Skip to content
SmiKar Software

Investigations (Cases)

4 min read · Last updated · Page version 1

An incident is rarely one alert. A bulk download, a behavioural deviation and an out-of-hours flag on the same account within an hour are three rows in the Alerts page and one event in reality. The Investigations page - labelled Cases in the left navigation - is where Burrow groups them so you work the incident rather than the rows.

Investigations page listing clustered cases with status, severity, assignee and linked alert counts

The case list

Each row is a cluster of related alerts on the same entity within a short window, auto-narrated by AI as an attack-chain summary - which is what stops three related alerts arriving as three separate emails.

Columns: title, status, severity, linked alert count, notes count, assignee, and last update. Status chips at the top narrow to Open, In progress or Closed. A CSV button exports the filtered list.

The case detail page

Clicking a case opens its detail view.

Investigation detail page showing the case summary, linked alerts, the analyst notes thread, and the cross-alert investigation chat

  • Header - the case ID, who created it and when, and when it was last updated.
  • Status, severity and assignee - editable in place. Status is open / in progress / closed.
  • Summary - free text, editable. The "what are we actually investigating" line.
  • Linked alerts - every alert attached to the case, each showing its category and user. Click a user to open the entity drill drawer without leaving the case; unlink one if it turns out not to belong.
  • Notes - an append-only thread with the author and timestamp on each entry. This is the case's working record.

Alerts are attached from the Alerts page using the link to case action on any row.

The investigation chat

Beneath those sits the Investigation chat, and it is the part that makes a case more than a folder.

Ask a question once and it is answered across every alert linked to the case rather than one alert at a time - "is this consistent with the user's normal behaviour?", "did any of it leave the tenant?". The answer draws on all the linked alerts' evidence together, which is exactly the comparison you would otherwise do by hand across several drawers.

The Q&A is kept on the case, so whoever opens it next sees the reasoning that has already been done rather than repeating it. On a case handed between shifts, that thread is usually the fastest way in.

How this differs from the per-alert chat

Both are AI Q&A, scoped differently:

  • Per-alert chat - one alert. "Why did this fire?"
  • Investigation chat - every alert on the case. "Do these add up to something?"
  • Identity chat - one person across time. "What is normal for them?"

When to open a case

  • More than one alert on the same account in a short window - the case is the shape of the incident.
  • Anything you will hand over - to another shift, to HR, to legal. The notes thread and chat history are the handover.
  • Anything that may be asked about later. The case is an append-only record of what was known and decided, and when.

You do not need a case for a single alert you resolve in two minutes. Dispose of it on the row and move on.

See also


Need help? support@smikar.com.

More in Squirrel

See all pages →