SafeToOpenEmail Security Docs

SafeToOpen Browser Security

Incidents, alerts and integrations

What becomes an incident, severities, alert cadence, and feeding events to ticketing and SIEM tools

Guide 5 of 7 · April 2026

1. What becomes an incident#

KindSourceSeverity
User reportThe person clicked Report in the panelHigh
User report (false positive)The person disputed a verdictLow
Auto-forwarded by policyAuto-forward policy sent a Dangerous message to the report inboxHigh
Dangerous verdictScan score in the dangerous bandCritical when the score is very low, otherwise High
Suspicious verdictScan score in the caution bandMedium
Executive impersonationDeeper Analysis alert zone on an Executive seatCritical
Executive reviewDeeper Analysis review zoneMedium

The same message seen again within 24 hours updates the existing incident rather than creating a second one. When automatic Deeper Analysis is enforced, the quick scan and the analysis produce one merged incident. Incidents carry the sender, subject, reasons and workspace, never the message body; the original email is not stored.

2. Alerts#

  1. Settings → Incident alerts: recipients, cadence (real time, daily, weekly) and minimum severity for the organisation.
  2. Workspaces → a workspace → Alert recipients to route that workspace’s alerts elsewhere, for example to an MSP client contact.
  3. Alert emails link to the incident in the console; analysts open it directly.

3. Responding to a confirmed incident#

Every incident detail ends with a Response panel. Once a Microsoft 365 connector exists (guide 7), the panel shows which actions will run when you click Confirm issue, offers each action for a one-off manual run, and lists what has already been done with an Undo where the action is reversible. Typical rules: on Confirm at severity high, junk the sender in the affected mailbox; for executive impersonation, junk the sender for every member; where the person clicked through and entered credentials, sign them out everywhere and require a password change.

4. Integrations#

Console → Integrations (Email Security) offers the same three routes as Browser Security, scoped to Email Security events: pull with an export token, push with a signed webhook, and email-to-ticket via the alert recipients. Event type email_security.flagged_event; formats JSON, OCSF, ECS and CEF; STIX indicators for sender addresses and domains; write-back of triage status from your ticketing tool.

Reference: https://plus.safetoopen.com/docs/browser-security/integrations/reference.html.

The Browser Security side has the same response framework plus a hosted blocklist for firewalls; see https://plus.safetoopen.com/docs/browser-security/integrations/response-actions.html.