Skip to content

Dashboard

The Dashboard is the first screen you see after signing in. It provides a consolidated view of your incident management workflow in the current tenant.

Four key performance indicators at the top of the page:

KPIDescription
Open IncidentsCount of incidents in “Open” status
In ProgressIncidents currently in “In Progress” status
Closed (30d)Incidents closed or resolved in the last 30 days
Evidence ItemsTotal artifacts uploaded to active incidents

Each card shows a delta chip when available (e.g., “+3” or “-1” compared to the previous period).

A searchable, filterable table of all incidents in the tenant:

  • Search — Filter by title or ID
  • Status chips — Filter by All, Open, In Progress, Closed, Resolved
  • Table columns — ID (truncated), Title, Status badge, Severity badge, Created (relative time)
  • Click any row to jump to the incident detail page

Empty state: “No incidents yet — Start tracking security incidents by creating your first one.” with a “Create your first incident” button.

A timeline of the most recent evidence uploads from active incidents:

  • Shows filename, uploaded by, and relative timestamp
  • Up to 10 items from the 3 most recent non-closed incidents

Empty state: “No evidence uploaded yet”

Quick-access runbook templates for common incident scenarios:

  • Ransomware Response Runbook
  • Phishing Investigation Guide
  • Data Breach Notification
  • Endpoint Isolation Playbook

Playbooks are currently static reference links.

  • Cmd+I — Create a new incident immediately
  • Cmd+K — Open the command palette to search incidents and navigate pages
  • “New Incident” — Button in the header

On large screens, the dashboard uses a 3-column grid:

  • Left two-thirds: KPI Cards + Recent Incidents
  • Right third: Evidence Activity + Playbooks
  • Check the Dashboard daily to catch overdue milestones early
  • The overdue count badge in the sidebar is always visible
  • Use the command palette (Cmd+K) for the fastest navigation