M ManySignal

Case Management

A SOC case, not a repurposed JIRA ticket

When an escalation warrants investigation, ManySignal creates a numbered case with a priority level, SLA clock, assigned analyst, and an immutable timeline pre-populated with the triage verdict, entity graph snapshot, and correlated findings — before a human opens it.

Anatomy of a ManySignal case

Case header

Case number, severity (P1–P4), SLA deadline, assigned analyst, and current status. SLA clock starts at first alert time, not at case creation.

Triage verdict

The AI triage verdict with confidence score, contributing signal weights, and the full reasoning trace — collapsed by default, expandable to full text.

Entity graph snapshot

A read-only snapshot of the involved entities' graph state at detection time: relationships, blast radius, open findings, and behavioural deviation scores.

Immutable timeline

Every action — analyst note, automated action, approval, rollback, status change — appended to the timeline with timestamp and actor. No edits, only additions.

Correlated findings

Other active findings touching the same entities, within the same time window, or from the same attack chain are linked automatically and visible in a sidebar.

Evidence attachments

Raw log excerpts, screenshots, external reports, and PCAP references are attached to the case and included in the final evidence export.

SLA management that reflects actual risk

SLA deadlines are set per severity level, configurable per tenant. The SOC dashboard shows active SLA breaches in red, at-risk cases in amber, and healthy cases in green. Analysts can request a SLA extension with a mandatory reason — the extension and reason are logged to the case timeline.

Cases that breach SLA generate an escalation notification to the team lead and are automatically flagged in the weekly SLA report. SLA performance is tracked per analyst, per detection type, and per tenant for MSSP billing and reporting.

What case management handles automatically

Pre-populated context

Cases open with triage verdict, entity snapshot, and correlated findings already attached. Analysts start from context, not from a blank ticket.

Automatic analyst assignment

Assignment rules route cases by shift schedule, analyst workload, alert type, and entity criticality. Round-robin, weighted, and skill-based routing are all configurable.

Bi-directional JIRA/ServiceNow sync

If your organization requires ticketing system records, cases sync bi-directionally. Notes added in JIRA appear on the ManySignal timeline and vice versa.

Attack chain linking

When a case is opened, the investigation agent links it to any open cases touching overlapping entities within the last 72 hours — so related incidents are not investigated in parallel isolation.

Evidence export

A case can be exported to a structured PDF or JSON bundle including all timeline events, evidence attachments, entity snapshots, and action logs — suitable for legal hold or post-incident review.

Metrics and reporting

Mean time to detect, mean time to respond, SLA compliance, case volume by severity, and analyst throughput are available as built-in dashboards or exportable to your SIEM or BI tool.

Case Management — FAQ

Can cases be created manually, not just from alerts?

Yes. Analysts can create a case from scratch, from a threat hunt finding, or by promoting a finding that did not trigger automatic escalation. Manual cases have the same timeline, SLA, and evidence capabilities as automated ones.

How are duplicate cases handled?

When a new finding matches the entity and detection type of an open case within a configurable window, it is appended to the existing case rather than creating a duplicate. You can configure merge vs. link behavior per detection type.

Is the case timeline truly immutable?

Yes. Timeline entries are append-only and stored with a cryptographic hash chain. Corrections are added as new entries with a reference to the entry being corrected — the original entry is never modified or deleted.

Does ManySignal replace my ticketing system?

For SOC-specific workflows, yes. For organization-wide IT ticketing, it integrates with your existing tools. Most teams use ManySignal cases as the source of truth for security incidents and sync a read-only ticket to JIRA or ServiceNow for visibility.

How does case management handle regulatory notification deadlines?

SLA clocks can be mapped to regulatory notification windows — 72-hour GDPR, 60-day HIPAA, etc. The SOC dashboard surfaces approaching regulatory deadlines separately from SLA status. Pre-formatted notification drafts are generated automatically when a case approaches a regulatory threshold.

Can MSSP customers see cases across client tenants?

Yes. Multi-tenant case management gives MSSP analysts a cross-tenant view filtered by client, severity, and SLA status. Client tenants are fully isolated — an analyst can see only the tenants their role permits. Per-client reporting includes SLA performance and case volume metrics.

How is analyst workload balanced across the team?

Assignment rules support round-robin, weighted by seniority, skill-based routing by detection type, and on-call schedule integration. The team dashboard shows open case count and SLA health per analyst so team leads can rebalance load in real time.

What does the evidence export bundle contain?

A case export bundle includes: the case summary, full immutable timeline (all events, notes, actions), entity graph snapshots at detection and investigation time, attached evidence files, response action audit records, and operator attestation signatures. Available as structured JSON or human-readable PDF.

How does ManySignal calculate mean time to respond (MTTR) for reporting?

MTTR is calculated per case from first-alert time to case-closed timestamp, excluding approved SLA pauses. The metrics dashboard breaks MTTR down by severity, detection type, analyst, and month — exportable for executive reporting or auditor review.

Cases that come pre-investigated

See how a P2 case opens with entity graph, triage verdict, and correlated findings already inside.