"I think I clicked something": the employee report button
How staff report a suspicious click in ten seconds, what Sentinel-Q checks, what the owner's report card recommends, and how to hide the button.
The most useful security signal in a small company is an employee saying I think I just clicked something, and the most common reason it never arrives is that saying it feels embarrassing. The report button makes it a ten-second, no-blame action: two questions, one button, and a calm reply. Sentinel-Q then does the first hour of investigation, and you get one card with what it checked, what it found and what it recommends.
What your employees see
A card at the top of My apps, with a red I think I clicked something button. It asks two questions and nothing else:
- What happened? I clicked a link · I opened an attachment · I typed my password · I approved a sign-in request · I'm not sure.
- When? In the last 10 minutes · In the last hour · Earlier today · Before today.
There is no free-text box. That is deliberate: a report cannot name someone else, cannot carry an instruction to the AI, and cannot be used to smuggle anything into your investigation. The report is always filed as the person who is signed in.
While Sentinel-Q works, the employee sees We're checking. Keep working, and don't turn off your computer. When it finishes they get one of a small, fixed set of replies — nothing found; your administrator is securing your account; your administrator will contact you about your computer; a person will take a look. No AI-written text ever reaches the employee. The replies are the same translated sentences every time, so nothing an attacker plants in an email or a log line can change what your staff are told.
What Sentinel-Q checks
A report becomes an alert at high severity — a report can raise the severity of what we look at, never lower it — and Sentinel-Q investigates it like any other alert, following an evidence plan made for this case:
- The reporter's sign-ins over the window they chose: a new country or network, a sign-in straight after the report, sign-in approvals they did not start.
- The reporter's devices, where a Qorionix sensor is installed: what ran after the mail client, browser or document reader, new persistence, downloads.
- Their Microsoft 365 mailbox and audit activity, where your logs are connected: new inbox or forwarding rules, app consent grants, unusual mail sends.
Every self-report gets its own investigation, even if a colleague reported something similar a minute earlier, and a self-report is never closed automatically.
Your card: Reports from your team
Each report appears once, at the top of the Overview for anyone who can read containment plans. The card is built from the investigation's recorded results, not from AI prose, and reads in plain language: Anna opened an attachment in the last 10 minutes. Then what was checked, the outcome, what was found, and the recommendation.
| Outcome | What it means | Recommendation |
|---|---|---|
| Nothing found | The evidence was read and nothing harmful turned up. | No action. Close the report once you have read it. |
| Account at risk | A suspicious sign-in or mailbox change was confirmed, or the employee said they typed their password or approved a request. | Approve the proposed plan: sign them out everywhere and require a second factor at the next sign-in. |
| Device at risk | Suspicious activity on their computer was confirmed. | Approve the plan, which can also isolate the device if you have configured isolation. |
| Needs a look | The evidence was unclear, incomplete, or contained text that tried to steer the verdict. | Open the investigation and decide. |
Approve and run asks you to confirm, stating exactly what will happen — for example Anna will be signed out of every device and asked for a second factor at the next sign-in — and then runs the plan. Review plan opens the full containment plan, where reversible steps can be undone. Open investigation takes you to Sentinel-Q's decision with its evidence.
What happens without you
Sentinel-Q investigates and proposes; it does not contain. Today every containment plan waits for a person, whatever your plan or settings, and isolating a device is always a human decision, because the person who reported is usually still working on that laptop. Nobody is signed out until you approve the plan.
Plans and hiding the button
| Plan | What happens when someone reports |
|---|---|
| Free | The button is off by default. If you turn it on, a report tells your administrators; nothing is investigated automatically. |
| Core | Sentinel-Q investigates and proposes a plan for you to approve. |
| Protect, Complete | As Core: the plan waits for you to approve it. The narrow automatic sign-out described above is designed for these plans but is not active today. |
The button is on by default on paid plans. An administrator sees a Hide from employees control on the same card in My apps; hiding it asks you to confirm, because a click that worries someone may then reach you late or not at all. Hidden, the card is visible only to administrators, with a Show to employees control to turn it back on.
Your phone gets a short push for each report and when its investigation finishes, if you have the mobile app. The push never names the reporter or includes evidence; it links to the card.
What to read next
- What to do when an alert arrives — the same first steps apply to a report that needs a look.
- Isolating a machine — what isolation does, and how to set it up so a plan can propose it.
- Evidence-bound drafts — writing the incident story, staff note and customer email from the plan afterwards.