Reviewing findings
The Brand Protection page — the list and its filters, the detail view, each finding's page, the four statuses, Jira tickets and export.
The Brand Protection page is built for working a queue. The View mode control in the header offers four ways to see the same filtered findings:
| View | What it is for |
|---|---|
| Details | The dense list beside a permanent inspector, so assessing a domain never means leaving the screen. The default. |
| Board | A column per status, each finding a card; drag a card to change its state, and read "what is waiting on us" off the columns |
| Screenshots | Every finding as its captured page, for a visual sweep |
| List | The full table — every column, sorting, flat or grouped by brand — and the export order |
The view rides along in the URL, so a link opens the view it was copied from. Beside the control, Run statistics opens what each discovery run did (see Runs and limits) and Export downloads the current findings.
Details view
The list on the left shows each finding's domain, the brand it trades on, its threat types, an MX marker when it can receive mail, and its risk score; the finding under inspection is highlighted, and the first finding is inspected until you choose another. ↑ ↓ move down the list.
The inspector on the right is the finding in one screen:
- the header — the domain and its risk badge, the brand it trades on, when and how it was found — with View details page and Open site
- Live capture — the screenshot (click to enlarge) and when the finding was last checked
- Why this scored N — the model's reasoning, then the observations behind the score as bullets: each threat type, what the page is doing, whether it can receive mail, and the zones of yours it resembles, with the component scores and confidence on one line
- Signals — the serving state and HTTP status, the page state, mail records, where the page redirects to, how the finding was found, first seen and last checked, and its visual distance from your own sites
- Related — how many other findings trade on the same brand or resemble the same zone
- the decision bar, pinned at the bottom — the four status buttons, the Jira action, your position in the queue (1 of 15) and previous/next
P / W / F / I set the status from the keyboard and ← → move through the queue, as in the detail view. Triaging advances to the next finding. On a narrow screen the Details view is the list alone, and choosing a finding opens the detail view instead.
Board view
The Board treats each finding as a case moving through review. The columns are the statuses — Pending review, Watching, Flagged, Ignored — so the screen answers what is waiting on you without touching a filter. Above them a strip counts the open cases (everything not ignored), how many are high risk and mail-enabled, their median age, and how many are new this week.
Each card carries the domain, its risk score and a bar for it, the brand and the finding's age, and a chip: the lead threat type, the Jira ticket key once one exists, or the reason for an ignored finding. Drag a card into another column to change its status — dropping it on Ignored asks for the reason, as everywhere — or click it (Enter from the keyboard) to open the detail view, which carries the same triage. Read-only viewers can open cards but not drag them. The Ignored column fills only once ignored findings are loaded (Include ignored).
Screenshots view
The same findings as a gallery of captured screenshots, each card showing the domain and its risk score; click a card to open the finding.
List view
Findings are listed flat, highest risk first. The columns:
| Column | Shows | Default |
|---|---|---|
| Domain | The copycat domain, with an MX chip when it publishes mail records (it can receive mail — a phishing signal) and a note icon when it carries notes. ⌘/Ctrl-click opens the finding's page | Shown |
| Risk | The 0–100 score and its classification, in the same badge style as the dashboard's Changes detected panel; an asterisk marks a fallback assessment | Shown |
| Threats | The threat types the assessment attached — Brand impersonation, Phishing, Domain for sale — on one line, with what the page is doing and the model's reasoning in the tooltip | Shown |
| Status | The finding's status as a pill that opens a menu — triage without opening the finding | Shown |
| Jira | Raises a ticket in one click, or links to the linked ticket | Shown |
| Page | What the page is doing once assessed (Active page, Parked page, Redirects elsewhere, Inactive), otherwise its liveness state | Hidden |
| Impersonation | The impersonation score as a percentage | Hidden |
| Confidence | The model's confidence as a percentage | Hidden |
| Page title | The fetched page's title | Hidden |
| Finding date | When the domain was first seen | Hidden |
Hidden columns are switched on from the Columns menu; the choice is remembered. Every column sorts, and the sort order is the order every view and the detail view's previous/next controls follow.
Grouped arranges the list under the brand each finding trades on — each brand row carries its finding count and expands or collapses on click, with Expand all / Collapse all for the lot — and adds a Brand column. Flat is the default.
Filters and search
The filter bar sits above every view and works like the Issues page's:
| Filter | Options |
|---|---|
| Risk | High risk, Medium risk, Low risk, Benign |
| Page | Active page, Parked page, Redirects elsewhere, Inactive, Unknown |
| Threat | Brand impersonation, Phishing, Credential harvesting, Malware, Scam, Counterfeit goods, Affiliate abuse, Domain for sale, Typosquatting, Other |
| State | Serving, Dormant, Unresolved, Offline |
| Status | Pending review, Watching, Flagged, Ignored |
| Include ignored | Show ignored findings alongside the rest |
| Include low risk | Show hidden findings — below the risk floor, or not yet assessed by the model |
| Brand | Set by arriving from the Zones table or the dashboard; shown as a removable chip |
Options that would match nothing under the other filters are greyed out, so a filter never leads to an empty list by surprise. The search box matches the domain, its brands, a matched zone, and anything the assessment said — the site status, threat types, reasoning and page title — so searching for parked, counterfeit or login finds those findings.
Ignored findings are hidden by default, and so are findings below the risk floor or not yet assessed by the model; tick the two boxes to see them, or filter on the Ignored status. Filters (though not the search text) live in the URL, so a filtered view can be bookmarked or shared.
The detail view
In the Board, Screenshots and List views, click a finding to work it in place. The detail view is a slim card that paints instantly from the list row:
- the verdict — the risk badge, the threat types, what the page is doing, and whether it can receive mail; an ignored finding shows its reason here
- the model's reasoning
- the four scores and the confidence on one line
- the screenshot — click it to enlarge — and the page title
- the triage buttons: Pending review, Watching, Flagged, Ignored
The title shows where you are in the queue — 12 of 348 — and ← → (or ↑ ↓, or the arrow buttons) move to the previous or next finding in the order the list shows. P / W / F / I set the status from the keyboard. Triaging a finding advances to the next one automatically, so a queue can be worked through without extra clicks. The next finding's detail is fetched ahead of time.
Two controls sit in the title: View details page opens the finding's own page, and an arrow opens the copycat site itself in a new tab.
The finding page
Every finding has its own page — reach it from View details page, a
⌘/Ctrl-click on the domain in the list, the dashboard card, a Review
Pipeline row, a Jira ticket or a changelog entry, or directly at
/brand-protection/<domain>. It is the deep dive, in three cards:
- Why it scored N — the model's reasoning and bars for name similarity, impersonation, commercial, malicious and confidence.
- What the page serves — the screenshot, page title and description, the text excerpt, the final URL and HTTP status, the redirect chain and the outbound links.
- Signals — the liveness state, mail records, the brands and zones it resembles, how it was found, its visual distance from your own sites, and when it was first and last seen.
The page carries the same triage buttons and the Jira action, plus:
- Open site — opens the copycat domain in a new tab. It is opened without
a referrer and marked
nofollow, but it is still the suspect page: treat it as hostile, and do not enter anything into it. - Copy link — copies the page's address to share with a colleague.
- Back to Brand Protection — returns to the filtered list you left; from the Review Pipeline the link reads Back to Review Pipeline and returns there instead.
Statuses
| Status | What it means | What it does |
|---|---|---|
| Pending review | Nobody has looked yet; every new finding starts here | Sits in the review queue |
| Watching | Worth keeping an eye on | The domain is re-checked daily and you are notified when its page changes |
| Flagged | Something needs doing about this domain | Marks it for action; raise a Jira ticket to track that action |
| Ignored | A false positive, or a domain you have dealt with | Hidden from every view; the domain is never scanned or raised again |
Ignoring needs a reason of at least 10 characters (up to 500) — the dialog asks for it wherever a finding can be ignored: the list's status menu, the detail view, the finding page and the Review Pipeline. The reason stays beside the finding, in the detail view, on the finding page, in the pipeline's Ignored list and in exports. Every status change records who made it and when.
Setting a status from the detail view, the finding page or the Review Pipeline updates the finding everywhere at once, without a refresh.
Adding domains by hand
Discovery will not find everything: a registration a colleague spotted, a domain from a takedown notice, a competitor's lookalike that no search surfaces. Add domains in the page header takes a list — one per line, or separated by commas; a pasted URL is reduced to its hostname — and adds each as a finding. Choose a brand to attribute every domain to, or leave the choice open and each domain is matched to the brand whose name it contains.
A hand-added domain is checked, assessed and screenshotted exactly like a discovered one: a discovery run is queued at once, so its verdict and screenshot usually arrive within a few minutes (the page refreshes itself while it waits, and the finding reads Awaiting its first check until then). Two things differ from a discovered finding: it is never hidden — whatever it scores, and even before the model has assessed it — because you asked to see it, and it shows Added by hand as its source. Adding a domain you had ignored brings it back into review.
The dialog reports what it could not add: entries that are not hostnames, domains in your own inventory, domains that match none of your brands when no brand was chosen, and domains already listed. Up to 100 domains can be added at a time.
Notes
Every finding carries notes — a record of who thought what and when, kept beside the finding for the next reviewer. Add one from the detail view, the inspector, the finding page or the Review Pipeline row's page: type in the box and press Add note (or ⌘/Ctrl+Enter). Notes are append-only, as on issues, and up to 2,000 characters each. A finding with notes shows a note icon beside its domain in the list, the inspector and the Review Pipeline; the latest note's opening words travel with the finding in exports.
Jira tickets
With a Jira connection configured under Integrations, the Jira column, the detail view, the finding page and the Review Pipeline all raise a ticket for a finding in one click, and link to it once it exists. The ticket is titled Copycat domain: the-domain (its brands) and carries the domain, the brands and matched zones, whether it is serving and can receive mail, the risk score and classification, the threat types and the model's reasoning, plus a link back to the finding's page. A finding holds one ticket; the link survives every later re-check.
Export
Export (top right of the page) downloads every finding the current filters leave — one row per finding, in the order shown — as CSV or Excel. Both carry every field the list and detail views show:
Domain, Brands, Risk, Classification, Page, Site status, Threats, Status, Serving, Has MX, Similarity, Impersonation, Commercial, Malicious, Confidence, Assessment (the reasoning), Fallback assessment, Page title, HTTP status, Matched zones, Sources, Jira ticket, Jira URL, Screenshot URL, First seen, Last checked, Notes (the count).
The Excel workbook adds a Summary sheet with the export date, the row
count, and counts by classification and by status. The file is named
brand-protection-findings-<date>.