Skip to main content
Audience: Company users requesting investigation and MSP staff or other explicitly permitted users creating follow-up work. Security read access alone does not grant ticket, Planner, Calendar, or Acronis write access. Your MSP manages permissions.

Company users: start with the Home AI Assistant

  1. Open Home and describe the EDR issue to the AI Assistant.
  2. Include the company, incident number, host, severity, and displayed date from EDR Incidents.
  3. Answer any missing questions, review the request, and confirm submission when prompted.
  4. Check the resulting ticket confirmation. Merely viewing or describing the incident is not proof that a ticket was submitted.
See How to open a ticket for the primary support workflow.

Optional Create Ticket shortcut

The incident row’s … > Create Ticket shortcut copies a summary and incident details to the clipboard, then opens Tickets > New Ticket. For a bulk selection, it combines details from the selected loaded rows. This shortcut does not submit a ticket or automatically populate the form. Paste and review the copied details, select the appropriate company and required fields, then submit through the ticket workflow. Work with one company’s incidents at a time and verify every pasted host before submission. The current shortcut shows Incident details copied to clipboard without waiting for clipboard confirmation. If paste does not contain the incident details, copy the required information manually or use the Home AI Assistant. Do not assume the success message means the clipboard or ticket submission succeeded.

Add to Meeting

  1. Choose Add to Meeting from one incident’s row menu, or select same-company incidents and use the page’s bulk-actions menu.
  2. Review the company and Items to add.
  3. Use Select Meeting to choose an upcoming meeting and inspect its Current Agenda.
  4. Recheck the destination if you reopened the dialog or changed company.
  5. Select Add to Agenda, wait for the result, then verify the entries in the meeting.
Each incident becomes a text agenda entry. This does not create a new meeting or establish a live incident link that updates automatically. The picker shows up to 50 upcoming same-company meetings. Calendar write access is required even when the menu is visible. Selecting a meeting alone does not save the agenda.

Add to Planner

  1. Choose Add to Planner from the row menu or a same-company bulk selection, if your role permits it.
  2. Review the proposed title, company, description, item type, status, business value, dates, notes, and sharing.
  3. Replace the initial start and due dates when today is not appropriate. A High-severity or Not Mitigated incident starts with High business value; other selections start at Medium.
  4. Select Save, wait for success, then open the item in Planner and check what actually saved.
Several selected incidents create one Planner item. Incident details are copied into Private Notes; this shortcut does not establish the Cork-style linked-source records or keep those notes synchronized with future Acronis changes. The shared form can show advanced fields that this shortcut does not fully save, including individual cost lines, additional relationships, and custom fields. Add or verify those through the main Planner workflow after creation. Review sharing explicitly before saving; the draft does not guarantee a private item merely because incident details appear in Private Notes. If an error occurs, check Planner before trying again. Do not treat closing the dialog as proof that every field saved. Creating or completing the Planner item does not close or remediate the Acronis incident.

Frequently asked questions

No. It copies details and opens the new-ticket page. You must paste, review, complete required fields, and submit. The Home AI Assistant remains the primary Company support entry point.
No. The selection prepares one Planner item with copied incident notes. Meeting follow-up instead creates one text agenda entry per incident.
No. They are copied information, not a live synchronized incident link.
The destination needs its own permissions and valid company context. Ask the MSP to check access and inspect any partially created follow-up work before retrying.