FAQ
Triage questions
Quick answers about how HRS Triage scores reported email, what it does on its own, and what stays with a person.
These answers summarize the HRS Triage guides. Each one links to the full guide.
Where do reports come from?
From the Report Phishing button in Outlook, from a monitored mailbox, or from another tool through the signed API. Auto-replies are ignored, and "Fwd:" and "[External]" prefixes are stripped. See How a reported email becomes a case.
How does Triage decide whether an email is malicious?
A deterministic engine adds up the evidence from headers, links, attachments, QR codes and threat lists, and every point has a reason you can read on the case. The total sets the verdict: malicious, suspicious, needs review or benign. If an admin turns on the AI second opinion, its influence is capped and only counts in full when independent evidence agrees.
Is confidence a probability?
No. Confidence (low, medium or high) says how much independent evidence agrees.
What happens when someone reports a practice phishing email?
Triage recognizes it as an HRS simulation, closes it as reported correctly, and HRS Learn credits the person who reported it. It never lands in front of an analyst as a threat.
Does Triage remove emails on its own?
Only when an admin allows it and every safety check passes: a high-confidence malicious verdict, enough independent signals agreeing, no disagreement from the AI, no VIP among the recipients, and fewer mailboxes than the blast-radius limit. Otherwise it prepares the action for a person. See The Triage Agent.
Can a removal be undone?
Yes. Restore all puts the message back in every mailbox it was taken from. Nothing is deleted: Microsoft 365 moves mail to Recoverable Items, and Gmail to Trash for 30 days. See Remove a phish from every mailbox.
What protects our executives?
Add them as VIPs. Mail involving a VIP is never removed or contained automatically; a person always decides. See Autonomy, VIPs and trusted senders.
Will a spoof of a trusted partner get through?
No. Trusted senders only quiet mail that passes DMARC alignment for the listed domain, so a spoof of that partner is still scored normally.
Do the people who reported hear back?
If you want them to. Analysts can send a received, safe, confirmed threat or handled notice from the case, and an admin can turn on automatic replies when a verdict is set. See Close the loop with reporters.
Does Triage need access to our mailboxes?
Only to remove or restore messages. Scoring works without it. To act on mail, connect Microsoft 365 or Google Workspace.
Can Triage open tickets or post to chat?
Yes: Slack, Microsoft Teams, Jira and ServiceNow, and the PSAs ConnectWise, Autotask and HaloPSA. See Send threats to Slack, Teams, Jira or ServiceNow and Open tickets in ConnectWise, Autotask or HaloPSA.
How does Triage handle our data?
Reported email can contain other people's personal data, and Triage uses it only to analyze and clean up the message. Some link and file details are checked against outside threat-intelligence services. See How customer data is handled.
Where do I check whether Triage is working normally?
The status page, or the in-app status page. See Check system status.