Risk review
Triage flagged activity, mark an assessment, and reopen a finding when new evidence changes the conclusion.
On this page
Risks shows flagged workspace events for investigation. It is an assessment workflow, not a command approval queue. Owners, administrators, and security managers can mark records reviewed or reopen them. Auditors can inspect activity read-only.
Work through open findings
- Open Risks → Open in the intended workspace.
- Inspect the finding summary, severity, agent, and timestamp.
- Locate related activity and local evidence when needed.
- Determine what was proposed, what was observed, and which effects remain unverified.
- Choose Mark reviewed after completing your assessment.
The list shows the latest 200 matching records, not an unlimited incident history. A low count can reflect filters, retention, or delivery gaps rather than a complete absence of risk.
Assess severity in context
Severity describes a heuristic match. It does not establish malicious intent or successful execution. For example, a command mentioned in documentation can resemble an instruction to execute that command. Read the surrounding artifact and the agent's actual action before drawing a conclusion.
Record supporting evidence in your team's incident workflow when more detail is needed. Beam's review toggle is not a complete case-management record and does not itself remediate a device.
Reopen a reviewed finding
Open Reviewed, locate the event, and choose Reopen if new evidence warrants another look. Both review and reopening are recorded in the administrative audit log. Read-only users see the status without a mutation control.
Marking reviewed does not remove the underlying event, disable the detection rule, change policy, or acknowledge that a risky command was safe to run.
Correlate local and shared views
Studio also has a local reviewed marker. Connected review updates are forwarded best-effort; network failures can leave views out of sync. Verify the record in the system relevant to your team's workflow instead of assuming immediate propagation.
For an incident, preserve a redacted local export and the original supporting evidence before local retention or offboarding removes it. Use Audit log to verify who changed the administrative review state.