# Incident Management Guide: Real-Time Alerts & Remediation | Hexnode UEM

**Architecture Overview:** Hexnode Incidents are dynamic, real-time alerts generated by potential risks or system failures. Unlike static compliance rules, incidents track runtime variables such as failed deployments, agent errors, and third-party integration disruptions.

Organizational Benefits
-----------------------

- **Environment Visibility:** Real-time monitoring of the entire managed fleet.
- **Proactive Remediation:** Early detection of misconfigurations and vulnerabilities.
- **Auditability:** Detailed incident stories and chronological logs for compliance.

Administrative Roles & Permissions
--------------------------------------

Hexnode helps with Role-Based Access Control (RBAC) to delegate incident handling:

- **Super Admins & Admins:** Full authority to view, assign, and resolve incidents.
- **Incident Manager:** A custom role for dedicated technicians focused on investigation and remediation.

Navigational Path to Hexnode Incidents
--------------------------------------

The steps to access incidents:

1. Login to the Hexnode console.
2. Navigate to the **Incidents** sub-tab.

Incident Categories & Purpose
---------------------------------

Incidents are grouped into seven distinct categories for streamlined prioritization:

 CategoryPurpose**[Critical](https://www.hexnode.com/mobile-device-management/help/manage-critical-incidents/)**Immediate high-severity failures like expired Apple APNs certificates or UEM license limits.**[Endpoints](https://www.hexnode.com/mobile-device-management/help/manage-endpoint-incidents/)**Device-level issues: rooted/jailbroken states, compliance violations, and command failures.**[Users](https://www.hexnode.com/mobile-device-management/help/user-incidents-management/)**Identity-related risks: location anomalies, geofence violations and suspicious credential changes.**[Apps](https://www.hexnode.com/mobile-device-management/help/manage-app-incidents/)**Application management failures: VPP license depletion and unsuccessful installations.**[Patches](https://www.hexnode.com/mobile-device-management/help/patch-management-incidents/)**Vulnerability status: failed patch deployments and unpatched operating systems.**[Identity Providers](https://www.hexnode.com/mobile-device-management/help/identity-provider-incidents/)**Integration synchronization: failed directory syncs and deleted directory objects.**[Exports](https://www.hexnode.com/mobile-device-management/help/exporting-incident-reports/)**Centralized hub for all incident report (PDF/CSV) export requests. ![Critical incidents dashboard in Hexnode UEM](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2025/11/Manage-incidents-from-the-Critical-Incidents-dashboard.png)

Critical Incident Sources
-------------------------

Specific integrations monitored for Critical alerts:

- **Apple Services:** APNs certificates and VPP token validity.
- **Android Enterprise:** Organization disenrollment and profile deletions.
- **UEM License:** Device count limits and license expiration.
- **Hexnode Agents:** Active Directory and DAFS sync health.

 ![Screenshot of the Hexnode UEM console for customizing the Critical incident dashboard](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2025/11/Customize-Critical-subtab-dashboard.png)

Incident Data Attributes
------------------------

 FieldDefinition**Severity**Automatic levels: Critical, High, Medium, Low, or Info.**Status**Lifecycle stage: Open, In Progress, or Resolved.**Verdict**Technician assessment: Pending, False Positive, or Fixed. ![Screenshot of Hexnode UEM console assigning a technician to an incident. Navigate to the Incidents tab, choose an incident from any category and click on the Add Assignee option for that incident.](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2025/11/Assign-an-incident-to-a-technician.png)

Efficiency Controls: Filtering
------------------------------

 Filter TypeLogic Range**Time**Today, Yesterday, Last 7/30 Days, or Custom Range.**Assignee**Specific technician name search.**Status/Verdict**Narrow down by resolution state and investigation result. ![Screenshot of the Filtering options for incidents in Hexnode UEM. Navigate to the corresponding section within the Incidents tab and click on the Filter option available on the top-right. ](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2025/11/Available-options-to-filter-incidents-scaled.png)

Collaboration & Customization
---------------------------------

- **Incident Story:** Chronological history of all state changes and comments.
- **Comments:** Threaded discussions with **@mention** support.
- **Custom Fields:** Organization-specific data points. Each custom field requires a Field Name and supports an optional Description. (Supported data types: Link, Checkbox, Dropdown, etc.).