Alerts tell you something changed; cases are how you work them to resolution. The Portal brings security and network events into one queue so nothing falls between tools.
Alerts vs cases
- Alerts are individual signals — a link degraded, a detection fired, a risky sign-in.
- Cases group related alerts into one investigation with an owner, a status, and a history. Managed SOC analysts open and work security cases; network cases can be auto-created from SD-WAN events. For the detection side of that grouping — correlating activity across vendors into one incident — see multi-tenant SIEM detection and correlation.
Work a case
Triage
Open the queue, sort by severity, and pick a case. The detail view shows the grouped alerts, affected assets, and the analyst's assessment.
Assign
Take it yourself or assign it to a teammate. Ownership and every change are recorded.
Approve or take action
Where a response needs your sign-off — isolating a device, disabling an account — approve it from the case. Co-managed actions are logged with who approved them.
Note and close
Add notes as you go, then resolve with a disposition. The history stays for audit and for the monthly review.
Severity & SLAs
Cases carry a severity and, for Managed SOC customers, a response SLA. The Portal shows time-to-acknowledge and time-to-resolve so you can hold the process — and the SOC — to account.
Routing out
Cases and alerts can also leave the Portal: route them to email, a webhook, or your ticketing/ITSM via notifications, so they land in whatever tool your team already lives in.
Co-managed by design
You choose how much the SOC does autonomously versus what needs your approval. High- confidence containment can be automatic; anything you want eyes on waits for a sign-off in the case. Set this per action type with your onboarding team.
