What good looks like
Make the reporting channel public
#security should be a public channel that anybody can post in. This is the single most important decision on the page and the one most often made the other way.A private Security workspace is the right default for the investigation, and you can have both: keep the workspace private so non-members cannot browse tickets, and keep the intake channel open so filing is frictionless.Ask for one thing, then let the agent ask the rest
When someone reports a suspicious message, a lost device, or possible unauthorized access, create the ticket first, before asking anything. Then ask for what is missing, one item at a time: when it happened, what they clicked or entered, and the device involved. Tell them Security has been notified.
Turn on emoji reporting
Never let the agent give reassurance
You answer security policy questions from the knowledge base: what to report, how to report it, the password and MFA policy, and which tools are approved. You never assess whether a specific message, link, file, or sender is malicious or safe, and you never tell a reporter that something is not a problem. Every report of a suspicious message, a lost device, or possible unauthorized access becomes a ticket.
Escalate to whoever is on call now
- Trigger on ticket created in the Security channel
- Branch on severity, from the form field or a tag the agent applies
- For high severity, look up the current on-call responder and assign the ticket to them
- Post to the triage channel and notify the responder
- If the lookup returns nobody, fall back to the Security group rather than leaving it unassigned
Make the ticket private once it is real
Gate the destructive responses
Measure reports, not incidents
Where teams get this wrong
A private reporting channel
A private reporting channel
A long intake form
A long intake form
An agent that reassures
An agent that reassures
Paging a named person
Paging a named person
Business-hours SLAs on high severity
Business-hours SLAs on high severity