Risk review

Triage flagged activity, mark an assessment, and reopen a finding when new evidence changes the conclusion.

On this page

Risks shows flagged workspace events for investigation. It is an assessment workflow, not a command approval queue. Owners, administrators, and security managers can mark records reviewed or reopen them. Auditors can inspect activity read-only.

Work through open findings

  1. Open Risks → Open in the intended workspace.
  2. Inspect the finding summary, severity, agent, and timestamp.
  3. Locate related activity and local evidence when needed.
  4. Determine what was proposed, what was observed, and which effects remain unverified.
  5. Choose Mark reviewed after completing your assessment.

The list shows the latest 200 matching records, not an unlimited incident history. A low count can reflect filters, retention, or delivery gaps rather than a complete absence of risk.

Assess severity in context

Severity describes a heuristic match. It does not establish malicious intent or successful execution. For example, a command mentioned in documentation can resemble an instruction to execute that command. Read the surrounding artifact and the agent's actual action before drawing a conclusion.

Record supporting evidence in your team's incident workflow when more detail is needed. Beam's review toggle is not a complete case-management record and does not itself remediate a device.

Reopen a reviewed finding

Open Reviewed, locate the event, and choose Reopen if new evidence warrants another look. Both review and reopening are recorded in the administrative audit log. Read-only users see the status without a mutation control.

Marking reviewed does not remove the underlying event, disable the detection rule, change policy, or acknowledge that a risky command was safe to run.

Correlate local and shared views

Studio also has a local reviewed marker. Connected review updates are forwarded best-effort; network failures can leave views out of sync. Verify the record in the system relevant to your team's workflow instead of assuming immediate propagation.

For an incident, preserve a redacted local export and the original supporting evidence before local retention or offboarding removes it. Use Audit log to verify who changed the administrative review state.

Explore the docs