Operations

Visual guide from alerts to reports

Follow an observed change through notification, operator context and scoped reporting.

Keep the evidence together

The operational path starts with a completed check and its timestamp. Notification preferences and deduplication determine delivery, while notes and authorized remote work record follow-up. Reports summarize a selected scope and period. This is a conceptual guide, not a capture of an actual customer incident.

Illustrative flow from completed check through alert, operator follow-up and scoped reportIllustration only. No live incident, customer note or report data is shown.

Operator checklist

  1. Confirm the affected asset, workspace, check result and freshness.
  2. Review alert history and delivery preferences. A deduplicated message is still an active condition until evidence says otherwise.
  3. Record follow-up in the approved notes or operational workflow; do not copy secrets into notes or public screenshots.
  4. Generate a report for the authorized recipient and selected time range. Verify asset scope and missing coverage before sharing.

Remote tools such as Terminal and Fleet Runner require their own authorization and audit path. See alert investigation, scoped reports, and terminal safety.

Before taking action

Confirm the active workspace, required permission, registered asset, and freshness of the data being used.

← Back to documentation