Guide
Triage a finding
Inspect affected entities, timing, severity, supporting sessions, and technical context before acting.
Last reviewed September 12, 2026
Inspect issue details
Open an issue to review its description, severity, affected page or resource, first and last seen times, recommended action, technical details, linked sessions, and raw record where available. Compare the finding with expected behavior and current resource version before choosing a lifecycle action.
Procedure
- 1.
Open the correct project and page
Use the project selector to choose the website you intend to review, then open Issues in the left navigation. Confirm the organization, project, and monitored domain before interpreting a record or changing a control.
- 2.
Preserve the original signal
Record the finding link, current status and severity, affected entity, first and last observation, relevant session, and recent deployment context before changing disposition or detection settings.
- 3.
Impact
Compare the signal with the affected entity, linked session, timing, and expected behavior before setting its disposition.
- 4.
Affected resource
Confirm the URL or domain, provider association, first and last observation, and the project in which the entity was recorded. Open the linked detail record; a display name or enrichment label is not proof of ownership or approval.
- 5.
Evidence
Preserve source, time, project, and transformation context and separate the technical record from the reviewer’s conclusion.
- 6.
Reproduce and compare
Repeat a representative journey when safe, then compare the new session and source records with the original finding. Verify that the selected disposition describes the reviewed evidence.
- 7.
Record the decision trail
Preserve the original finding, supporting records, expected behavior, owner, disposition, rationale, and follow-up. A workflow-state change must not replace the evidence used to reach it.
Inspect an anomaly
Open an anomaly to review the detected deviation, severity, affected resource, timestamps, behavioral analysis, sensitive access, network activity, detailed events, linked session or policy context, and raw record. Determine whether it is expected, unexplained, or actionable before acknowledging or closing it.