Triggered Controls Orchestration rule events are found under Incidents . In Forcepoint DSPM, Controls Orchestration rules are designed to identify data that requires attention by evaluating selected datasets, such as files, trustees, or agent activities, against rule conditions. When a rule condition is met, the result is operationalized as an incident so the security or governance team can review the matched data and determine the appropriate response.
Forcepoint’s documentation states that each Controls Orchestration rule is “automatically added as a card in the Incidents tab,” and selecting an incident card takes the administrator back to the related rule. It also explains that the Incidents section provides a top-down view of all orchestration rules and available match results. The documented navigation path is Policy Center > Incidents .
The other options are not the correct location for triggered orchestration events. Default dashboards and overviews provide summary visibility, but they are not the dedicated rule-event review workspace. Analytics supports broader investigation and reporting, but Controls Orchestration match results are reviewed through the Incidents workflow. References/topics: Policy Center, Controls Orchestration, Incidents, Rule Match Results, Enterprise Search Review .
Submit