Skip to main content
Issues are the top-level work items in Clarion. Anything a monitor surfaces becomes an issue, and the agent watching that monitor triages it first. The agent dispositions benign and duplicate findings without you. Some low-severity repeats of a finding already triaged as benign close without a new agent run. See How triage uses past issues.

How issues get created

Two paths, depending on the monitor. Integrations that run their own detection (Okta, CrowdStrike, Microsoft Sentinel) hand Clarion a finished alert or case. Each one becomes an issue directly. Everything else sends raw events, called signals. Those become issues only when an alert filter (a signal rule) matches them. A filter can match a single event, or a sequence of events grouped by a shared field inside a time window. If signals are arriving but no issues appear, check the filters on that monitor. Clarion ships alert filter templates for every supported source. Fork one, or write your own.

What’s on an issue

  • Number: ISS-1, ISS-2, counting up per workspace.
  • Status: New, Triaging, Open, Escalated, Resolved, or Closed. See Status.
  • Kind: What the issue is: a threat, a vulnerability, a risk, and so on. See Issue kinds.
  • Disposition: The triage verdict. See Disposition.
  • Severity: Critical, High, Medium, or Low. See Severity.
  • Action required: Set when the issue is blocked on a human, either approval for a tool call or an answer to a clarification the agent asked for. This is what fills the Needs input queue.
  • Source: The integration the underlying signal came from.
  • Assignee: The member driving it.
  • Related issues: Findings linked under a shared parent. Campaign grouping and escalation chains both show up here.
  • Deduplication key: The external event ID. A redelivery carrying a key Clarion has already recorded folds into the existing issue instead of opening a second one.

Status

An agent can escalate as soon as it has enough evidence, without waiting for triage to finish.

Taking an issue off the escalated board is a human decision

Once an issue is Escalated, only a person can move it to Open or Closed, and the app asks them to confirm. An agent that tries is rejected, and the issue stays escalated. Agents can still move it to Resolved once the threat is contained. In the same way, only a person can reopen a Closed issue.

Severity

Severity grades the issue itself: Low, Medium, High, or Critical. Agents grade the severity the evidence supports and let the escalation bar decide whether it pages. They don’t raise a severity to force a page. Synthetic tests, drills, false positives, and benign noise are graded Low. With the default bar, that keeps them from paging anyone.

Disposition

The disposition records what the issue turned out to be. Issues about the same underlying problem, such as one campaign or one root cause, are grouped under a single parent instead of being tracked side by side. Each link names how the two issues relate. Linking doesn’t change anything else: every issue still gets its own disposition from its own evidence. When a new issue turns out to be the same problem as one that is already Escalated, the agent groups it under that escalated issue. Grouping is silent. The parent already notified your team when it escalated, so the child doesn’t page again, and agents are blocked from posting separate Slack or Teams messages about it. Updates go on the parent’s existing thread.

Issue kinds

Every issue carries a kind that says what it is, separate from its source (where it came from) and its severity (how bad it is).

Where the kind comes from

The kind is set when the issue is created:
  • Alert filters declare the kind of issue they fire. Every Clarion template has one, and filters generated with AI always pick one. Custom filters without a kind produce unclassified issues. A filter can’t produce Platform issues.
  • Integrations that hand over finished findings, such as Wiz or GCP Security Command Center, map each finding to a kind.
  • Manual issues require you to pick a kind in the create dialog.

How the kind is used

  • Escalation. When an agent escalates a Vulnerability or Risk, the issue stays Open and pages nobody, since these are remediation backlog rather than incidents. The one exception is a Critical finding the agent justifies as imminent danger. Every other kind follows the workspace’s Severities that escalate setting.
  • Closing. Kinds are closed on different grounds. A Threat is judged on whether there’s a real attack in your estate. An Intel item has no attack to find, so it closes once it’s been reviewed and no action is needed in your estate.
  • Finding work. The issue list can filter and group by kind, so you can separate active threats from the remediation backlog. The kind badge on an issue shows a one-line explanation on hover.

How triage uses past issues

Clarion uses earlier issues in two ways. Low-severity repeats skip triage. A new Low issue closes as Duplicated of an earlier issue, with no agent run, when the earlier issue:
  • is also Low and came from the same source (and the same monitor, when the new issue has one),
  • was created in the last 30 days, investigated by an agent, and dispositioned Benign or False Positive,
  • shares the new issue’s recurrence key.
Issues from other sources have no recurrence key and always get a full triage. The shortcut applies only to a new issue’s first triage; a manual retrigger or an escalation always runs the agent. The closed issue links to the earlier one under Related issues, and its status comment names it. To investigate it anyway, reopen it and retrigger triage. Similar issues are context, not a verdict. Before triage, Clarion finds up to five workspace issues with similar titles and gives the agent each one’s status, disposition, and the first line of its conclusion. The agent uses them to decide whether the new issue is the same underlying problem and should be grouped. It does not copy their disposition or severity. An earlier Benign result is a hypothesis the agent tests against the new evidence.

What you can do

  • Triage it yourself, or hand it to an agent for the first pass.
  • Set disposition as you confirm or rule things out. Marking one Duplicated means naming the issue it duplicates.
  • Escalate to notify on-call and move the issue to Escalated. The button only appears while the status is New or Triaging.
  • Assign to a member, and reassign as ownership moves.
  • Resolve from the issue header, or pick any status from the badge dropdown.
  • Link tasks for follow-up work that outlives the issue.
Status, severity, assignee, and disposition can each be set across a selection of issues at once from the list view.
The Escalated and Needs input queues collapse child issues under their parent, so a grouped campaign reads as one row. Apply any filter, or search, and the list goes flat. The children reappear and the count jumps; nothing new happened, the filter just stopped collapsing them.
Learn about Tasks →