Reviewing Requested Actions

For each requested action in the Approval Queue, open its approval details page. The page provides an approval summary along with the Agent recommendation and confidence level.

To understand why the Agent reached its recommendation, review:

  • Evidence— information supporting the recommendation. AURA shows both what it found and what it checked but did not find. That gives you visibility into the evidence supporting the alert and the corroborating evidence that was absent, instead of hiding the investigation behind a single AI verdict.

  • How I reached this decision— agent reasoning behind its recommendation.

  • Agent trace— sub-agent and tools that participated in the run as well as their responsibilities, tool calls, and findings.

  • History — previous activity and context associated with the alert or incident.

Deciding How the Alert Should Proceed

Note: You must have the Triage Alerts permission to triage alerts. See Managing Rolesfor details.

After reviewing the request approval for an alert, select the appropriate action:

  • Promote: recommends creating an incident. Choose this when the alert represents a real security event that needs formal investigation and tracking. You can promote a single alert or select multiple related alerts to promote together into one incident. Note that this verdict does not automatically create an incident.

  • Investigate: sends the alert for further investigation before a final call is made. Use this when you suspect something is wrong but don't yet have enough evidence to promote or dismiss it. If the investigation confirms a real threat, you'll still need to approve creating an incident .

  • Monitor: keeps the alert open for ongoing observation instead of resolving it right away. Use this for alerts that aren't clearly malicious but are worth watching, For example, low-confidence signals that may escalate over time. The alert will be periodically re-evaluated and will eventually be promoted or closed, depending on what happens next.

  • False Positive: marks the alert as not a genuine security concern. Alerts classified as false positive are automatically resolved and removed from the active work queue. The decision, rationale, and supporting evidence remain part of the auditable history for later review of these alerts.

The Agent performs the initial triage and presents its findings, but you make the decision that determines how the alert moves forward.

If you choose to promote and approve the recommendation, the workflow continues automatically. The agent creates the incident, links the source alert or alerts, assigns the incident type, and hands the investigation to the Incident & Investigation Agent. See Incident & Investigation Agent for details.

Deciding How the Incident Should Proceed

After reviewing the approval details for an incident, select the appropriate action:

  • Escalate: Indicates the activity requires a coordinated response effort from a higher tier staff or external team.

  • Close: Resolves the incident indicating the activity has been handled and does not require further coordinated response.

Note: To escalate or close an incident, the Manage Incidents permission is required. For details, see Managing Access to Incidents.