Find pressure in the queue.
Review open cases, aging and service-level risk. Open supported metric tiles to inspect the underlying cases before deciding what needs attention.
Imperum brings workload, response approvals, reporting and supervised case review into one operational platform. Give your SOC leaders a clear view of the work, control over consequential decisions, and evidence they can take into the next review.
Example tenant · current snapshot
Generate the configured report and retrieve the resulting file in History. Review its content before sharing it with leadership.
A queue total tells you how much work exists. Platform KPI helps you understand its age, priority, ownership and outcomes, so the next staffing or process discussion starts with the cases behind the numbers.
Review open cases, aging and service-level risk. Open supported metric tiles to inspect the underlying cases before deciding what needs attention.
Explore resolution, routing, analyst activity and shift views. Select a reporting window and export KPI data as CSV or Excel for further analysis.
Views use authorized tenant scope. Current backlog and historical activity answer different questions; large datasets can be subject to query limits.
Explore the case workflowUse configured approval steps in Automatio to pause a response workflow for review. The approver can inspect the requested action, affected assets and context before choosing the next branch.
A case investigation requests containment of LAB-WS-07. Check the evidence and business impact before permitting the configured response branch.
Approval follows the configured approval branch. Rejection follows the configured rejection branch. The response result is checked separately.
The approval record stores the decision, authenticated actor, timestamp and any reason. Review that record separately from the eventual action result.
Approval rules differ across playbooks and agents. Review each capability’s permissions and policy before enabling automated changes.
Build an executive summary, daily SOC brief or client report from reusable widgets. Choose the scope, period and format, then generate a file or set up a subscription for recurring delivery.
Start with a built-in template or create your own. Combine metrics with text, tables and charts. Use framework-specific templates to organize evidence for a compliance review. History lists completed and failed runs and provides downloads for available files.
Filter the Audit Log by actor, action, resource, result or date, then export matching records as CSV or JSON. Inspect case evidence in Casebook when the question concerns an incident.
| Time | Actor | Action | Resource | Result |
|---|---|---|---|---|
| 09:41 | Example analyst | Updated | CASE-DEMO-24 | Success |
| 10:06 | Example reviewer | Updated | CASE-DEMO-24 | Success |
Reuse the reporting setup. Spend the review explaining exceptions and next steps, with a consistent format and the relevant records close at hand.
Magister connects junior analysts with mentors. When an analyst in an active mentorship proposes closing a case they own or are assigned to, the case goes to their mentor for review.
The analyst submits their case conclusion.
The assigned mentor checks the work and gives feedback.
Approval closes the case. A request for changes keeps it open for rework.
Coach at the point of decision. Review and rework become part of case handling, giving the team a concrete way to improve investigation quality.
Magister requires the relevant licensed capability and permissions. This closure gate applies to active mentorships and eligible owned or assigned cases.
Choose the tenant and reporting period. Identify the workload question, the response that needs oversight, and the evidence your audience expects. Then configure the report and review workflows around those responsibilities.
Available modules and actions depend on your Imperum license, assigned permissions and configuration. Scheduled email delivery also requires the deployment’s email service.
No. The illustration uses synthetic data to explain the workflow. Your operational metrics depend on the cases, activity, scope and period in your deployment. No customer savings or performance result is claimed here.
Approval behavior depends on the capability, permissions and configured policy. An Automatio approval step routes the workflow through its configured approval or rejection branch. Approval does not establish that the response action succeeded.
Yes. Reports and KPI views use authorized tenant scope. Cross-tenant reporting requires additional authorization; it is not enabled simply by choosing a report template.
Check the tenant, time range, included widgets and generated content. Reports read data at generation time. PDF output requires an available PDF renderer; otherwise generation can produce HTML. Download the available file from History and check that it fits the review’s purpose.
A report or audit export supplies records for your review. Your governance team still needs to assess whether the evidence answers the control or requirement being examined. Audit exports and generated reports are separate outputs.
Have any other questions?
Talk to our team
See how workload, approvals and reporting can support your SOC’s next operational review.