Check the evidence attached to the request.
  3. Choose Approve, Reject, or Request more info - always leave a reason.
  4. Approvals are single-use and time-boxed; an approval for one action does not cover the next.

Filing a risk, incident, or exception

Use the guided forms; each asks for a title, an impact statement, and a suggested owner.

The platform suggests a CVE mapping when your title contains a CVE id.

Reporting phishing

Forward suspicious email to the phishing mailbox or use Report phishing in the portal.

Never click links in a suspected phish; report and delete.

← End-User Guide  ·  All guidelines