By Role

For IT And Security Leads

The product exposes several governed workflows in one operator interface, but it does not collapse them into one automatic ticket lifecycle. Investigation cases, execution jobs, findings, calendar occurrences, and temporary access requests keep their own controls and histories.

This role cares about

First product view

Collect current facts in a case

Retained record

Review distinct control records

Product path

What this role can inspect and operate.

Investigate

Collect current facts in a case

Resolve a target, use the connected capabilities available to it, and retain evidence, hypotheses, findings, notes, and the narrated method.

  • Only configured and available typed capabilities are exposed.
  • Investigation tools remain read-only.
  • External mutation uses a separate durable proposal path.

Operate

Run managed endpoint work

Agents, playbooks, queues, schedules, and routines provide explicit definitions, target scope, execution state, and returned output.

  • Each enrolled agent authenticates independently.
  • Agents verify signed workloads before local execution.
  • Schedules and routines follow configured controls rather than a universal per-run approval claim.

Govern

Review distinct control records

Alert routing, scanner findings, hardening, compliance, and temporary access each expose the fields appropriate to that workflow.

  • Review qualification and delivery state for alerts.
  • Keep scanner findings separate from hardening evidence and remediation.
  • Inspect access eligibility, mappings, approvers, duration, and step-up readiness.

Read next

Pages for this role.

Next step

Want the walkthrough for your role?

Book a walkthrough and I will show the parts of GAEZLA that matter for your job.