From signal to action

Identity incident management

An alert indicates a condition. An incident coordinates the evidence, ownership and response to a potential material event.

Decision boundary

An alert is not yet an incident.

How an alert becomes an owned incidentA signal matches a detection and creates an alert. Assessment branches to close and tune when it is not actionable, or to an owned incident, response and learning when it is actionable.SIGNALDETECTIONALERTASSESSMENTNOT ACTIONABLECLOSE / TUNERetain evidenceACTIONABLEINCIDENTOwner · severity · contextRESPOND + LEARNAlert and incident decision pathSignal, detection, alert and assessment are stacked. Assessment branches to close and tune or to an owned incident and response.SIGNALDETECTIONALERTASSESSMENTCLOSE+ TUNEINCIDENTOwnedRESPOND + LEARNContain · remediate · improve
Alerts require assessment. Incidents require ownership, severity, an accountable response and closure evidence.

Runbook control

Automate safely. Escalate deliberately.

Human-assisted incident runbookAn incident is enriched and assessed. Safe actions may execute automatically while high-risk actions require human approval. Both paths converge on remediation, verification and closure.INCIDENTENRICHASSESSAUTOMATED ACTION?Risk + guardrail checkSAFE → EXECUTEBounded automationHIGH RISKHuman approvalREMEDIATE + VERIFYCLOSEHuman-assisted incident runbookIncident, enrichment and assessment lead to a branch between bounded automation and human approval. Both paths converge on remediation, verification and closure.INCIDENTENRICHASSESSAUTOMATED ACTION?Risk + guardrail checkSAFEEXECUTEBoundedHIGH RISKAPPROVALHumanREMEDIATE + VERIFYCLOSE + LEARN
Bounded low-risk actions can execute automatically; high-impact containment retains explicit human approval.
01

Triage and severity

Validate signal quality, affected identities and resources, current exposure and business impact before assigning severity and ownership.

02

Investigate and escalate

Build a timeline, enrich identity and authority context, identify related changes and escalate to the responsible identity, security, application or business owner.

03

Contain and remediate

Possible actions include suspending access, revoking delegated authority, correcting a policy, triggering credential revocation, rotating secrets or requiring stronger verification.

04

Runbooks with judgement

Automation can enrich incidents, create tickets, notify owners or execute low-risk actions. High-impact containment can retain explicit human approval.

05

Close and learn

Closure records evidence, actions, residual risk and owner acceptance. Lessons should improve telemetry, controls, detections and runbooks.

Apply the model

Make the signal actionable.

Start with the risk, available telemetry, accountable owner and proportionate response.

Talk to MAITS →