Overview
Teams organize analysts, ownership, escalation, and notifications within an organization. Open Settings → Account → Teams. The list is scoped according to your role:- Super Admins can view teams across the instance.
- Organization Admins can view teams in their current organization.
- Other users see teams to which they belong.
Create a team
Team creation requires an administrative role with team-create permission.1
Open Teams
Go to Settings → Account → Teams.
2
Start creation
Select Create team.
3
Configure Basic settings
Enter a team name and optional description. Team names contain between 2 and 50 characters in the creation form.A Super Admin selects the organization. An Organization Admin creates the team in their current organization.
4
Configure Classification
Select the team’s function and tier. You can also select an escalation team when the team participates in an escalation chain.
5
Add contact information
Optionally provide an email address, Slack channel, or Microsoft Teams channel reference.
6
Create the team
Submit the form, then open the team detail page to manage members and complete notification-channel configuration.
Manage a team
Select Manage or View from the team list. The action shown depends on your permissions.Basic settings
Administrators with team-management permission can update:- Name and description
- Team function and tier
- Escalation team
- Email address
- Slack and Microsoft Teams channel references
- Other available team defaults
Classification
Use function and tier values consistently so routing, reporting, and escalation behavior remain understandable across the SOC. When assigning an escalation team:- Confirm that the target team has the required coverage.
- Avoid circular escalation relationships.
- Review escalation ownership after organizational changes.
Manage members and roles
The team detail page displays active and pending members. Authorized administrators can:- Invite a member to the team
- Assign or change a team-scoped role
- Remove a member from the team
Configure team notifications
Open a team and select the Notifications tab. Team notifications are distinct from each user’s personal notification preferences.Slack
Slack delivery can use:- An authorized Slack workspace and channel
- A supported incoming webhook configuration
Microsoft Teams
Provide a supported Microsoft Teams webhook URL and enable the desired event types.Event controls
Depending on the configured channel, teams can enable notifications for events involving:- Cases
- Alerts
- Tasks
- SLA milestones and breaches
- Escalation and collaboration
- Correlation results
Channel settings and event filters are evaluated independently. Enabling an event does not deliver a message unless its destination channel is also configured and enabled.
Delete a team
Users with team-management permission can delete a team from its detail page. After deletion, CaseBender returns to the team list.Access and permissions
- All authenticated users can open the Teams section.
- Administrators create, edit, and delete teams according to their role.
- Non-administrators receive a view-only experience for teams in their allowed scope.
- The team detail page displays Access denied when a non-Super Admin opens a team outside their current organization.
- Management and notification controls are shown only when the user’s role has team-management permission.
Operational recommendations
Establish ownership
- Assign a clear function and tier.
- Maintain a monitored team email or collaboration channel.
- Identify a valid escalation team for after-hours or specialist support.
Control membership
- Grant only the role required for the member’s responsibilities.
- Remove stale memberships promptly.
- Review active and pending memberships during access reviews.
Test notifications
- Validate each destination after changing credentials or webhooks.
- Keep webhook URLs secret.
- Confirm that critical SLA and escalation events reach an attended channel.