Incidents, Tasks and Notifications
Track incidents on the Dashboard, work the Incidents queue and Incident Detail, manage regulation deadlines, draft and record notifications, run remediation, sign off the review, and complete breach tasks.
Every report submitted through a breach intake form becomes an incident. Neostra scores it, works out which regulations apply, and starts the breach workflows matched by the form rules. This page covers the Dashboard, the Incidents queue, Incident Detail, the Tasks queue, statuses, and how an incident is closed.
Neostra prepares notification drafts and records when and how you sent them. It does not send anything to a supervisory authority, to data subjects or to your board. You send the letter through your own channel, then mark it as sent in Neostra.
Dashboard
Open Breach Management > Dashboard.
| Card | Meaning |
|---|---|
| Total Incidents | All incidents in your tenant. |
| Open Workflows | Workflow instances that are open or in progress. |
| Overdue Deadlines | Incidents not yet closed whose earliest regulatory deadline has passed. A second line shows how many more are due within 24h. |
| Pending Tasks | Breach tasks that are neither completed nor cancelled. |
Incidents by Status shows Open, Under Review and Closed counts. Incidents by Risk shows Low, Medium, High and Severe. Monthly Incident Trend (Last 6 Months) is a bar chart by month.
Analytics & Trends adds Avg. Hours to Notification, Notification Fulfilment, Avg. Days to Resolution, Reviews Signed Off, a 12-Month Incident Trend, Root Cause Distribution and Top Triggered Regulations.
Incidents queue
Open Breach Management > Incidents. Each row shows Incident ID, Status, Risk, Score, Reporter, Submitted, Regulatory Deadline, Workflows (count) and Actions. Geographies is hidden by default; use the column preferences control to show or hide columns. A report with no reporter name or email shows as Anonymous.
Incident IDs have the form BI-<year>-<sequence>, for example BI-2026-0007, numbered per year within your tenant.
Pick a search scope (All Fields, Incident ID or Reporter Email) and type in the Search with box. Click Filters to narrow by Status, Risk Classification and Submitted Date. Active filters appear as chips; Clear all removes them.
Regulatory Deadline carries a Due soon chip when fewer than 24 hours remain and Overdue once the deadline has passed. Expand a row to see one line per workflow instance: Instance ID, Workflow, Rule, Status, Current Stage and Due Date.
The eye icon opens Incident Detail. The row menu offers Change status with Open, Under Review and Closed; closing is rejected until remediation is resolved.
Incident Detail
The header shows the Incident ID, the status chip, the risk chip and Submitted date. Details expands a panel; Change Status offers Open, Under Review and Closed. Changing status and editing tags require a role with breach incident update permission.
Four cards summarise the incident: Applicable Regulations (with overdue, due soon, notified and pending counts), Risk Score, Workflow Instances and Incident Age.
The Details panel shows Reporter (Name, Org, Email, Phone, or Anonymous), Affected Regions, Tags (edit with the pencil icon, pick from Add tag, save) and Actions with View Incident Data, which opens every question and answer submitted on the intake form.
The left navigation groups the tabs: Compliance (Compliance, Notifications), Investigation (Risks, Workflows), Remediation (Remediation, Evidences) and Post-Incident (Review).
Compliance
When the report names affected geographies, Neostra matches them against your regulations and creates one deadline per applicable regulation, calculated from the report time using that regulation's notification window. If no regulation matched, a single Regulatory Deadline card shows the platform default of 72 hours from the report.
The toolbar counts the regulations, Overdue and Due within 24h, and toggles card or list view. Each card shows the regulation, its jurisdiction, the notification window (for example 72h window), the Deadline, a progress bar and a countdown chip such as 2d 5h remaining, Due in 3h or 1 day overdue. Once the Supervisory Authority notification for that regulation is marked as sent the card turns green; if that happened after the deadline it reads Notified late. The Notifications row lists each audience as Draft, Sent or Suppressed, or None generated.
Super admins also see Add, which opens Add Applicable Regulation to attach a regulation your rules did not match. Its deadline runs from the report time and the card is badged Manual.
Notifications
Click Generate Notification. Choose the Regulation and a Recipient Type: Supervisory Authority, Data Subjects or Board. Options are marked Suggested based on the incident's risk score, with a short reason. Click Generate.
Neostra builds a letter from the incident data, form answers, regulation details and any remediation actions, and opens it in the Notification letter editor as a Draft. Placeholders such as [PLACEHOLDER] and [DPO Name] mark what you must fill in. Click Save Changes to keep edits. Generating again for the same regulation and audience replaces the draft.
When you have sent the letter through your own channel, open the draft and click Mark as Sent. It becomes Sent with the date, and the regulation card on the Compliance tab is marked notified. If a notification is not required, click Suppress, give a Reason and confirm. Only drafts can be edited, marked as sent or suppressed. These actions require breach incident edit permission.
Risks
The Risks tab shows the score out of 100 as a gauge, the Risk Classification chip (or Unscored), an Encryption key compromised flag when the report said so, and an Overall Score bar. Score Breakdown lists how each dimension contributed: Data Sensitivity, Exposure Severity and Harm Probability add points; Mitigation deducts. Classification by total: Low below 30, Medium 30 to 59, High 60 to 79, Severe 80 and above.
If any escalation rule matched, the incident is Severe regardless of score; the matched rules are listed with a note that the score was overridden. Scoring happens once at submission using the scoring configuration on the intake form and is not edited on the incident. An unscored incident reads No Risk Assessment.
Workflows
One tab per workflow instance shows Status (Open, In Progress, Completed or Canceled), Rule, Current Stage, Due Date and Completed. Below, the Stages stepper lets you select a stage; Advance Stage completes the current stage and starts the next, or completes the workflow after the last stage.
Tasks Status shows progress. Toggle Disabled Tasks and Filter by Completed or In Progress. The table lists Name, Assignee (count), Status (Pending, Assigned, Completed or Cancelled), Alert (Due soon within 3 days, Overdue), Completion Date, Due Date and Actions. Assign opens Assign Task while the stage is active and the task is open. The eye icon opens the Task Detail drawer; there, Mark as Complete is offered when the stage is active and a response exists, with notes if the task requires them. Expand a task for its assignees with Send Reminder, View Task and Cancel Assignment.
Remediation
This tab is locked until every workflow on the incident is completed or canceled. Then click Edit on Root Cause Analysis to set Category (Human Error, System Failure, Third Party, Malicious Actor or Unknown), What happened?, How was it discovered?, Contributing factors and Closure Notes. Under Remediation Actions, Add action adds a checklist item; tick items as they are done.
Closure lists what still blocks resolution: the category, the narrative, open actions, and notifications still in draft. When the list is empty, Mark Incident as Resolved locks the remediation record. Requires breach incident edit permission.
Evidences
Drop a file on Click to upload or drag & drop (PDF, images, Word, Excel or video, up to 50 MB), optionally Add a note, and click Upload. Each file offers Preview (inline for images and PDFs), Download and Remove. Uploading is disabled once the incident is Closed. Upload and remove require breach incident update permission.
Review
The Review tab is gated until remediation is resolved. Click Edit Review to record Lessons Learned (required), Prevention Measures, Regulatory Outcome (required: No Action Taken, Informal Warning, Formal Warning, Fine Issued, Ongoing Investigation or Dismissed) with notes, Data Subject Impact Summary, Policy Changes Required, and Staff Training Required with notes.
DPO Sign-Off lists what is still required. Sign Off Review is irreversible: it locks the review and records who signed off and when.
Tasks
Open Breach Management > Tasks. Switch between My Tasks and All Tasks. Columns: Task Id, Incident Ref, Task Name, Alert, Status (Pending, Completed or Cancelled), Assignee, Workflow, Current Stage, Creation Date, Due Date and Last Updated. Use Search By (Task Id, Incident Id or Workflow) and tick Completed or Cancelled to include those tasks. Click a row to open the task.
Completing a task
The task page shows the title, status, due date, assignee and response type, plus Incident Details. Any Change Requests appear at the top. Depending on the task, the Response is free text, a single choice, a multiple choice or a date. Notes and Attachments appear when the task allows them and are marked required when it says so; files up to 50 MB.
Edits save automatically about a second after you stop typing. Submit Response is available to the assignee only, once the response and any required notes and attachments are present. Anyone else sees the task read-only.
All Responses, reached from the Task Detail drawer, lists every assignee as Submitted, Draft, Awaiting Answer or Cancelled. On a submitted response, Request Changes sends a Message and reopens it, or Accept Response selects it; on an unanswered one, Send Reminder emails the assignee or Cancel Assignment removes them. After acceptance the page shows only the Accepted Response.
Incident statuses
| Status | How an incident gets there |
|---|---|
| Open | Set on submission. |
| Under Review | Chosen from Change Status while investigating. |
| Closed | Chosen from Change Status after remediation is resolved. |
Workflow, remediation and review states are tracked separately from the incident status.
Closing an incident
Finish the workflows
Advance every stage of every workflow instance on the incident.
Deal with notifications
Mark each notification as sent, or suppress it with a reason.
Resolve remediation
Record the root cause, complete all actions, then Mark Incident as Resolved.
Sign off the review
Record lessons learned and the regulatory outcome, then Sign Off Review.
Close
Use Change Status > Closed. Neostra refuses to close while remediation is unresolved.
Deadlines come from the notification window on each regulation, for example 72 hours under GDPR Article 33. Confirm them with your DPO or counsel; Neostra does not give legal advice.