Message Investigations (Cases)

Written By Matt Sywulak

Last updated 5 days ago

Message Investigations lets you group related messages into cases, track them through triage, and remediate them together. It's the case-management view on the Triage page.

Message Investigations is a gated beta feature and will be rolling out slowly through Q3

Finding Message Investigations

Open Triage from the main navigation, then select the Message Investigations tab. The tab shows a live count of open (pending) cases for the selected team, and a summary card above the list breaks pending cases down by Critical and High. You can also deep-link straight to it with /triage?t=cases.

[Screenshot: Triage page with the Message Investigations tab selected]

The cases list

Each row is a case. Columns: Case, Details, Priority, Severity, Type, and Status. The list is server-paginated at 20 cases per page with Previous / Next controls.

Use Sort by to order the list by Date, Severity, or Priority, with an ascending/descending toggle. The list also respects the timeframe selected at the top of the Triage page.

Editing case fields

Priority, Severity, and Type are shown as pills you can click to change inline:

  • Priority: Low, Normal, High, Urgent.

  • Severity: Info, Low, Medium, High, Critical.

  • Type: Classification, False positive, False negative, Delivery issue, Followup.

The case title and details are also editable in place (pencil icons). For closed cases, Status can be edited as well.

Working a case

Click a case to expand it in place. The expanded view shows the case's messages (newest first, paginated 20 per page), with a both / inbound / outbound direction filter. Each message row shows the date, sender, subject, an optional verdict, and a user-report tally, plus actions to find similar messages, view message details, remove from case, and remediate. Expand a message's User Reports group to confirm, reject, or un-confirm individual reports.

Remediating a case

You can remediate an entire case at once or a single message.

  • Remediate case β€” the shield button on a case row opens the Remediate case wizard, which acts on all still-open messages in the case. The flow adapts to the case Type (for example, a False positive case marks its messages safe; a False negative case is limited to spam/phish then delete).

  • Remediate message β€” each message inside a case has its own shield button to remediate just that message.

In the wizard you pick a verdict (Safe, Spam, or Phish). For Spam/Phish there's an optional Find and delete these messages? step that searches recipients' mailboxes and deletes inbound copies in the background. You can also choose Resolve without remediating to close the case without acting on messages. Finish with Start Remediation (or Finish).

[Screenshot: Remediate case wizard]

Allow-list and block-list actions are available only when remediating a single message, not in the case-wide flow.