Introduction
This guide explains how to use the Ticketing capability in SAFE to create, manage, and track remediation work for security findings.
Ticketing enables security teams to convert findings into actionable remediation tasks. Users can assign ownership, define priorities, track remediation progress, and synchronize tickets with enterprise ITSM platforms such as ServiceNow.
Benefits:
Centralized remediation tracking
Internal and external ticket management
Reduced manual effort through Ticketing Rules
Visibility into remediation progress
Faster Mean Time to Remediate (MTTR)
You can access the Ticketing module from the left navigation menu by navigating to Projects > Tickets. The Tickets page provides a centralized view to create, manage, assign, and track remediation tickets for security findings.

Ticketing Workflow
The Ticketing workflow in SAFE CTEM provides a structured process for converting security findings into actionable remediation tasks.
Discover findings.
Select one or more findings.
Click Create Ticket.
Select the ticket type (Internal or External).
Apply a Ticketing Rule (optional).
Review and complete the ticket details.
Create the ticket and assign an owner.
Track remediation progress.
Resolve and close the ticket.
Ticketing Permissions
Action | Admin | Standard User |
|---|---|---|
Create Ticket | ✓ | ✓ |
Edit Ticket | ✓ | Based on Permission |
Delete Ticket | ✓ | — |
Create Ticket Rules | ✓ | — |
Remove Findings | ✓ | If permitted |
Tickets List
The Tickets page, found under Projects > Tickets. It gives you a paginated, searchable, filterable view of every remediation ticket across the environment.
Insights Dashboard
The Insights section gives a quick, at-a-glance read on the remediation program.
Total Tickets | Total number of tickets created. |
Open Findings | Total findings across all tickets that are still in a failing state. |
Mitigated Findings | Total findings across all tickets that have been mitigated. |
Tickets Older Than 90 Days | Number of tickets that have stayed open for more than 90 days. |
Ticket Details
Clicking into a ticket opens the Ticket Detail view, which shows the full ticket record alongside remediation progress.
The Ticket Detail view is organised into four tabs:
Summary | High-level overview of the ticket including progress metrics and key details at a glance. |
Findings | The list of findings linked to this ticket, along with their current remediation status. |
Assets | The assets associated with the ticket's findings. |
Details | Full ticket metadata such as title, status, priority, assignee, due date, tags, and external integration information. |
Progress Calculation
Progress shows what percentage of the ticket's originally scoped findings have been resolved. A finding counts as resolved if it has been mitigated, accepted, or has disappeared (i.e., the source no longer reports it). Progress is capped at 100%.
Two key counts drive the progress calculation:
Initial Finding Count | The number of findings that were linked to the ticket when it was created (adjusted if findings are unlinked). |
Active Finding Count | The number of findings currently still in a failing (open) state. |
Why disappeared findings count?
Many security tools signal that something has been fixed simply by no longer reporting it. SAFE CTEM treats these as resolved so the progress bar reflects real-world remediation.
Note
Progress metrics refresh periodically, so newly mitigated or offboarded findings may take a few minutes to reflect in the progress bar.
Ticket Status
Internal tickets: Status is managed directly within SAFE CTEM (e.g., Open > In Progress > Resolved).
External tickets: Status syncs in from the external system based on the configured sync frequency.
Reaching 100% progress doesn't automatically change a ticket's status, users stay in full control of the ticket lifecycle.