Dashboard GuideAlerts & Incidents

Alerts & Incidents

The Alerts & Incidents panel is a card-based incident board for managing security events.

Alert Display

Each alert is a collapsible card:

  • Collapsed view — severity badge + title + age timer + status pill for quick scanning
  • Expanded view — description, source, instance, ACK/Resolve buttons, and backlink to the originating panel

Alert Severities

SeverityColorMeaning
CRITICALRedImmediate attention required (BLOCK verdict, break-glass activation, service failure)
HIGHOrangeSignificant threat or operational event
MEDIUMYellowModerate concern
LOWBlueInformational

Alert Lifecycle

  1. OPEN — new alert, needs attention
  2. ACKNOWLEDGED — someone is looking at it
  3. INVESTIGATING — active investigation
  4. MITIGATED — threat contained
  5. RESOLVED — issue resolved
  6. FALSE POSITIVE — not a real threat

Each alert card links back to its source: correlation alerts link to the Correlations tab, shield alerts link to Prompt Shield, session-watcher alerts link to Traffic Monitor.

Common Alert Types

AlertWhat To Do
”Shield BLOCK: [rule]“Review the detection; whitelist if false positive
”Shield REVIEW: [rule]“Check the traffic entry; may need investigation
”Watchdog: Dashboard recovered”Check logs; usually transient
”Break-Glass Activated”Verify authorization; review unscanned traffic after