When an incident occurs, detecting the problem is only the beginning. The next challenge is understanding the environment around it: What asset is involved? Who has access? What changed recently? Is the configuration normal? Are other systems affected?
Without that context, responders spend valuable time jumping between portals, checking documentation, gathering configuration data, and trying to reconstruct what happened.
Liongard gives service and security teams access to current and historical asset intelligence across supported systems, helping them quickly establish context, investigate changes, and make more informed response decisions.
This helps MSPs:
Reduce time spent gathering incident context
Investigate configuration changes faster
Understand affected assets and identities
Validate current versus previous system state
Reduce portal hopping during investigations
Improve escalation and handoff between teams
Support root-cause analysis with historical evidence
Why context matters during incident response
An alert can tell you something happened. Responders still need to determine:
What system or asset is involved?
How is it configured?
Which identities or accounts are associated with it?
What changed before the incident?
Is the current configuration expected?
Is this isolated or part of a broader issue?
Liongard helps provide that surrounding operational context so teams can spend less time collecting evidence and more time investigating the incident.
Step 1 — Identify the affected asset or identity
Start by establishing what is involved in the incident.
Depending on the issue, use Liongard to review relevant:
Devices
Identities and accounts
Systems
Network infrastructure
Security configurations
Cloud environments
Asset Inventory can provide a centralized view of applicable device and identity data, helping responders understand what they are dealing with before taking action.
For an identity-related incident, for example, you might review the user's accounts, privileged access, MFA status, and other available identity information.
Step 2 — Establish the current state
Once you've identified the affected system, review its current configuration.
Depending on the Inspector and incident, this could include:
Account and permission settings
Security policies
Firewall configurations
Microsoft 365 settings
Endpoint configurations
Network settings
Licensing or service configurations
This gives responders a factual starting point for the investigation rather than relying on potentially outdated documentation.
Step 3 — Determine what changed
If the current state looks suspicious, use Liongard's historical inspection data and Change Detection to investigate what changed. Review:
Previous versus current values
Configuration changes
Identity and access changes
Policy modifications
Other changes relevant to the affected system
The timing of those changes can provide important clues during root-cause analysis.
For example, if a user suddenly experiences an authentication issue, seeing that MFA, group membership, or another relevant configuration changed shortly before the problem began can dramatically narrow the investigation.
Step 4 — Investigate with Roar Assistant
Roar Assistant can help responders quickly explore Liongard data and gather context conversationally.
Instead of manually searching through individual systems, responders can ask questions related to the investigation, such as:
What do we know about this device?
Which users have privileged access in this environment?
Which privileged accounts don't have MFA enabled?
Show me the relevant configuration for this system.
What should I review when investigating this issue?
Roar Assistant can help accelerate the initial investigation and point responders toward relevant Liongard data for deeper validation.
Step 5 — Correlate the evidence
An individual configuration change doesn't necessarily explain an incident.
Bring together the available context to understand the larger picture:
Asset context
What system is affected and what role does it play?
Identity context
Which users, administrators, or service accounts are relevant?
Configuration context
What is the system's current state?
Historical context
What changed before or during the incident?
Looking at these together helps responders distinguish normal operational activity from changes that may have contributed to the incident.
Step 6 — Escalate with context attached
When an issue needs to move from the service desk to a senior engineer, security team, or SOC, include the relevant Liongard findings in the escalation.
Instead of: “User can't log in. Please investigate.”
the receiving team can start with information about:
The affected identity or asset
Current configuration
Relevant historical changes
Privileged access
MFA or security-control status
Other findings already validated
That reduces duplicate investigation and helps the next responder start further into the troubleshooting process.
Step 7 — Use findings to prevent repeat incidents
Incident response shouldn't end when service is restored. After resolution, review what Liongard surfaced during the investigation and determine whether the finding should become part of a proactive workflow. For example:
Recurring configuration issue → Create or refine an Actionable Alert
Unexpected privileged access → Add it to your user access review process
Configuration drift → Establish a security change tracking workflow
Visibility gap → Expand Inspector or Asset Inventory coverage
This turns individual incidents into opportunities to strengthen future operations.
Example: Investigating a suspicious sign-in
A security team receives an alert for suspicious authentication activity involving a Microsoft 365 user. Using Liongard, the responder can:
Identify the user and review available identity context.
Check MFA and privileged-access information.
Review relevant configuration data.
Investigate historical changes that may provide additional context.
Use Roar Assistant to quickly explore related Liongard data.
Escalate the incident with the relevant evidence already collected.
Rather than beginning the investigation by gathering basic environmental information, the responder starts with a clearer understanding of the affected environment.
Best practices
Use Liongard early in the investigation to establish environmental context.
Review current and historical state before making configuration changes.
Look at asset, identity, configuration, and change data together.
Validate Roar Assistant findings against the underlying data when making response decisions.
Include relevant context when escalating incidents between teams.
Turn recurring findings into Actionable Alerts or standardized review processes.
Preserve historical context for post-incident and root-cause reviews.
Operational outcomes
Using asset intelligence during incident response helps MSPs:
Reduce investigation time
Reduce portal hopping
Improve root-cause analysis
Provide stronger escalation context
Reduce duplicate technician work
Make more informed remediation decisions
Improve collaboration between service and security teams
Turn incident findings into proactive operational improvements