Incidents are in beta and are available to the Super Admin, Security Admin, and IT Admin roles. If you don’t see Incidents in the sidebar, contact your Runlayer account team to enable it.
How It Works
Incidents do two things: group noisy signals into a handful of items, and let you take action on each one without leaving the view. Grouping — A background worker (~1-minute cadence) folds new audit events into persistent incident records. Related signals roll up by a stable key (connector, scanner, violation reason, subtype), counts accumulate over time, and each incident carries aggregated context — top actors, clients, devices, and a trend sparkline. A priority score (severity, volume, recency, and breadth) floats the most important incidents to the top. Taking action — From the inbox or an incident’s detail view you triage (resolve, snooze, dismiss) and remediate in one click (tune scanners, block tools or actors, disable connectors, manage shadow assets). Every action is scoped to the incident and enforces the same permission as the underlying change.Incident counts are cumulative — an incident reflects everything seen since it was first opened, not just the current view window. Triage state is organization-level: resolving an incident resolves it for everyone. Idle incidents with no new activity are eventually cleaned up automatically.
Incident Sources
Each incident belongs to one source bucket, which drives the chips and remediation actions shown:The Inbox
Open Incidents from the sidebar to see every grouped incident in one ranked list, highest-priority first. Filter by type (Violations, Shadows, Session alerts), severity, scanner, client, server, or user, and sort by priority, recency, age, event volume, or number of users affected. Each row summarizes the incident at a glance: a trend sparkline, what the scanner did (blocked, masked, or allowed), the client involved, and a severity indicator.Triage
Triage is organization-level — resolving an incident resolves it for everyone — and can be applied to a single incident or in bulk. The inbox has a tab per state (Unresolved, Snoozed, Resolved, Dismissed, All); these actions move incidents between them:Incident Detail
Open an incident to see its activity feed (lifecycle events — created, triaged, remediated — each with actor and timestamp), the affected users (top actors), clients, and devices driving it, and a handful of sample events — recent audit log entries that compose the incident. Top actors are the users and agents most frequently involved in the incident’s underlying events, each with a per-actor event count derived from the audit log. Beyond the top list, every incident tracks an exact count of distinct users affected — the inbox can sort by it — and the Block actors remediation targets these top users and agents directly.Remediation Actions
Incidents offer one-click remediation scoped to the incident’s type and scanner. Each action enforces the same capability as its underlying mutation, so the incident view is never a privilege bypass.Violation incidents
Violation actions fall on a spectrum from dialing a noisy scanner down to escalating a real threat:
There’s also Configure scanner settings, which jumps to the Security Scanners admin page. The available actions are narrowed to what makes sense for the incident’s scanner — e.g. PII-label opt-out only appears for PII detection, and per-server tuning is hidden for serverless / local-stdio groups.
Shadow incidents
Remediation actions are idempotent. Re-running an action that’s already in effect (e.g. a deny policy that already exists) reports no change rather than creating duplicates.
Auditability
Every incident lifecycle event — creation, triage (resolve / snooze / dismiss / clear), and remediation action — is written to the audit log. Lifecycle events (except idle cleanup) also trigger a Slack notification if your org has Slack connected.Related Resources
Security
Security alerts and scanner configuration
Shadow AI
Detect and enforce on shadow MCP servers and skills
Policies
Allow and deny rules for tools and actors
Audit Logs
Full activity and access history