Hi, I would like to see more information about the handling of incidents to determine if the threat has been removed or actions are pending on the device (eg a reboot). Case and point, whilst Huntress reported an incident was resolved, when a Huntress analyst checked on the backend, there was still a reboot pending on the device in question. If I see a green tick and resolve status, I want to be confident that all actions are complete and if a reboot is pending, then I can contact the end user to perform a quick reboot etc. I dont want to wait to see if the incident is going to come back the next time a Huntress scan kicks off.