Ticketing Overview

Prev Next

Introduction

This guide explains how to use the Ticketing capability in SAFE to create, manage, and track remediation work for security findings.

Ticketing enables security teams to convert findings into actionable remediation tasks. Users can assign ownership, define priorities, track remediation progress, and synchronize tickets with enterprise ITSM platforms such as ServiceNow.

Benefits:

  • Centralized remediation tracking

  • Internal and external ticket management

  • Reduced manual effort through Ticketing Rules

  • Visibility into remediation progress

  • Faster Mean Time to Remediate (MTTR)

You can access the Ticketing module from the left navigation menu by navigating to Projects > Tickets. The Tickets page provides a centralized view to create, manage, assign, and track remediation tickets for security findings.

Ticketing Workflow

The Ticketing workflow in SAFE CTEM provides a structured process for converting security findings into actionable remediation tasks.

  1. Discover findings.

  2. Select one or more findings.

  3. Click Create Ticket.

  4. Select the ticket type (Internal or External).

  5. Apply a Ticketing Rule (optional).

  6. Review and complete the ticket details.

  7. Create the ticket and assign an owner.

  8. Track remediation progress.

  9. Resolve and close the ticket.

Ticketing Permissions

Action

Admin

Standard User

Create Ticket

✓

✓

Edit Ticket

✓

Based on Permission

Delete Ticket

✓

—

Create Ticket Rules

✓

—

Remove Findings

✓

If permitted

Tickets List

The Tickets page, found under Projects > Tickets. It gives you a paginated, searchable, filterable view of every remediation ticket across the environment.

Insights Dashboard

The Insights section gives a quick, at-a-glance read on the remediation program.

Total Tickets

Total number of tickets created.

Open Findings

Total findings across all tickets that are still in a failing state.

Mitigated Findings

Total findings across all tickets that have been mitigated.

Tickets Older Than 90 Days

Number of tickets that have stayed open for more than 90 days.

Ticket Details

Clicking into a ticket opens the Ticket Detail view, which shows the full ticket record alongside remediation progress.

The Ticket Detail view is organised into four tabs:

Summary

High-level overview of the ticket including progress metrics and key details at a glance.

Findings

The list of findings linked to this ticket, along with their current remediation status.

Assets

The assets associated with the ticket's findings.

Details

Full ticket metadata such as title, status, priority, assignee, due date, tags, and external integration information.

Progress Calculation

Progress shows what percentage of the ticket's originally scoped findings have been resolved. A finding counts as resolved if it has been mitigated, accepted, or has disappeared (i.e., the source no longer reports it). Progress is capped at 100%.

Two key counts drive the progress calculation:

Initial Finding Count

The number of findings that were linked to the ticket when it was created (adjusted if findings are unlinked).

Active Finding Count

The number of findings currently still in a failing (open) state.

Why disappeared findings count?

Many security tools signal that something has been fixed simply by no longer reporting it. SAFE CTEM treats these as resolved so the progress bar reflects real-world remediation.

Note

Progress metrics refresh periodically, so newly mitigated or offboarded findings may take a few minutes to reflect in the progress bar.

Ticket Status

  • Internal tickets: Status is managed directly within SAFE CTEM (e.g., Open > In Progress > Resolved).

  • External tickets: Status syncs in from the external system based on the configured sync frequency.

Reaching 100% progress doesn't automatically change a ticket's status, users stay in full control of the ticket lifecycle.