Incidents are in beta and are available to the Super Admin, Security Admin, and IT Admin roles.
How It Works
Incidents do two things: group noisy signals into a handful of items, and let you take action on each one without leaving the view. Grouping — Runlayer continuously folds new security signals into persistent incident records, so related signals appear as one item rather than many. Each incident accumulates counts over time and carries aggregated context — top actors, clients, devices, and a trend sparkline. Incidents are ranked so the most urgent surface first, based on how severe, how frequent, how recent, and how widespread the activity is. Taking action — From the inbox or an incident’s detail view you triage (resolve, snooze, dismiss) and remediate in one click (tune scanners, block tools or actors, disable connectors, manage shadow assets). Every action is scoped to the incident and enforces the same permission as the underlying change.Incident counts are cumulative — an incident reflects everything seen since it was first opened, not just the current view window. Triage state is organization-level: resolving an incident resolves it for everyone. Idle incidents with no new activity are eventually cleaned up automatically.
Incident Sources
Each incident belongs to one source bucket, which drives the chips and remediation actions shown:The Inbox
Open Incidents from the sidebar to see every grouped incident in one ranked list, highest-priority first. Filter by type (Violations, Shadows, Session alerts), severity, scanner, client, server, or user, and sort by priority, recency, age, event volume, or number of users affected. Each row summarizes the incident at a glance: a trend sparkline, what the scanner did (blocked, masked, or allowed), the client involved, and a severity indicator.Triage
Triage is organization-level — resolving an incident resolves it for everyone — and can be applied to a single incident or in bulk. The inbox has a tab per state (Unresolved, Snoozed, Resolved, Dismissed, All); these actions move incidents between them:Incident Detail
Open an incident to see its activity feed (lifecycle events — created, triaged, remediated — each with actor and timestamp), the affected users (top actors), clients, and devices driving it, and a handful of sample events — recent audit log entries that compose the incident. Top actors are the users and agents most frequently involved in the incident’s underlying events, each with a per-actor event count derived from the audit log. Beyond the top list, every incident tracks an exact count of distinct users affected — the inbox can sort by it — and the Block actors remediation targets these top users and agents directly.Remediation Actions
Incidents offer one-click remediation scoped to the incident’s type and scanner. Each action enforces the same capability as its underlying mutation, so the incident view is never a privilege bypass.Violation incidents
Violation actions fall on a spectrum from dialing a noisy scanner down to escalating a real threat:
Scanner-wide and per-rule actions collapse into “Downgrade … to ›” / “Escalate … to ›” menus relative to what’s enforced today, so you only ever see targets that would actually change something. Downgrading a rule all the way to allow is how you stop flagging that one type without touching the rest of the scanner.
There’s also Configure scanner settings, which jumps to the Security Scanners admin page. The available actions are narrowed to what makes sense for the incident’s scanner — e.g. per-rule retuning only appears for PII detection and credential scanning, and per-server tuning is hidden for serverless / local-stdio groups.
Shadow incidents
Remediation actions are idempotent. Re-running an action that’s already in effect (e.g. a deny policy that already exists) reports no change rather than creating duplicates.
Auditability
Every incident lifecycle event — creation, triage (resolve / snooze / dismiss / clear), and remediation action — is written to the audit log. Lifecycle events (except idle cleanup) also trigger a Slack notification if your org has Slack connected and is using the incident notification format.Related Resources
Security
Security alerts and scanner configuration
Shadow AI
Detect and enforce on shadow MCP servers and skills
Policies
Allow and deny rules for tools and actors
Audit Logs
Full activity and access history