> For the complete documentation index, see [llms.txt](https://docs.lightbeam.ai/lxqobxw6ak7CTnsQjikH/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.lightbeam.ai/lxqobxw6ak7CTnsQjikH/core-features/spectra-ai/playbooks/policy-and-alerts/levels-of-actions-on-alerts.md).

# Levels of Actions on Alerts

Actions can be performed at four different levels, providing flexibility in alert management:<br>

[#id-1.-individual-sub-alert-actions](#id-1.-individual-sub-alert-actions "mention")

├ [#i-resolving-sub-alerts](#i-resolving-sub-alerts "mention")

├ [#ii-reassigning-sub-alerts](#ii-reassigning-sub-alerts "mention")

├ [#iii-adding-sub-alerts-to-no-scan-list](#iii-adding-sub-alerts-to-no-scan-list "mention")

├ [#iv-adding-sub-alerts-to-permit-list](#iv-adding-sub-alerts-to-permit-list "mention")

└[#v-muting-sub-alerts](#v-muting-sub-alerts "mention")\
\
[#id-2.-batch-sub-alert-actions](#id-2.-batch-sub-alert-actions "mention")

[#id-3.-multiple-alert-level-actions](#id-3.-multiple-alert-level-actions "mention")

[#id-4.-alert-level-actions](#id-4.-alert-level-actions "mention")

***

### 1. Individual Sub Alert Actions

Actions are taken on individual sub alerts, allowing you to resolve, reassign, add to permit list, or perform other actions on specific objects within an alert. This level of control is particularly useful when you need to handle each impacted object differently based on its content, sensitivity, or other factors.

#### i) Resolving Sub Alerts

1. Select the checkbox next to the sub alert(s) you want to act on.<br>
2. Select 'Resolve' from the Actions dropdown menu.

<figure><img src="https://682442409-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0FnJiPbEPpkm5U4tiZUM%2Fuploads%2FGXaP33EENaFmbk5SXX5g%2Fimage.png?alt=media&amp;token=ced3dd6e-2a7e-4053-b69c-b424b0cff2b0" alt="" width="253"><figcaption><p>Figure 36: Resolve Sub Alerts</p></figcaption></figure>

3. In the Resolve window, add a note to provide context or document the actions taken offline.

<figure><img src="https://682442409-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0FnJiPbEPpkm5U4tiZUM%2Fuploads%2FirEdTBUP7OTtdjZ7iUUI%2Fimage.png?alt=media&amp;token=0a5e11f9-49e0-4dd1-bdfc-2d041faf5583" alt="" width="375"><figcaption><p>Figure 36.1: Resolve Sub Alerts</p></figcaption></figure>

4. Click 'Resolve' to mark the sub alert(s) as resolved.

<figure><img src="https://682442409-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0FnJiPbEPpkm5U4tiZUM%2Fuploads%2FENi9RShrin4ihBdiFtGa%2Fimage.png?alt=media&amp;token=c7390a32-fd70-4016-870a-8401b4c0cd7e" alt="" width="375"><figcaption><p>Figure 36.2 Resolve Sub Alerts</p></figcaption></figure>

**Impact on Table View:** After resolving a sub alert, it will be removed from the '**Objects Impacted'** table, as it has been marked as resolved.

<figure><img src="https://682442409-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0FnJiPbEPpkm5U4tiZUM%2Fuploads%2FkIkCFQ0B9IemPq52A51Y%2Fimage.png?alt=media&amp;token=71a92044-fe98-4beb-b007-cf4f32c2cddb" alt=""><figcaption><p>Figure 36.3 Resolve Sub Alerts</p></figcaption></figure>

**Impact on Dashboard View:** The alert dashboard will update to reflect the decreased number of objects impacted, entities impacted, and attributes associated with the resolved sub alert(s).

<figure><img src="https://682442409-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0FnJiPbEPpkm5U4tiZUM%2Fuploads%2F8sJ3o4Dca06Ba1LBrVx5%2Fimage.png?alt=media&amp;token=ab149c91-5616-411d-ba62-8806e959ce9a" alt=""><figcaption><p>Figure 36.4 Resolve Sub Alerts</p></figcaption></figure>

#### ii) Reassigning Sub Alerts

1. Select 'Reassign' from the Actions dropdown menu.

<figure><img src="https://682442409-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0FnJiPbEPpkm5U4tiZUM%2Fuploads%2FBWNkKO8o6Sqg6d4EXxT4%2Fimage.png?alt=media&amp;token=1aaba45c-c91e-4a72-8850-eddf2c039744" alt=""><figcaption><p>Figure 37: Reassign Sub Alerts</p></figcaption></figure>

2. In the Reassign window, enter the email address of the user you want to reassign the sub alert(s) to.

<figure><img src="https://682442409-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0FnJiPbEPpkm5U4tiZUM%2Fuploads%2FAwU1avEh8TuwmTsnhyKp%2Fimage.png?alt=media&amp;token=54509494-e1f4-4717-a721-799f38d373f4" alt="" width="375"><figcaption><p>Figure 37.1: Reassign Sub Alerts</p></figcaption></figure>

2. Click '**Assign**' to complete the reassignment.

<figure><img src="https://682442409-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0FnJiPbEPpkm5U4tiZUM%2Fuploads%2FoxyyExV95lhhXwYYoA2r%2Fimage.png?alt=media&amp;token=5665e2c1-200b-4f48-8bc9-302662d8b0fb" alt="" width="372"><figcaption><p>Figure 37.2: Reassign Sub Alerts</p></figcaption></figure>

**Impact on Table View:** After reassigning a sub alert, the '**`Assignee`**' column in the '**Objects Impacted**' table will update to display the email address of the new assignee for the corresponding sub alert(s).

<figure><img src="https://682442409-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0FnJiPbEPpkm5U4tiZUM%2Fuploads%2FptymVvfk6cg3zlq3O0Fr%2Fimage.png?alt=media&amp;token=aa6b89f8-09b2-48aa-938c-3f4f125255ea" alt=""><figcaption><p>Figure 37.3: Reassign Sub Alerts</p></figcaption></figure>

**Impact on Dashboard View:** The total number of assignees in the alert dashboard will increment to reflect the additional assignee(s) for the reassigned sub alert(s)

#### iii) Adding Sub Alerts to No Scan List

1. Select '**`Add to "No Scan List"`**' from the **Actions** dropdown menu.

<figure><img src="https://682442409-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0FnJiPbEPpkm5U4tiZUM%2Fuploads%2FekF32RXq90FcuJVMJ44v%2Fimage.png?alt=media&amp;token=23046ba7-6372-4175-a605-dbc1a9d6c6a5" alt=""><figcaption><p>Figure 38: Add Sub Alerts to No Scan List</p></figcaption></figure>

2. In the Add to No Scan List window, you can choose to add a note if necessary and then click on **Add to no-scan list**.

<figure><img src="https://682442409-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0FnJiPbEPpkm5U4tiZUM%2Fuploads%2FyxM4b01evWhSzusxv8A9%2Fimage.png?alt=media&amp;token=5eaa82f5-bdb7-4fba-9ea9-1112169b6aee" alt="" width="375"><figcaption><p>Figure 38.1: Add Sub Alerts to No Scan List</p></figcaption></figure>

<figure><img src="https://682442409-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0FnJiPbEPpkm5U4tiZUM%2Fuploads%2Fcd6FNtUDCGiMCptsqjHT%2Fimage.png?alt=media&amp;token=8c29994e-24bb-4ec1-ad03-4c250313d2b0" alt="" width="372"><figcaption><p>Figure 38.2: Add Sub Alerts to No Scan List</p></figcaption></figure>

**Impact on Table View:** After adding a sub alert to the no scan list, it will be removed from the 'Objects Impacted' table, as it will no longer be scanned by the data source.

<figure><img src="https://682442409-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0FnJiPbEPpkm5U4tiZUM%2Fuploads%2FjGZXJ2RUOdSQ4h2qzQ2a%2Fimage.png?alt=media&amp;token=518c424a-2852-4d36-935f-9d09e4e26c81" alt=""><figcaption><p>Figure 38.3: Add Sub Alerts to No Scan List</p></figcaption></figure>

**Impact on Dashboard View:** The alert dashboard will update to reflect the decreased number of objects impacted, entities impacted, and attributes associated with the sub alert(s) added to the no scan list.

<figure><img src="https://682442409-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0FnJiPbEPpkm5U4tiZUM%2Fuploads%2Flk4mJgaw2tCyivqLlwqM%2Fimage.png?alt=media&amp;token=b6676c3b-8ef2-41fc-bbd2-c42807e24820" alt=""><figcaption><p>Figure 38.4: Add Sub Alerts to No Scan List</p></figcaption></figure>

#### iv) Adding Sub Alerts to Permit List

1. Select '**Add to Permit List**' from the Actions dropdown menu.

<figure><img src="https://682442409-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0FnJiPbEPpkm5U4tiZUM%2Fuploads%2FXcC5jcvld7cP7YbmD2Px%2Fimage.png?alt=media&amp;token=1c534df9-959e-45ac-9e1a-a65ccecb8761" alt=""><figcaption><p>Figure 39: Add Sub Alerts to Permit List</p></figcaption></figure>

2. In the Add to Permit List window, you can choose to add a note to provide additional information.

<figure><img src="https://682442409-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0FnJiPbEPpkm5U4tiZUM%2Fuploads%2FFaNuOCRaoZgtwFkH01kB%2Fimage.png?alt=media&amp;token=e1f5a61d-0d33-446d-a77a-ac886dacbf4b" alt="" width="375"><figcaption><p><br>Figure 39.1: Add Sub Alerts to Permit List</p></figcaption></figure>

3. Click '**Add to Permit List**' to complete the action.

<figure><img src="https://682442409-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0FnJiPbEPpkm5U4tiZUM%2Fuploads%2Fxhsobm2dBAUPD4Gg680R%2Fimage.png?alt=media&amp;token=01185c37-7949-406a-9813-61593e81057d" alt="" width="372"><figcaption><p>Figure 39.2: Add Sub Alerts to Permit List</p></figcaption></figure>

**Impact on Table View:** After adding a sub alert to the permit list, it will be removed from the 'Objects Impacted' table, as it has been exempted from the policy rules.

<figure><img src="https://682442409-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0FnJiPbEPpkm5U4tiZUM%2Fuploads%2FvYFaAuq3tnwOY2caRxAp%2Fimage.png?alt=media&amp;token=c4020573-9264-4a74-9e70-be23e224a911" alt=""><figcaption><p>Figure 39.3: Add Sub Alerts to Permit List</p></figcaption></figure>

**Impact on Dashboard View:** The alert dashboard will update to reflect the decreased number of objects impacted, entities impacted, and attributes associated with the sub alert(s) added to the permit list.

<figure><img src="https://682442409-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0FnJiPbEPpkm5U4tiZUM%2Fuploads%2FXghrBkENssIMTgQcOlU9%2Fimage.png?alt=media&amp;token=3f333739-b40c-49b2-ae7c-5449fc8da2a9" alt=""><figcaption><p>Figure 39.4: Add Sub Alerts to Permit List</p></figcaption></figure>

#### v) Muting Sub Alerts

1. Select '**Mute Alert**' from the **Actions** dropdown menu.

<figure><img src="https://682442409-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0FnJiPbEPpkm5U4tiZUM%2Fuploads%2FqrfMi2VxlErOO1ANGQy3%2Fimage.png?alt=media&amp;token=e1b50948-edae-47e5-9d0f-3ed722257560" alt=""><figcaption><p>Figure 40: Mute Sub Alerts</p></figcaption></figure>

2. In the Mute Alert window, set the mute duration by selecting the number of days, weeks, or months from the dropdown menu.<br>
3. Add a note to provide additional information.

<figure><img src="https://682442409-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0FnJiPbEPpkm5U4tiZUM%2Fuploads%2FyORp7gkhb2ALgbFrtgE0%2Fimage.png?alt=media&amp;token=7fa67955-c2fb-4596-8dd0-4bf5b6a8f3ca" alt="" width="375"><figcaption><p>Figure 40.1: Mute Sub Alerts</p></figcaption></figure>

4. Click '**Mute Alert**' to temporarily suppress the sub alert(s) for the specified duration.

<figure><img src="https://682442409-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0FnJiPbEPpkm5U4tiZUM%2Fuploads%2F62rQv2K5K36APz26mBrC%2Fimage.png?alt=media&amp;token=94c4d4ae-2054-45d0-a731-434efbc30089" alt="" width="370"><figcaption><p>Figure 40.2: Mute Sub Alerts</p></figcaption></figure>

**Impact on Table View:** After muting a sub alert, it will be removed from the 'Objects Impacted' table for the specified mute duration and added to the '**Permit List'** table within Playbooks.

<figure><img src="https://682442409-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0FnJiPbEPpkm5U4tiZUM%2Fuploads%2FFv7XJaU5CsKnAm4ZJNPh%2Fimage.png?alt=media&amp;token=1be86608-8887-4069-8204-3ea6b5b10d84" alt=""><figcaption><p>Figure 40.3: Mute Sub Alerts</p></figcaption></figure>

**Impact on Dashboard View:** The alert dashboard will update to reflect the decreased number of objects impacted, entities impacted, and attributes associated with the muted sub alert(s) for the duration of the mute period.

<figure><img src="https://682442409-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0FnJiPbEPpkm5U4tiZUM%2Fuploads%2Ft0PlqNnXCo5lmkvjk4c9%2Fimage.png?alt=media&amp;token=839f1787-f73d-42fc-b664-6b16b553d5eb" alt=""><figcaption><p>Figure 40.4: Mute Sub Alerts</p></figcaption></figure>

***

### 2. Batch Sub Alert Actions

Alerts 2.0 allows users to perform batch actions on sub alerts, streamlining alert management. You can select all sub alerts on a page at a time by checking the boxes next to each relevant row in the 'Objects Impacted' table. This feature enables you to efficiently apply the same action to multiple sub alerts simultaneously, saving time and effort.

<figure><img src="https://682442409-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0FnJiPbEPpkm5U4tiZUM%2Fuploads%2F9MwjUqp5MToTF4UqgjQO%2Fimage.png?alt=media&amp;token=50f19859-cf05-407b-8346-b28ae3942f7d" alt=""><figcaption><p>Figure 41. Batch Actions on Sub Alerts</p></figcaption></figure>

***

### 3. Multiple Alert-level Actions

The multiple alert level allows you to perform actions on sub alerts across multiple alerts simultaneously. This means that you can select different alerts from a single list-view and perform an action on them at once. &#x20;

To perform a multiple alert-level action, follow these steps:

1. Navigate to the **Alerts** page, which displays a list view of all the alerts.
2. Select the checkboxes next to the alerts you want to perform the action on. You can select alerts from different policies or rule sets.
3. Once you have selected the desired alerts, click on the action button (**Reassign**, **Resolve**, or **Mute**).

<figure><img src="https://682442409-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0FnJiPbEPpkm5U4tiZUM%2Fuploads%2FLlYaR54KxVlE1LOohcJu%2Fimage.png?alt=media&amp;token=0fd9d6b5-f8cc-4474-8c44-27f78675bdcd" alt=""><figcaption><p>Figure 42. Multi-alert-level Actions</p></figcaption></figure>

***

### 4. Alert-level Actions

Actions at this level affect all sub alerts within a single alert. When you perform an action at the alert level, it is applied to every object impacted by the alert. This is useful when you want to apply the same action to all sub alerts within an alert, such as reassigning the entire alert to a different user or adding all impacted objects to the permit list.

Users can further perform actions on the alerts by ticking the checkbox for the alert under **Alert name**.

To perform an alert-level action, follow these steps:

1. On the alert details page, locate the action buttons in the top-left corner of the screen.
2. Click on the desired action button (**Reassign**, **Resolve**, or click on the :arrow\_down\_small: arrow to **Mute**) to apply the action to all sub alerts within the alert.

<figure><img src="https://682442409-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0FnJiPbEPpkm5U4tiZUM%2Fuploads%2FF1bssa0C2ipFR6AjqFVy%2Fimage.png?alt=media&amp;token=9e6e6503-1b24-4696-b278-a12b830f4e74" alt=""><figcaption><p>Figure 43. Alert-level Action on Sub Alerts</p></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.lightbeam.ai/lxqobxw6ak7CTnsQjikH/core-features/spectra-ai/playbooks/policy-and-alerts/levels-of-actions-on-alerts.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
