On this page:
Using Approval Queue
Use the Approval Queue to review and act on the decisions AURA has routed to you for approval.
On the Approval Queue page, you can:
-
Review a recommendation. Open the approval details page for an alert to see the recommended action, the confidence level, and the evidence, reasoning, and history behind it.
-
Approve a recommendation. Promote an alert or alert group to an incident, or approve an escalation or closure recommendation for an incident.
-
Reject or redirect a recommendation. Send the item back for further investigation, set it to monitor, or dismiss it as a false positive.
-
Override a prior disposition. Reopen and change an action AURA already took automatically, including an alert AURA closed as a false positive, from the alert history.
-
Process items in bulk. Approve a batch of similar recommendations at once instead of reviewing each one individually.
(Click the image to enlarge it.)
Search requested actions: Search requested actions by their name. The search is incremental.
Criticality: Filter requested actions by their criticality—info, low, medium, high, or critical. The criticality value defines how severe the underlying threat or finding is.
Risk: Filter requested actions by their risk—info, low, medium, high, or critical. The risk value defines how risky it would be to take the recommended action.
Type: Filter requested actions by their type—human-created or agent-created.
Status: Filter requested actions by their status:
-
Created—task is generated but has not yet started. This is the starting point for both Agent tasks and human tasks.
-
In Progress—work is actively happening on the task. For an Agent task, this means the Agent is running the associated workflow (for example, correlating a CVE against the asset inventory).
-
Decision Required—task that needs a person to make a decision before it proceeds. This status displays as a "Decision Required" badge in the queue. If the workflow is HITL (human-in-the-loop), the underlying action is blocked until the decision is made.
-
Actioned—human task has been resolved.
-
Completed—Agent has finished its work. The result of the work, including supporting evidence, is stored with the task.
-
Closed—task has reached its final state. A task reaches Closed after being Actioned (human task) or Completed (Agent task). A task can also move directly to Closed without ever reaching Decision Required, if the Agent determines no human decision is needed (for example, when a credential lookup finds the associated identity is no longer active).
Reset: Reset filters.
Requested Action: See Reviewing Requested Actions for details.
Criticality: Criticality of the requested action.
Type: Type of the requested action—human-created or agent-created
Risk: Risk level of the requested action.
Status: Status of the requested action.
Policy: Identifies the specific workflow rule that generated this task and is governing how it's handled. The format shows the domain and workflow (for example, soc:alert_triage) followed by a unique identifier for that run, so you can trace exactly which policy required this item to come to you for a decision.
View Settings: Select the columns and table density (default or compact) to be displayed. By clicking the drag handle icon (
), drag and drop columns to change their position in the table. To return the view back to its default settings, click Reset View.
