Documentation — August 21, 2026
1 file changed, 28 insertions, 8 deletions — view the commit on the mirror.
SaaS Security ticketing moves to Run Automation; new Slack remediation route for SaaS Posture and AI Agent issues
- A single page moved: Create and monitor tickets in Cortex Cloud SaaS Security.
- The Jira/ServiceNow flow is rewritten — tickets now start from a right-click Run Automation on Cases and Issues, not from an issue’s Overview page.
- A new Send issues to Slack for remediation section routes SaaS Posture and AI Agent issues to a Slack channel.
- Linked tickets are now read from the issue’s War Room rather than from any issue view.
- Remaining edits are wording: “SSPM console” becomes “Cortex console”, and the Prerequisites heading is demoted to bold.
Highlights
-
Jira and ServiceNow tickets are now created through Run Automation
The rewritten procedure right-clicks the issue under Cases and Issues, then fills a Create a Jira Ticket side panel with Description, Issue Type, Project Key and Summary — and offers to connect the Jira instance inline if the integration is not already present.
-
New section: send issues to Slack for remediation
It requires outbound Slack issue notifications to be configured first, and the procedure itself is to right-click the target issue and select Create a case, which posts a notification to the linked channel.
-
The page's scope widens to SaaS Posture and AI Agent issues
Both the rewritten ticket procedure and the new Slack section name SaaS Posture and AI Agent issues as the targets, where the previous text spoke only of a SaaS Security issue.
-
Linked tickets are tracked from the War Room
Viewing a ticket reference now means opening the targeted issue and choosing War Room, rather than selecting the highlighted reference within any issue view.
Changes
1 file listed, 1 written up and shaded below.
-
▸ ▾ Create and monitor tickets modified +28 −8 Ticket creation moves to right-click Run Automation on Cases and Issues, a Slack remediation section is added, and the scope widens to SaaS Posture and AI Agent issues.
xsiam/cloud-security/cortex-cloud-saas-security/create-and-monitor-ticketsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -3,34 +3,54 @@ description: Learn more about creating a synced ticket to remediate an issue.------# Create and monitor tickets# Create and monitor ticketsIntegrate SaaS Security with Jira or ServiceNow to streamline misconfiguration remediation. This integration allows security teams to delegate manual remediation tasks directly to SaaS application administrators using your organization's existing issue tracking system.Integrate SaaS Security with Jira or ServiceNow to streamline misconfiguration remediation. This integration allows security teams to delegate manual remediation tasks directly to SaaS application administrators using your organization's existing issue tracking system.
### PrerequisitesPrerequisitesBefore managing tickets from the SSPM console, ensure:Before managing tickets from the Cortex console, ensure:• An active Jira or ServiceNow instance is connected and authenticated within your tenant settings. Follow these steps to activate Issue Syncing.• An active Jira or ServiceNow instance is connected and authenticated within your tenant settings. Follow these steps to activate Issue Syncing.
### Ticket Management Workflows### Ticket Management Workflows####- Create a Ticket
####- Create a Ticket
When a SaaS Security issue requires manual intervention within a target SaaS application:When a SaaS Security issue requires manual intervention within a target SaaS application:1. Open the target Issue in the Cortex console.1. Navigate to Cases and Issues and locate the target SaaS Posture or AI Agent Issue.2. On the Overview page, select Jira under the issue properties. This takes you to the ticket’s sync settings.2. Right-click on the Issue you wish to create a ticket for and select Run Automation. Integrations are available for Jira and Service Now. The workflow below uses Jira as an example:3. Under Sync Configuration, select Bi-directional.1. Select Create a Jira ticket from the available automations. If the Jira integration is not already present, you will be directed to provide the URL for you Jira instance and the associated secrets to initiate the integration.4. Assign the ticket to the appropriate team member or administrator for investigation and resolution.2. On the Create a Jira Ticket side-panel, enter your data for the Description, Issue Type, Project Key, and Summary fields.3. Under Sync Configuration, select Bi-directional, and click OK.4. Assign the ticket to the appropriate team member or administrator for investigation and resolution.Once created, SaaS Security automatically establishes a bi-directional reference linking the specific issue to the new ticket ID.Once created, SaaS Security establishes a bi-directional reference linking the specific issue to the new ticket ID.####- View Linked Tickets
####- View Linked Tickets
You can track remediation progress directly from the SaaS interface:You can track remediation progress directly from the SaaS interface:• Select the highlighted ticket reference within any issue view to open the issue directly in Jira or ServiceNow.• Navigate to the targeted Issue and choose War Room to view the highlighted ticket reference. To track remediation progress, click on the ticket to open the issue directly in Jira, and Service Now.
### Send issues to Slack for remediationStreamline issue remediation by routing SaaS Posture and AI Agent alerts directly to a dedicated Slack channel.Prerequisites• Set up outbound Slack issue notifications to link your channel.Procedure1. Navigate to Cases & Issues.2. Locate and right-click the target issue.3. Select Create a case.A notification for the new case posts to the linked Slack channel.Show markdown source
@@ -3,34 +3,54 @@ description: Learn more about creating a synced ticket to remediate an issue. --- # Create and monitor tickets Integrate SaaS Security with Jira or ServiceNow to streamline misconfiguration remediation. This integration allows security teams to delegate manual remediation tasks directly to SaaS application administrators using your organization's existing issue tracking system. *** -### Prerequisites +**Prerequisites** -Before managing tickets from the SSPM console, ensure: +Before managing tickets from the Cortex console, ensure: * An active Jira or ServiceNow instance is connected and authenticated within your tenant settings. Follow these steps to activate [Issue Syncing](../../detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/issue-syncing). *** ### Ticket Management Workflows #### 1. Create a Ticket When a SaaS Security issue requires manual intervention within a target SaaS application: -1. Open the target Issue in the Cortex console. -2. On the **Overview** page, select Jira under the issue properties. This takes you to the ticket’s sync settings. -3. Under **Sync Configuration**, select Bi-directional. -4. Assign the ticket to the appropriate team member or administrator for investigation and resolution. +1. Navigate to **Cases and Issues** and locate the target SaaS Posture or AI Agent Issue. +2. Right-click on the Issue you wish to create a ticket for and select **Run Automation**. Integrations are available for Jira and Service Now. The workflow below uses Jira as an example: + 1. Select **Create a Jira ticket** from the available automations. If the Jira integration is not already present, you will be directed to provide the URL for you Jira instance and the associated secrets to initiate the integration. + 2. On the **Create a Jira Ticket** side-panel, enter your data for the Description, Issue Type, Project Key, and Summary fields. + 3. Under **Sync Configuration**, select Bi-directional, and click OK. + 4. Assign the ticket to the appropriate team member or administrator for investigation and resolution. -Once created, SaaS Security automatically establishes a bi-directional reference linking the specific issue to the new ticket ID. +Once created, SaaS Security establishes a bi-directional reference linking the specific issue to the new ticket ID. #### 2. View Linked Tickets You can track remediation progress directly from the SaaS interface: -* Select the highlighted ticket reference within any issue view to open the issue directly in Jira or ServiceNow. +* Navigate to the targeted Issue and choose War Room to view the highlighted ticket reference. To track remediation progress, click on the ticket to open the issue directly in Jira, and Service Now. + +*** + +### Send issues to Slack for remediation + +Streamline issue remediation by routing SaaS Posture and AI Agent alerts directly to a dedicated Slack channel. + +**Prerequisites** + +* Set up [outbound Slack issue notifications](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/post-deployment/data-and-log-forwarding/forward-logs-and-data-from-cortex-xsiam-to-external-services/configure-external-applications-for-forwarding/integrate-slack-for-outbound-notifications) to link your channel. + +**Procedure** + +1. Navigate to **Cases & Issues**. +2. Locate and right-click the target issue. +3. Select **Create a case**. + +A notification for the new case posts to the linked Slack channel.