Using the Triage Page

Written By Matt Sywulak

Last updated About 3 hours ago

The Triage page is your central workspace for reviewing and acting on email that needs attention. It's organized into tabs, each showing a live count in the tab bar so you can jump straight to the queue that needs work. Use the team selector and date range selector in the top-right to scope the view; a specific team must be selected.

Triage Page is gated as a beta feature. Contact your account team to have it enabled for your organization.

The Triage tabs

Depending on what your team has enabled, Triage can show these tabs:

  • Reported Mail β€” emails your users reported, with one-click remediation. See Reported Mail. (Beta)

  • Message Deletions β€” in-flight message deletion and remediation requests, with their status.

  • Burst Management β€” users currently in inbound or outbound burst mode, and users you've prevented from entering burst mode.

  • Outbound Protection β€” Account Takeover (ATO) enforcements, described in detail below. Requires the outbound protection entitlement.

  • Message Investigations β€” group related messages into cases and remediate them together. See Message Investigations. (Beta)

A tab appears only when the matching feature or entitlement is enabled for your team, so you may see a subset of the tabs above.

Burst Management

The Burst Management tab summarizes burst activity with four stats β€” Active Inbound, Active Outbound, Prevented Inbound, and Prevented Outbound β€” and lists the affected users in two tables: Active bursts and Prevented users ("These users are blocked from entering burst mode."). Outbound stats appear only if your team is entitled to outbound protection.

Outbound Protection (Account Takeover enforcements)

The Outbound Protection tab is the view for monitoring and managing all active and historical Account Takeover (ATO) enforcements. Its header stat, Active Enforced Users, counts users currently in enforcement mode.

Reading the enforcement list

Each enforcement appears as a row showing:

  • The user's email address

  • A threat level badge (High / Medium / Low)

  • An enforcement status pill: Active (currently in enforcement), Expired (time elapsed without admin action), or Released (manually dismissed by an admin)

  • The subject line of the triggering message and intended recipients

  • When enforcement began and how long ago

  • The time of the most recent message held under enforcement

  • A message count (total messages held)

Active enforcements are sorted to the top. Expired and released enforcements appear below. Use the search bar to filter by email address and the High / Medium / Low buttons to filter by risk level.

Reviewing an enforcement

Click anywhere on an enforcement row to expand it. The expanded view shows an alert summary banner describing what triggered enforcement (for example, "3 dangerous links, 1 phishing content signal detected across 2 signals"), three stat boxes for how many messages are currently Quarantined, Discarded, and Delivered, and a message table. Each message shows its subject (with any matched workflow rules), recipients, action, date, status, and links to open message details or the Observations page.

Approving and rejecting quarantined messages

For messages that are currently quarantined and have not yet been acted on, administrators with Modify permission see Approve and Reject buttons in the message row.

  • Approve β€” releases the message for delivery to recipients

  • Reject β€” discards the message permanently

Actions take effect immediately. If multiple messages share a group key (part of the same sending batch), processing one will lock the others from simultaneous action until complete.

Releasing a user from enforcement

To end an active enforcement before its Time in Force expires, click the shield icon on the right side of the enforcement row. This opens the Release modal, where you choose how to handle any still-quarantined messages:

  • Approve Quarantined Messages β€” releases all held messages for delivery

  • Reject Quarantined Messages β€” discards all held messages

  • Do Nothing with Quarantined Messages β€” leaves held messages in place (they will be automatically rejected when enforcement ends)

Click Release User to confirm. The user's outbound messages resume normal delivery immediately, and the enforcement row remains visible with a Released status.

Bulk Deletion Limitations:

  • When a user selects the top checkbox from observations, it only selects everything in the current list, which loads in batches of 100.Β 

  • Selecting a message that has already been remediated will not allow re-remediation (no trash icon).Β 

  • Selecting a large number can take some time to process.