Security Tickets and Planning
Security tickets
Section titled “Security tickets”The Security Tickets section ensures that tickets related to security incidents are flagged, prioritized, and routed with heightened visibility. These tickets often involve data breaches, unauthorized access attempts, malware infections, or compliance-related events and must be escalated to the right teams without delay.
Fields & options
Section titled “Fields & options”- Enable Security Tickets Activates dedicated handling of tickets marked as security-related.
- Agent Model Defines the AI reasoning model used to analyze and classify security events. Example: OpenAI GPT-5 Medium Reasoning.
- Priorities to Alert to Teams Chat Select which ticket priorities (e.g., Medium, High, Emergency) will trigger alerts in Microsoft Teams channels. This ensures that only relevant incidents reach the security team.
- Teams Chat/Conversation ID A Microsoft Teams channel ID used for sending targeted security alerts.
- Full Feed Teams Chat/Conversation ID An optional second Teams channel ID where all security tickets are mirrored, creating a comprehensive feed for auditing and SOC visibility.
- Sync MSPC User with AAD User Matches ticket requesters in MSPControl with their corresponding Azure AD accounts to strengthen identity context.
- Add Internal Note to the Ticket Automatically appends system-generated notes to tickets for audit trails.
- Add Discussion Note to the Ticket Inserts human-readable updates intended for collaboration between engineers.
- Send Notification to the Teams Chat Sends a notification message into the configured Teams channel when a qualifying security ticket is detected.
Behavior
Section titled “Behavior”Virtubot monitors incoming tickets for security-related keywords, sources, or triggers. If a ticket matches defined conditions, it is marked as a Security Ticket. Alerts are sent to the selected Teams channels, with optional full-feed duplication for SOC monitoring. Linked Azure AD accounts are synchronized to give analysts full identity context when investigating the incident.
Best practices
Section titled “Best practices”- Enable Emergency and High priorities for Teams alerts to minimize noise while ensuring visibility of critical events.
- Use the Full Feed channel for SOC staff who need a complete log of all incidents.
- Always enable Sync MSPC User with AAD User to ensure accurate correlation of incidents with user accounts.
- Configure audit-ready internal notes for compliance requirements (e.g., ISO27001, SOC 2).
- Test alerts regularly by creating simulated security incidents to confirm routing works as expected.
Security tickets
Section titled “Security tickets”The Security Tickets section ensures that tickets related to security incidents are flagged, prioritized, and routed with heightened visibility. These tickets often involve data breaches, unauthorized access attempts, malware infections, or compliance-related events and must be escalated to the right teams without delay.
Fields & options
Section titled “Fields & options”- Enable Security Tickets Activates dedicated handling of tickets marked as security-related.
- Agent Model Defines the AI reasoning model used to analyze and classify security events. Example: OpenAI GPT-5 Medium Reasoning.
- Priorities to Alert to Teams Chat Select which ticket priorities (e.g., Medium, High, Emergency) will trigger alerts in Microsoft Teams channels. This ensures that only relevant incidents reach the security team.
- Teams Chat/Conversation ID A Microsoft Teams channel ID used for sending targeted security alerts.
- Full Feed Teams Chat/Conversation ID An optional second Teams channel ID where all security tickets are mirrored, creating a comprehensive feed for auditing and SOC visibility.
- Sync MSPC User with AAD User Matches ticket requesters in MSPControl with their corresponding Azure AD accounts to strengthen identity context.
- Add Internal Note to the Ticket Automatically appends system-generated notes to tickets for audit trails.
- Add Discussion Note to the Ticket Inserts human-readable updates intended for collaboration between engineers.
- Send Notification to the Teams Chat Sends a notification message into the configured Teams channel when a qualifying security ticket is detected.
Behavior
Section titled “Behavior”Virtubot monitors incoming tickets for security-related keywords, sources, or triggers. If a ticket matches defined conditions, it is marked as a Security Ticket. Alerts are sent to the selected Teams channels, with optional full-feed duplication for SOC monitoring. Linked Azure AD accounts are synchronized to give analysts full identity context when investigating the incident.
Best practices
Section titled “Best practices”- Enable Emergency and High priorities for Teams alerts to minimize noise while ensuring visibility of critical events.
- Use the Full Feed channel for SOC staff who need a complete log of all incidents.
- Always enable Sync MSPC User with AAD User to ensure accurate correlation of incidents with user accounts.
- Configure audit-ready internal notes for compliance requirements (e.g., ISO27001, SOC 2).
- Test alerts regularly by creating simulated security incidents to confirm routing works as expected.
Ticket planner
Section titled “Ticket planner”The Ticket Planner automates the alignment of tickets with service plans, budgets, and templates, ensuring consistency and efficiency across multiple helpdesk boards. By leveraging AI-driven classification and Microsoft Teams integration, the system distributes tasks, applies budgets, and enforces templates to maintain a standardized approach to ticket handling.
Fields & options
Section titled “Fields & options”- Agent Model Defines the AI reasoning model responsible for analyzing and aligning tickets with defined plans. Example: OpenAI GPT-5 Medium Reasoning.
- Boards (comma-separated, empty for all boards) Specifies which boards the Ticket Planner applies to. If left empty, all boards are included. Example: Professional Services, Help Desk, SOC.
- Teams Chat/Conversation ID The Microsoft Teams channel ID used for posting notifications and updates related to ticket planning.
- Add/Update Tasks based on the Plan Automatically generates or updates ticket tasks according to the associated service plan.
- Add/Update Ticket Budget based on the Plan Aligns ticket budget values with the defined service plan, ensuring correct cost tracking.
- Add Internal Note to the Ticket Appends system-generated notes into the ticket for audit and traceability.
- Send Notification to the Teams Chat Notifies the configured Teams channel whenever ticket planning actions are performed.
- Use Company Service Templates when Available Applies company-level templates for consistent service delivery if available.
- Use Global Service Templates when Available Applies global templates to maintain standardization across all boards and organizations.
- Consider All Boards when looking for Templates Extends the search for templates across every board, not just the selected one.
- Download Service Ticket Templates Exports the configured ticket templates as a reference for further adjustments or auditing.
Behavior
Section titled “Behavior”The Ticket Planner automatically synchronizes tasks and budgets with the defined service plan. It ensures tickets are enriched with internal notes and that relevant updates are shared with Microsoft Teams channels. Service templates—whether company-specific or global—are applied to standardize ticket handling across boards. When enabled, cross-board template searching guarantees that the best matching template is always applied, regardless of origin.
Best practices
Section titled “Best practices”- Always specify boards explicitly unless all boards should be included.
- Enable both Add/Update Tasks and Add/Update Ticket Budget for maximum automation efficiency.
- Use Company Templates for internal consistency and Global Templates when standardization across organizations is required.
- Test Teams notifications with sample tickets to verify correct routing and visibility.
- Download templates periodically for review and compliance documentation.