A real-time incident command surface for security teams: raise and run incidents, fire emergency alerts, triage distress from external contacts, and review everything afterwards. An Enterprise feature.
Security Operations is the place your team runs a live incident from. It pulls the things you need in a crisis into one surface: declare an incident, work a protocol, broadcast to rooms, fire an emergency alert to staff and external contacts, triage anyone who replies that they're not safe, and — once it's over — write it up. It's built for security teams who have to respond and prove they responded.
security_ops.view permission to see it or security_ops.manage to run it. Tenant admins get both by default; everyone else must be granted access.Open Security Operations from the dashboard sidebar. It runs as its own workspace, with a left-hand menu for each view and a live dashboard front and centre.
security_ops.view) — See incidents, alerts, distress cases, protocols, announcements and intelligence. Read-only.security_ops.manage) — Everything in View, plus create and resolve incidents, fire alerts, run protocols, edit announcements, respond to distress, and sign off after-action reviews.