Overview
The case orchestration page is the main operational workspace for managing an active case.
It brings together playbook activities, assigned responsibilities, deadlines, supporting information, comments, files, costs, and case progress in one structured view.
Use this page to coordinate the response, document decisions, and monitor the work performed by each participant.
Page layout
Case progress
The phase bar at the top of the page shows the current position of the case across the incident lifecycle:
- Detection
- Containment
- Remediation
- Recovery
The phase indicators help users identify completed, active, visited, and upcoming phases.
Playbook activities
The central area displays the playbook steps assigned to the case.
Each activity may include:
- The activity title and instructions
- The assigned participant or role
- Available answers or completion options
- Hints and supporting guidance
- Target completion time
- Related standards or controls
- Files, comments, and costs
- Notification and sharing options
The information shown may vary according to the playbook item and the user's permissions.
Activity ownership
The participant responsible for an activity is shown above the item.
Case leaders may also be able to review or answer activities assigned to other participants when operationally necessary.
Supporting information
Each activity can include additional operational records:
- Item Files for evidence and supporting documents
- Item Comments for discussion and contextual information
- Item Costs for financial impacts or response expenses
These records remain associated with the relevant activity and contribute to the overall case record.
Activity details
The panels displayed beside an activity may show:
- Activity type
- Playbook category
- Target completion time
- Regulatory or framework references
- Notification settings
- Sharing and assignment controls
These details help participants understand the purpose, urgency, and governance context of the activity.
Case navigation
The case menu provides access to the other operational areas of the case, including:
- AI Advisor
- Edit Case
- New Impact
- New Step
- New Timer
- Playbooks
- Case Content
- Timeline
- Full Summary
- Export
- Close
- Reports
- Analytics
- Audits
- Audit Log
The available options depend on the user's permissions, assigned role, tenant configuration, and product edition.
Completing an activity
- Review the activity title, instructions, hints, and supporting information.
- Add any required files, comments, or costs.
- Select the appropriate answer or completion option.
Operational considerations
- Record decisions and supporting information as work is performed.
- Avoid entering unsupported conclusions simply to complete an activity.
- Add comments when an answer requires context or qualification.
- Attach relevant evidence to the activity rather than storing it outside the case.
- Review target times and warnings regularly during an active incident.
- Confirm that sensitive information is only accessible to authorized participants.
Related articles
- Case orchestration :: Details
- Case orchestration :: Summary
- Case orchestration :: Activities
- Case orchestration :: Impacts
- Case orchestration :: Timeline
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article