On this page:

Using Approval Queue

Use the Approval Queue to review and act on the decisions AURA has routed to you for approval.

On the Approval Queue page, you can:

  • Review a recommendation. Open the approval details page for an alert to see the recommended action, the confidence level, and the evidence, reasoning, and history behind it.

  • Approve a recommendation. Promote an alert or alert group to an incident, or approve an escalation or closure recommendation for an incident.

  • Reject or redirect a recommendation. Send the item back for further investigation, set it to monitor, or dismiss it as a false positive.

  • Override a prior disposition. Reopen and change an action AURA already took automatically, including an alert AURA closed as a false positive, from the alert history.

  • Process items in bulk. Approve a batch of similar recommendations at once instead of reviewing each one individually.

(Click the image to enlarge it.)

Search requested actions: Search requested actions by their name. The search is incremental.

Criticality: Filter requested actions by their criticality—info, low, medium, high, or critical. The criticality value defines how severe the underlying threat or finding is.

Risk: Filter requested actions by their risk—info, low, medium, high, or critical. The risk value defines how risky it would be to take the recommended action.

Type: Filter requested actions by their type—human-created or agent-created.

Status: Filter requested actions by their status:

  • Created—task is generated but has not yet started. This is the starting point for both Agent tasks and human tasks.

  • In Progress—work is actively happening on the task. For an Agent task, this means the Agent is running the associated workflow (for example, correlating a CVE against the asset inventory).

  • Decision Required—task that needs a person to make a decision before it proceeds. This status displays as a "Decision Required" badge in the queue. If the workflow is HITL (human-in-the-loop), the underlying action is blocked until the decision is made.

  • Actioned—human task has been resolved.

  • Completed—Agent has finished its work. The result of the work, including supporting evidence, is stored with the task.

  • Closed—task has reached its final state. A task reaches Closed after being Actioned (human task) or Completed (Agent task). A task can also move directly to Closed without ever reaching Decision Required, if the Agent determines no human decision is needed (for example, when a credential lookup finds the associated identity is no longer active).

Reset: Reset filters.

Requested Action: See Reviewing Requested Actions for details.

Criticality: Criticality of the requested action.

Type: Type of the requested action—human-created or agent-created

Risk: Risk level of the requested action.

Status: Status of the requested action.

Policy: Identifies the specific workflow rule that generated this task and is governing how it's handled. The format shows the domain and workflow (for example, soc:alert_triage) followed by a unique identifier for that run, so you can trace exactly which policy required this item to come to you for a decision.

View Settings: Select the columns and table density (default or compact) to be displayed. By clicking the drag handle icon (), drag and drop columns to change their position in the table. To return the view back to its default settings, click Reset View.