docs: add knowledge base guides for reporting, compliance, queue operations, user management, and CVE tracking
This commit is contained in:
89
docs/kb-ivanti-queue-guide.md
Normal file
89
docs/kb-ivanti-queue-guide.md
Normal file
@@ -0,0 +1,89 @@
|
||||
# Ivanti Queue & Batch Operations Guide
|
||||
|
||||
## Overview
|
||||
|
||||
The Ivanti Queue is a personal staging area for batch-processing vulnerability findings. You select findings from the Reporting Page table, assign them a workflow type and vendor, and stage them in the queue. From there you can create FP workflows, track Archer exceptions, or manage CARD dispositions.
|
||||
|
||||
## Workflow Types
|
||||
|
||||
| Type | Color | Purpose | Vendor Required? |
|
||||
|------|-------|---------|-----------------|
|
||||
| FP | Amber | False Positive — finding is not actually a vulnerability | Yes |
|
||||
| Archer | Blue | Risk Acceptance — vulnerability exists but can't be patched | Yes |
|
||||
| CARD | Green | Asset disposition — device not owned by your BU | No |
|
||||
|
||||
## Adding Findings to the Queue
|
||||
|
||||
### Single Finding
|
||||
1. In the findings table, click the checkbox area on a row (not the checkbox itself — click the cell)
|
||||
2. A popover appears with:
|
||||
- The finding ID
|
||||
- Vendor/Platform input field (required for FP and Archer)
|
||||
- Workflow type toggle (FP / Archer / CARD)
|
||||
3. Enter the vendor name and select the workflow type
|
||||
4. Click "Add to Queue"
|
||||
|
||||
### Batch Add (Multiple Findings)
|
||||
1. Select multiple findings using checkboxes (Shift+Click for range selection)
|
||||
2. The selection toolbar appears at the top of the table
|
||||
3. Choose the workflow type (FP / Archer / CARD)
|
||||
4. Enter the vendor name (not needed for CARD)
|
||||
5. Click "Add to Queue" — all selected findings are added at once (up to 200 per batch)
|
||||
|
||||
## The Queue Panel
|
||||
|
||||
Click the **Queue** button (top right of the Reporting Page) to open the slide-out panel. The badge shows the count of pending items.
|
||||
|
||||
### Layout
|
||||
- Items are grouped by vendor (alphabetically)
|
||||
- CARD items appear in their own green section at the top
|
||||
- Each item shows: finding ID, CVEs, hostname, IP address, and workflow type badge
|
||||
|
||||
### Item Actions
|
||||
|
||||
| Action | How |
|
||||
|--------|-----|
|
||||
| Mark complete | Click the green checkbox |
|
||||
| Mark pending | Uncheck the green checkbox |
|
||||
| Select for deletion | Click the red checkbox (left side) |
|
||||
| Delete selected | Click "Delete (N)" button in footer |
|
||||
| Clear all completed | Click "Clear Completed" button in footer |
|
||||
| Redirect workflow | Click the redirect arrow (↗) on completed items |
|
||||
|
||||
### Redirect Feature
|
||||
|
||||
When a finding is completed under one workflow type but needs to be processed under another:
|
||||
1. Complete the item first
|
||||
2. Click the redirect arrow (↗) icon
|
||||
3. Choose the new workflow type
|
||||
4. A new pending item is created with the same finding data but the new workflow type
|
||||
|
||||
Example: You submitted an FP but it was rejected. You now need to open an Archer ticket instead. Complete the FP item, then redirect it to Archer.
|
||||
|
||||
## Creating FP Workflows from the Queue
|
||||
|
||||
1. Open the Queue panel
|
||||
2. Select pending FP items using the checkboxes
|
||||
3. Click "Create FP Workflow" in the footer (only enabled when FP items are selected)
|
||||
4. Fill in the workflow details (name, reason, description, expiration date)
|
||||
5. Attach supporting files (screenshots, evidence)
|
||||
6. Submit — the workflow is created in Ivanti and queue items are marked complete
|
||||
|
||||
See the [FP Submission Editing Guide](kb-fp-submission-editing-guide.md) for details on editing submitted workflows.
|
||||
|
||||
## FP Submissions Section
|
||||
|
||||
Below the queue items, a "Submissions" section shows your previously submitted FP workflows with:
|
||||
- Workflow name and Ivanti batch ID
|
||||
- Lifecycle status badge (Submitted, Rework, Rejected, Resubmitted, Approved)
|
||||
- Finding count and submission date
|
||||
|
||||
Click any submission to open the Edit Modal for viewing details, adding findings, or reading reviewer notes.
|
||||
|
||||
## Tips
|
||||
|
||||
- Group related findings by vendor before adding to the queue — this makes it easier to create batch FP workflows
|
||||
- Use CARD for findings on devices that belong to another team — no vendor entry needed
|
||||
- The queue is per-user — other team members can't see or modify your queue items
|
||||
- Completed items stay in the queue until you clear them, so you have a record of what was processed
|
||||
- Use the redirect feature when a workflow type needs to change after initial processing
|
||||
Reference in New Issue
Block a user