Skip to content

War Rooms

zach115th edited this page Sep 30, 2026 · 16 revisions

War Rooms

Since IRIS-NG-v2.0.0, a war room is a persistent workspace for an incident that has outgrown one case — the first thing in IRIS-NG that is genuinely about several cases at once. A room attaches cases, gives the responders a shared stream, tasks, notes, timelines and situation reports, and carries the cross-case correlation view for its cases.

Rooms live in the sidebar under Investigation → War Rooms, as a card grid filtered by status chips.

The one rule that governs everything

Membership is not case access. Being in a room never lets you read a case you could not read otherwise. The stream's case-activity lane, the timelines, the notes and cases tabs, and the correlation view all filter per viewer by ordinary case access — and a case you cannot see is marked inaccessible rather than quietly dropped, so the room never looks smaller than it is.

Rooms therefore have no per-member "access" control, on purpose: access is managed where it always was, on the case.

Membership, roles, statuses

  • Roles: lead > responder > observer. The last lead cannot be removed or demoted; anyone but the last lead can leave on their own. Adding a member notifies them (Notifications).
  • Statuses: open, active, standby, closed. Only a closed room is read-only. Closing a room that was promoted from a correlation group frees that group to be promoted again.
  • Deleting a room is lead-only and removes the room and its own content (stream, tasks, notes, SitReps, room timelines). Linked cases are untouched — the room only ever referenced them.
  • Guests (since IRIS-NG-v2.4.0) Outside participants — the affected organisation's lead, a partner liaison — can be invited into one room without becoming IRIS-NG users. They sign in through the guest portal with email and password, take part at responder level on the room's own content (stream, polls, room tasks, room notes, SitRep drafts, room timelines, teams, ICS forms), see every attached case read-only (attaching is the sharing decision), get no AI feature, and lose access at expiry, on revoke, or when the room closes. Rooms also carry a slug (Edit dialog) for their portal address. Everything about them is on Guest Portal.

The stream

Chat with date separators and three lanes: messages, case activity mirrored from the linked cases (per-viewer filtered), and a system lane derived from what actually happened in the room — case attached, member added, SitRep published.

  • Replies thread one level deep; /thread names a thread and keeps the composer posting to it.
  • Topics partition the stream; pins mark what matters.
  • @mentions autocomplete over the room's members (by login) and its teams (by slug). A mention notifies — including a self-mention, since typing a login is an explicit address. While the autocomplete is open, Enter completes instead of sending. Messages highlight the mentions that resolved (since IRIS-NG-v2.2.0); the same palette now sits on every comment box outside the room — see Notifications.
  • Teams are named groups inside a room — @ir-leads reaches everyone in the team at send time. Teams accept room members only: they group, they never grant. Administrators can define default teams under Settings → War Room Teams (name, description, colour, order, enabled) (since IRIS-NG-v2.2.0). Every new room — created or promoted from a correlation cluster — starts with one empty team per enabled default, and the lead adds the people; existing rooms are not changed, and a seeded team is an ordinary room team afterwards.
  • Polls — 2 to 20 options, single- or multiple-choice, optional auto-close, optional anonymity. Anonymous polls withhold voter names server-side, not merely in the UI. Everyone with room access votes, observers included.
  • Slash commands — 13 of them, with a completion palette: /task creates a room task, /poll a poll, /topic and /thread organize, /summary asks the AI for a draft, /priority sets severity, and so on.
  • Resource tokens insert a case, asset or indicator inline as a linked chip, picked from the linked cases — so "this host again" can be that host, clickably.

The stream is REST polled every few seconds by design — no websocket dependency, and it survives every proxy that plain HTTPS survives.

Tasks, timelines, notes

  • Tasks — room-level tasks (distinct from case tasks) with a list and a kanban board, subtasks, tags, due dates and assignment; re-assignment notifies. Below them, a read-only aggregation of the linked cases' tasks, per-viewer filtered.
  • Timelines — read-only, toggleable views of each linked case's timeline, plus room-level timelines for coordination annotations (colour-coded rails). Case timelines are only ever read; the case pages remain the source of truth.
  • Notes — room notes with one level of folders, Markdown with autosave; deleting a folder moves its notes to the root rather than deleting content. Linked-case notes appear read-only, viewer-access-checked.
  • ICS forms (since IRIS-NG-v2.1.1) — when the first case is attached, Incident Command System forms are seeded into an ICS folder from bundled templates (ICS 201 Incident Briefing, ICS 202 Incident Objectives, ICS 203 Organization Assignment List; since IRIS-NG-v2.2.0: ICS 204 Assignment List, ICS 205A Communications List, ICS 209 Incident Status Summary, ICS 214 Activity Log), prefilled with what the room already knows, then completed by an AI pass that fills only the fields still empty and marks every fill, then handed to the Incident Commander. One set per room; a seeded note is never rewritten. The clipboard and sparkle icons in the Notes rail header run the seed and the AI pass on demand, and each ICS note downloads as the filled official FEMA PDF (since IRIS-NG-v2.2.0). Full detail on the ICS Forms page.

The Summary tab

(Since IRIS-NG-v2.4.0.) The tab carries an operational summary of the room's cases at ICS / Emergency Support Function level, maintained by the AI and editable by the analyst: eight ICS-209-shaped sections (situation, significant events, life safety and threat, projected activity, objectives, critical resource needs, planned actions, cooperating agencies and ESFs). The ESFs are derived on the server from the attached cases' sector tags, using the California ESF list with CA-ESF 18 Cybersecurity on every room. The summary regenerates itself on room events (case attached or detached, status change, SitRep publish, ICS note save) as long as nobody has edited it; an edit freezes it until Revert to AI. An amber badge says when the inputs have changed since the text was written. It never reads the SitReps, and the SitRep drafter never reads it, so the two cannot feed each other. The short export description (the campaign text on STIX export and MISP push) stays a separate field under it, edited from the room's Edit button. Detail on AI Features → War-room operational summary.

Situation reports

SitReps are drafted in a two-pane editor (rail of reports, inline Markdown editor with preview), seeded from a Situation / Actions / Next-steps skeleton.

  • Publishing is lead-only and notifies the room. Every edit of a published SitRep snapshots the pre-edit state as a revision — the version history is complete by construction. A lead can also delete a published SitRep.
  • Who is told (since IRIS-NG-v2.2.1): the members of the room's @leadership team receive the full report in the mailbox and by email (the SitRep published (leadership team / room lead) event, on for both channels by default; the org matrix and personal settings still win). Everyone else in the room keeps the in-app teaser. A room with no leadership team, or an empty one, addresses the room leads instead. Only the first publish notifies — later edits of a published SitRep write revisions and tell nobody.
  • Exports: Markdown, HTML, and print-to-PDF.
  • AI drafts (AI Features): the model composes a draft from the linked cases' cached summaries and the room's own activity, and it lands as a draft in the editor. AI never publishes. (since IRIS-NG-v2.2.1) After a room's first published SitRep, drafts are deltas — what changed since that report, opened by a server-written "Delta since …" line, with still-open decisions carried forward; the status line under the AI button reports how many draft lines repeat the previous SitRep verbatim, so a model that ignored the rule is caught before review.

Correlation in the room

The correlation engine and every /api/v2/correlation/ endpoint are unchanged (IOC Correlation) — what moved is where you work with results.

  • The war-rooms page carries a discovery panel of correlated case groups, each with promote to war room: creates the room, attaches the cases, and seeds the room summary and first SitRep from the correlation narrative you already reviewed. Rooms are never created automatically, and promoting the same group twice is refused while its room lives.
  • Inside a room, the Correlation tab lists the shared indicators — as the same cards the correlation workspace shows, rendered by one shared renderer since IRIS-NG-v2.0.2 — plus campaign tagging, the per-IOC context drawer, the STIX export and the MISP campaign push over the room's attached cases.
  • Outbound sharing keeps the TLP rules: most-restrictive-wins, unset TLP is not shareable, and both exports report how many indicators were withheld — a partial export never looks complete.

Notifications

Room events ride the normal catalog (Notifications): being added, being mentioned, task assignment, and published SitReps (with a separate, email-on leadership event for the @leadership team since IRIS-NG-v2.2.1 — see Situation reports above). Per-message stream notifications exist but default to off — they fire once per message, so members opt in rather than being opted in.

Clone this wiki locally