A real-time incident command surface for security teams: declare an incident in one tap, alert staff and external contacts, watch everyone on a live map, and review it all afterwards. An Enterprise feature.
What Security Operations Is
Security Operations is the place your team runs a live incident from. It pulls the things you need in a crisis into one surface: declare an incident, work a protocol, broadcast to rooms, alert staff and external contacts at once, watch where everybody is on a live map, triage anyone who says they're not safe, and — once it's over — write it up. It's built for security teams who have to respond and prove they responded.
Security Operations is an Enterprise feature. You'll also need the security_ops.view permission to see it or security_ops.manage to run it. Tenant admins get both by default; everyone else must be granted access.
Getting There
Open Security Operations from the dashboard sidebar. It runs as its own workspace, with a left-hand menu for each view and a live dashboard front and centre. Declare Emergency sits at the top of that menu at all times — one tap from anywhere in the workspace to a sounded alarm.
The Views
Dashboard — Live picture: active incidents, alerts by severity, team presence, acknowledgement speed, and a running feed of recent events.
Active Incident — Run the incident in front of you. This is where most of a response happens; its tabs are listed below.
Announcements — Maintain the library of pre-recorded voice messages you broadcast.
Protocols — Build the reusable checklists incidents run from.
Settings — Everything you configure before an incident: your scenarios, the response page, and how live location behaves.
Intelligence — Review entities pulled automatically from incident transcripts.
History — Search past incidents and open their full dossier.
Incident Replay — Play an incident back, synchronised across transcript, audio and events.
Inside an Active Incident
The Active Incident view is tabbed, and the tabs are ordered by the question you're most likely to be asking. During a live alarm you land on Accountability by default, because "who is unaccounted for" is the thing you need first.
Accountability — Who has answered, who has not, and what each of them said.
Map — Everyone's live position, on real mapping. See The Live Incident Map.
Intelligence — Key facts pulled out of the incident's transcripts as they're said.
Response — Distress cases: the people who told you they need help.
Checklist — The protocol's steps, worked one by one.
Alarms — Fire an alert, send an update, stand it down.
Notes — A running narrative of what's happening.
Timeline — A read-only, time-stamped log of every action taken.
Who Can Do What
View (security_ops.view) — See incidents, alerts, distress cases, protocols, announcements, the map and intelligence. Read-only.
Manage (security_ops.manage) — Everything in View, plus declare and resolve incidents, fire alerts, run protocols, edit announcements, respond to distress, message people from the map, change Security Operations settings, and sign off after-action reviews.
Almost everything here can be run as a drill. A drill exercises the whole flow — alerts, replies, the lot — but is excluded from compliance breach counts, suppresses the most disruptive push channels, and never captures live location, so you can rehearse without crying wolf.