Skip to main content
You review the cases a workflow could not decide on its own. Everything you need sits in four places: the Dashboard for the overall picture, the Decision Queue for what is waiting, the Decision Console for the evidence and the decision, and Cases to find anything at any stage.

What you see when you sign in

The badge on Decision Queue is the number of cases waiting for a decision. It refreshes about once a minute and whenever you return to the tab. ⌘K opens a search palette that jumps to any page.

A day in the queue

1

Open the Decision Queue

Cases waiting for an analyst are listed by time in queue. High-risk and critical (over two hours) counts sit at the top. Decision Queue
2

Open a case and claim it

Press Enter on a highlighted row. Claiming locks the case to you so two analysts never decide the same case. Claim a case
3

Read the evidence

Subject, transaction, risk assessment, data-source results, discovered identifiers and the activity timeline. Read the evidence
4

Ask the customer if something is missing

Request Information sends a templated email through your company’s systems and parks the case as awaiting information. Request information
5

Decide

Approve, Decline with a reason, or run a workflow action your engineers declared. The console moves to the next case. Approve, decline or run a workflow action

What you cannot do here

  • Escalate, hold, snooze or reassign are not console actions. Escalation, when your tenant needs it, is a workflow action declared on the Review node (for example Escalate to senior), so it appears under Workflow actions only when the flow defines it.
  • Reopen or re-run a decided case is not possible. A senior analyst or manager can override the final decision, which records a new audited decision without re-running the workflow.
  • Export PDF, allowlists and blocklists do not exist in the console.

Keyboard cheat sheet

Queue Console

Pages in this guide

Dashboard

Decision Queue

Decision Console

Cases

Team (view)

Settings for analysts