Summary
Scenarios are the rules that cause messages to be flagged as Sentinel alerts. Scenarios are organised within scenario categories. From a category's detail page you can see each scenario, read its description, see how many alerts it has produced, and open its alerts. Editing an individual scenario's settings is available only when scenario editing is enabled for your organisation.
The UI does not provide a way to create or delete scenarios. You view the scenarios that exist within each category and, where editing is enabled, adjust an individual scenario's settings.
Prerequisites
Login credentials to MirrorWeb Insight
Access to an organisation that has Sentinel enabled
To open a scenario's settings, scenario editing must be enabled for your organisation
Step-by-Step Instructions
Step 1: Open the Scenarios area
In the sidebar, under Sentinel, select Scenarios to open the Scenario Categories page, then select a category to view its scenarios.
Step 2: View the scenarios in a category
The category detail page lists the category's scenarios under a "Scenarios" heading. Each scenario shows its name, a description, and an alert count badge (for example "0 alerts" or "12 alerts"). If a category has no scenarios, the page shows "No scenarios available for this category."
Step 3: View a scenario's alerts
For a scenario that has alerts, use the view-alerts action on the scenario row to open the Alerts page filtered to that scenario.
Step 4: Open a scenario's settings (if enabled)
If scenario editing is enabled for your organisation, an edit (cog) icon appears on each scenario row. Select it to open the scenario's Settings page. See How to configure scenario settings and rules.
Notes
Note: Alert counts shown on a scenario indicate how many alerts that scenario has produced; selecting the count opens those alerts in the Alerts page.
Note: Some categories are only shown to specific organisations and may be hidden for yours.



