Skip to main content

"I think I clicked something": the employee report button

How staff report a suspicious click in ten seconds, what Sentinel-Q checks, what the owner's report card recommends, and how to hide the button.

Written for the business owner9 min readUpdated

The most useful security signal in a small company is an employee saying I think I just clicked something, and the most common reason it never arrives is that saying it feels embarrassing. The report button makes it a ten-second, no-blame action: two questions, one button, and a calm reply. Sentinel-Q then does the first hour of investigation, and you get one card with what it checked, what it found and what it recommends.

What your employees see

A card at the top of My apps, with a red I think I clicked something button. It asks two questions and nothing else:

  • What happened? I clicked a link · I opened an attachment · I typed my password · I approved a sign-in request · I'm not sure.
  • When? In the last 10 minutes · In the last hour · Earlier today · Before today.

There is no free-text box. That is deliberate: a report cannot name someone else, cannot carry an instruction to the AI, and cannot be used to smuggle anything into your investigation. The report is always filed as the person who is signed in.

While Sentinel-Q works, the employee sees We're checking. Keep working, and don't turn off your computer. When it finishes they get one of a small, fixed set of replies — nothing found; your administrator is securing your account; your administrator will contact you about your computer; a person will take a look. No AI-written text ever reaches the employee. The replies are the same translated sentences every time, so nothing an attacker plants in an email or a log line can change what your staff are told.

What Sentinel-Q checks

A report becomes an alert at high severity — a report can raise the severity of what we look at, never lower it — and Sentinel-Q investigates it like any other alert, following an evidence plan made for this case:

  1. The reporter's sign-ins over the window they chose: a new country or network, a sign-in straight after the report, sign-in approvals they did not start.
  2. The reporter's devices, where a Qorionix sensor is installed: what ran after the mail client, browser or document reader, new persistence, downloads.
  3. Their Microsoft 365 mailbox and audit activity, where your logs are connected: new inbox or forwarding rules, app consent grants, unusual mail sends.

Every self-report gets its own investigation, even if a colleague reported something similar a minute earlier, and a self-report is never closed automatically.

Your card: Reports from your team

Each report appears once, at the top of the Overview for anyone who can read containment plans. The card is built from the investigation's recorded results, not from AI prose, and reads in plain language: Anna opened an attachment in the last 10 minutes. Then what was checked, the outcome, what was found, and the recommendation.

The outcomes a report can have, and what the card recommends for each.
OutcomeWhat it meansRecommendation
Nothing foundThe evidence was read and nothing harmful turned up.No action. Close the report once you have read it.
Account at riskA suspicious sign-in or mailbox change was confirmed, or the employee said they typed their password or approved a request.Approve the proposed plan: sign them out everywhere and require a second factor at the next sign-in.
Device at riskSuspicious activity on their computer was confirmed.Approve the plan, which can also isolate the device if you have configured isolation.
Needs a lookThe evidence was unclear, incomplete, or contained text that tried to steer the verdict.Open the investigation and decide.

Approve and run asks you to confirm, stating exactly what will happen — for example Anna will be signed out of every device and asked for a second factor at the next sign-in — and then runs the plan. Review plan opens the full containment plan, where reversible steps can be undone. Open investigation takes you to Sentinel-Q's decision with its evidence.

What happens without you

Sentinel-Q investigates and proposes; it does not contain. Today every containment plan waits for a person, whatever your plan or settings, and isolating a device is always a human decision, because the person who reported is usually still working on that laptop. Nobody is signed out until you approve the plan.

Plans and hiding the button

What each plan includes.
PlanWhat happens when someone reports
FreeThe button is off by default. If you turn it on, a report tells your administrators; nothing is investigated automatically.
CoreSentinel-Q investigates and proposes a plan for you to approve.
Protect, CompleteAs Core: the plan waits for you to approve it. The narrow automatic sign-out described above is designed for these plans but is not active today.

The button is on by default on paid plans. An administrator sees a Hide from employees control on the same card in My apps; hiding it asks you to confirm, because a click that worries someone may then reach you late or not at all. Hidden, the card is visible only to administrators, with a Show to employees control to turn it back on.

Your phone gets a short push for each report and when its investigation finishes, if you have the mobile app. The push never names the reporter or includes evidence; it links to the card.

What to read next

  1. What to do when an alert arrives — the same first steps apply to a report that needs a look.
  2. Isolating a machine — what isolation does, and how to set it up so a plan can propose it.
  3. Evidence-bound drafts — writing the incident story, staff note and customer email from the plan afterwards.

Was this article wrong?

If a procedure here does not match what you see, or a limit we described has changed, tell us and we will fix the page. Email us about this article, or see how to get help if you need an answer rather than a correction.

Everything in alerts and response