Annotate status changes on alerts
Problem to solve
When teams are triaging alerts, they need a way to annotate changes in status so that team members know why the status was changed and if any followups are needed. Annotations will help to share context broadly among team members which will reduce confusion and the need to constantly update team members synchronously.
This work drives the direction of the Alert Management category.
Following what's been done on vulnerabilities, we can have a commenting section appear as part of the system notes when the status is changed:
|Status is changed - comment field appears||Field is activated||Text is added||Final state with additional system note|
A new note field will appear each time the status is changed. Any edits to the note field can be captured in the system notes.
Update: we've recently decided to move the system notes to a separate tab. Depending on the order of implementation, the location of these annotations might change from what's shown in the designs above. When the system notes move to a separate tab, the annotations will, as well.