It'd be nice if we could add rules for identities rather than entire orgs right from the VPN incidents. Ex: User suddenly logs in from Nord VPN, we call the user "Oh yeah I use that on my cell phone, I pay for it personally for when I'm travelling and using public wifi" or they suddenly show up in Mexico "Oh yeah, I'm down here visiting my abuela, I come 2-3 times a year" it'd be nice if we could from the incident screen just create the rule for just that user, rather than exposing the entire company, or having to go chase down the rule and create a new one for just that identity.