Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Handle security incidents using Advanced Work Assignment

Handle security incidents assigned to you in SIR Workspace using Advanced Work Assignment.

Before you begin

Role required: sn_si.analyst and awa_agent

Procedure

  1. Navigate to Workspaces > Security Incident Response Workspace.

  2. Select the Inbox button.

  3. Indicate your availability status by selecting your presence state in the Status field.

    The available presence states are:

    • Available: You’re available and can accept security incidents. Whether you’ll be assigned incoming incidents is based on the configured service channel, queues and assignment rules.

      Note: If auto-assignment has been enabled, security incidents are directly assigned to you.

    • Away: You aren’t available to accept assignments of incoming incidents.

    • Offline (the default): You’re offline and aren’t available to accept assignments of incoming incidents.
    • Accept or reject a security incident assignment.

    Note: If rejection handling hasn’t been enabled in AWA, the Reject option isn’t available.

    • Accept the incident by selecting Accept.

      The incident is assigned to you.

    • Reject the incident by selecting Reject and select a reason for the rejection.

Parent Topic:Using SIR Workspace

Related topics

Working with Security Incident Records

Security Incident Playbook

Prerequisites for the Playbooks

Rebuilding existing playbooks in Workflow Studio

Activity Definitions

Sample Playbooks for SIR Workspace

Working with MSI Records

Working with Form UI actions

Security Incident Closure workflow