Skip to content

workflow handle_escalation

EDAMAME Dev edited this page Jul 2, 2026 · 2 revisions

Handle a security escalation


Workflow

📚 Handle a security escalation

Overview Work the engagement queue: review active escalations by type, navigate to the related device/user/policy, and dismiss items you have addressed. This walkthrough stops before dismissing so it is safe to run against the live demo workspace.

➡️ View the related feature

🪜 Steps

1. Open the Engagement page

Open Engagement from the End-users section. The stat cards at the top (highlighted) summarize open escalations by type: New Alerts, Signal Lost, Inactive Device, Onboarding Not Completed, and Policy Violation.


Open the Engagement page

Step 1: Open the Engagement page


2. Review the active queue

The 'Active' table (highlighted) lists open escalations (Username, Type, OS Type, Since). Click any row to jump to the related device, user, or policy and investigate the cause.


Review the active queue

Step 2: Review the active queue


3. Dismiss or resolve an item

Use the dismiss action at the end of a row (highlighted) to clear an escalation you have addressed. Dismissed items move to the 'Dismissed' section where they can be restored; resolved escalations appear read-only under 'Resolved'.


Dismiss or resolve an item

Step 3: Dismiss or resolve an item



🏠 Navigation


This page was automatically generated from workflow definitions.

Clone this wiki locally