Overview
My Queue is your personal triage worklist. It collects the open items across your workspace into one ranked list, so that you can work the list to zero. These items include investigations, behavior alerts, configuration drift, action plans, and proposed actions.
My Queue shows what needs your attention and allows you to clear each item in place. When Hearth proposes an action, you confirm that action here. Nothing runs until a person confirms it.
Note: Your workspace needs at least one connected source and some agent output before the queue contains items.
How it works
My Queue does not add a new data model. It reads the information that your workspace already has, and it assembles the open items that are worth your time. An item appears in the queue when it meets all of the following conditions:
- Actionable kind. The item is an investigation, a behavior alert, or a configuration drift artifact. An open action plan and an open proposed action also qualify.
- Meaningful severity. Hearth excludes artifacts below medium severity, so that low and informational items never fill the queue.
- Open status. Hearth removes any item that someone dismissed or resolved.
Hearth ranks the list by severity, from most serious to least serious. Hearth also groups the proposed actions that came from one scan into a single collapsible row. As a result, a scan that affects many accounts appears as one row instead of many rows.
Views in My Queue
The following table describes the two views:
| View | What it contains |
|---|---|
| Mine (the default) | The items that belong to you. These items include an investigation or a behavior alert that you created or last acted on, and an action plan that is assigned to you. |
| All open | Every item that is still open across the workspace. This view also includes configuration drift and proposed actions, which belong to the workspace rather than to one person. |
Proposed actions
Proposed actions are propose-only. A rule or a scan can surface a suggested action, but Hearth never runs that action. You review the action in the queue and confirm it. Hearth performs the action only after you confirm it, and only when your role can perform the action.
Opening My Queue and selecting a view
To open the queue:
- Navigate to My Queue. The page opens on the Mine view, which contains your own open items.
- (Optional) Click All open to see every item that is still open across the workspace.
Working an artifact item
To act on an investigation, a behavior alert, or a configuration drift row, do one of the following:
- Click Ack to record that you saw the item. The row stays in the queue as an acknowledged, open item.
- Click Dismiss to close the item as no action needed. The row leaves the queue.
- Click Resolve to close the item as handled. The row leaves the queue.
- Click the row to open the item in full and work it there.
Dismiss and Resolve are terminal actions. The row leaves the queue, and the navigation badge updates. Ack keeps the row in the queue, so that you do not lose the item.
Opening an action plan
An action plan row links to the plan. To review, approve, or dismiss the steps of a plan, click the row. The queue is where you notice that a plan needs your attention.
Confirming or dismissing a proposed action
A proposed action row shows the action, its target, and the source that proposed it. To act on the row:
- Review the action, its target, and its source.
- (Optional) If one scan produces several proposals, click the grouped row to expand it. The row states that Hestia proposed the actions from one scan, and that nothing runs until you confirm.
- Do one of the following:
- Click Confirm to perform the action. Hearth verifies on the server that your role can perform the action.
- Click Dismiss to close the proposal. Hearth performs nothing.
Note: Hearth never performs a proposed action on its own. A person confirms every action, and only a role that can perform the action can confirm it.
Troubleshooting common issues
| Issue | What to do |
|---|---|
| An item that you expected does not appear in the queue | The queue holds only open items of an actionable kind at medium severity or higher. Hearth excludes low and informational artifacts, and any item that someone dismissed or resolved. To work an excluded item, open it directly from the Artifacts page. |
| Configuration drift never appears in the Mine view | Configuration drift belongs to the workspace rather than to one person, so it appears only in the All open view. Proposed actions follow the same rule. |
| No proposed actions appear in the queue | Proposed actions appear only to a role that can see automation. Hearth hides these rows from every other role. |
| Confirm returns the message "Your role can't perform this action." | Only an owner or an administrator can confirm a proposed action. Ask an administrator to confirm the action or to change your permissions to include the ability to perform actions. |
| The page displays a permissions message instead of your queue | The queue requires the View Artifacts permission. Confirm your role’s permissions with an administrator. |