Understanding cases in federated view

Prev Next

A managed security service provider (MSSP) can deploy and maintain Helix Enterprise for multiple organizations. For security and privacy, each organization requires a separate Helix Enterprise environment.

Note

In this document, the MSSP is the "parent organization" and its managed organizations are "child" organizations.

The Helix Enterprise Cases page centralizes cases across these organizations into a single federated view.

The top part of the federated view Cases page contains widgets that allow you to filter by organization and view the status of open cases, users with the most case assignments, and cases by priority over time.

The table at the bottom part of the federated view Cases page offers the features provided on the standard Cases page (described in the topics in Understanding cases).

It also contains an Organization column to sort cases by organization. There is a menu at the end of each child case row. The same options are available for cases from both parent and child organizations.

To view and take actions from the federated view Cases page:

  1. Log in to a parent organization's instance as a user with the "Tap Federated Group" access permission.

  2. From the main menu, select Investigate > Cases.