Open an alert
- Go to Triage > Alerts.
- Search or filter the list.
- Select an alert to open its detail page.
Update the alert record
Analysts can keep the alert record current while triage progresses:- Click the title to rename it.
- Click the description to edit the markdown summary.
- Use the Severity menu to change severity.
- Use the Status menu to move the alert through its lifecycle.
- Add timeline comments in Activity.
Start response-agent triage
Assigning a response agent starts triage immediately.1
Choose an assignee
In the alert sidebar, open Assignee and select a response agent.
2
Cotool creates a triage run
Cotool starts a response-agent run with the alert context, recent
activity, source metadata, and alert-triage instructions.
3
Review the live run
The triage run opens in a side drawer so you can watch reasoning, tool
calls, and final output without leaving the alert.
4
Continue if needed
If the run asks for input or you want a follow-up, continue the
conversation from the drawer.
Only one response agent can actively triage an alert at a time. If a triage
run is still running, wait for it to finish or stop it from the timeline
before reassigning.
What response agents do during alert triage
When a response agent handles an alert, Cotool automatically adds alert-triage instructions to the run. The agent is expected to:- Read the latest alert context and timeline
- Investigate with its available tools
- Improve a generic title or description before changing status
- Add a final summary comment with evidence, conclusion, and gaps
- Update status before completing
- Escalate confirmed malicious or security-relevant alerts for human review
Close or reopen an alert
Close an alert by choosing one of the terminal statuses:- Closed · True Positive
- Closed · False Positive
- Closed · Benign
Mark an alert as duplicate
Use Duplicate when another alert should become the single record your team works from.1
Choose Duplicate
From the alert’s Status menu, select Duplicate.
2
Find the canonical alert
Search by alert ID or title, then choose the alert this one duplicates.
3
Confirm the link
Cotool marks the current alert as a duplicate of the canonical alert and
records the relationship in both alert timelines.
4
Continue work from the canonical alert
Duplicate alerts are archived and removed from active alert lists, so
future triage should happen on the canonical alert.
You can also mark multiple alerts as duplicates from the Alerts list by
using bulk status updates.
Permissions
Alert workflows use these permissions:
Starting triage requires both
alert.manage and agent.execute for the response agent.