What Security owns in Ravenna
Incident intake
Access reviews
Suggested shape
Two surfaces, deliberately different:- A public channel for reporting.
#securityshould be somewhere anyone can post without asking permission, because a private workspace adds a step exactly where you cannot afford one. - Private tickets for anything under investigation. This is how you get open reporting without the investigation being visible to the company.
Integrations that change the response
The agent’s role, and its hard limit
An agent is genuinely useful here for the documented questions: what counts as a reportable incident, how to report a phishing email, what the password policy is, whether a tool is approved. It has one absolute limit. It must never assess whether something is a real incident, tell someone a message is safe, or reassure a reporter. A false negative on a phishing question is a breach.Answer security policy questions from the knowledge base. Never assess whether a specific message, link, or file is malicious or safe, and never tell a reporter that something is not a problem. For any report of a suspicious message, a lost device, or possible unauthorized access, create a ticket immediately and tell the reporter that Security has been notified.
Where Security desks stall
A private reporting channel
A private reporting channel
Ungated remote actions
Ungated remote actions
Access reviews as a quarterly spreadsheet
Access reviews as a quarterly spreadsheet
An agent that offers reassurance
An agent that offers reassurance