Ayati One — Managed Cyber Security
Ayati One workqueue · multi-analyst collaboration

Case Management & Workflow Tracking

Incidents are treated as cases with assigned owners, timelines and actions — so nothing depends on somebody remembering.

Overview

An alert is a notification. A case is a unit of work: it has an owner, a state, a history and a definition of done. The difference matters most in the situations where security teams are least able to absorb ambiguity — a shift handover at 3am, an analyst on leave, an auditor asking what happened to a specific detection eight months ago.

Ayati One's workqueue treats every incident as a case from the moment it is raised. Ownership is explicit and assignment notifies the new owner by email. Progress moves through a guarded state machine, so a case cannot skip from new to closed without passing through the states that record what was actually done.

Underneath all of it is an append-only activity log. Every assignment, transition, comment, task, attachment and field change is written with the actor and the timestamp, and it cannot be edited after the fact. That is what makes the case record usable as evidence rather than merely as a summary.

Ayati One case workflow state machine: new, acknowledged, in progress, resolved and closed, with on-hold and reopened transitions, and the owner, SLA, tasks, comments, attachments and activity log carried on every case

What's included

Case Management capabilities

  • Explicit ownership

    Every case has one accountable owner, assignable to any permitted user, with an email notification on assignment. Shared responsibility is how incidents go quiet — this removes the ambiguity about whose move it is.

  • A guarded state machine

    New, acknowledged, in progress, on hold, resolved, closed and reopened — with only the valid transitions offered from each state. A resolved case can be reopened when it comes back, keeping its entire original history rather than starting a fresh, contextless ticket.

  • Tasks and checklists

    Break a case into discrete tasks with their own owners and completion state. Containment steps, evidence collection, stakeholder notification and verification each become something visibly outstanding rather than something assumed.

  • Working notes and discussion

    Threaded comments keep the reasoning attached to the case — why a detection was judged a false positive, what was ruled out, what the affected business unit confirmed. This is the context that is otherwise lost in private chat threads.

  • Attachments and evidence files

    Screenshots, exported logs, memory captures and third-party reports are stored against the case, so the evidence set is complete in one place when an investigation is reviewed later.

  • Linked cases

    Related incidents can be linked to one another, so a campaign spanning several assets is legible as a campaign — not as a scattering of individually unremarkable alerts.

  • Watchers and targeted notifications

    Anyone who needs visibility can watch a case and receive in-portal notifications on the events that matter, with a read and read-all inbox. People who need to know are informed without being copied into everything.

  • Append-only audit trail

    A complete, immutable record of who did what and when, on every case. This is what an ISO 27001 or SOC 2 auditor actually asks for, and it is produced as a by-product of doing the work rather than reconstructed before an assessment.

  • Bulk operations

    Administrators can action many cases at once — reassign a departing analyst's queue, or close out a resolved alert storm — without touching each one individually.

  • Your existing ticketing, if you want it

    Cases can be pushed to ServiceNow or Jira, either automatically or by hand. Deliberately opt-in per tenant: teams that already live in an ITSM tool can bridge to it, and teams that do not are not forced into a second queue that immediately falls out of sync.

  • Metrics that describe the operation

    Open case load, ageing, SLA attainment and per-analyst throughput — the numbers that tell you whether the security operation is keeping up, and the ones a board actually asks about.

The rest of the platform

Scope Case Management against your environment

A 30-minute conversation with our engineers is usually enough to map your requirement to a concrete plan and honest estimate.