> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/establish-case-context.md).

# Establish case context

Before you start to analyze the case, review the case title and description to establish case context. You can also review the case score, the assignee, and decide whether to star the case.

**AI-generated case summaries**

To gain immediate situational awareness, Cortex AgentiX automatically builds a narrative of the case using **AI-generated titles and descriptions**. This summarized context allows you to quickly grasp the scope of a case and provides a clear starting point for your investigation.

Leveraging LLM-based summarization, the system analyzes complex data to produce a human-readable overview of:

* The nature of the threat or activity
* The key issues and artifacts involved
* The affected assets or identities

**View the AI-generated case summary**

When you open a case, the case title and summary is automatically generated. As an investigation evolves, the case context is updated. Each time new data or issues are added, the system regenerates the title and description to ensure your situational awareness reflects the most current information available.

{% hint style="info" %}

### Note

The AI-generated title and description is a calculated value that is regenerated each time you open a case.

This value is not a saved static description, therefore it is not reflected in the saved case names in the list of cases in the **Split view** , or in the **Case Name** and **Case Description** columns in the **Table view**.
{% endhint %}

**System-generated case titles and descriptions**

In addition to the AI-generated case titles and summaries, Cortex AgentiX automatically generates static case titles and descriptions that are stored in the cases dataset. These are generated at the time of case creation based on correlated issues, behaviors, and contextual data.

These static descriptions are used when AI-generated case summaries are unavailable or disabled. In addition, they are reflected in the case title in the List of cases in the **Split view**, and the **Case Name** and **Case Description** columns in the **Table view.**

You can manually update these values. From the **Actions** ![Actions\_icon.png](/files/F3FSSVjsoefaiDWBYhBc) menu select **Edit case details**.

**Single issue cases**

For cases that contain a single issue, the case title and description directly reflect the issue’s title and description. In addition, AI-generated case summaries are not available. If more issues are linked to the case, Cortex AgentiX generates a case title and description to reflect the issues in the case, and a AI case title and summary is available.

**Limitations**

* **Supported regions:** AI-generated case titles and summaries are available only in supported regions. For more information, see [Cortex AgentiX supported regions](/cortex-agentix/onboard-cortex-agentix/deployment-steps/activate-cortex-agentix/cortex-agentix-supported-regions.md).
* **Supported domains:** AI-generated case titles and summaries are only supported for cases assigned to the **Security** domain.
* **Single-issue cases:** For cases that contain a single issue, AI-generated case summaries are not available. Instead, the case title and description directly reflect the issue’s title and description. If more issues are linked to the case, an AI case title and summary is generated.

**Enable AI summarization**

To enable AI case summarization on your tenant, go to Configurations → **General** → **Server Settings** → **AI Configuration** and enable the following settings:

* **Agents & LLM Experience**
* **AI Case Summarization**

You can also turn AI summarization on or off for a specific case. Take the following steps:

1. Open the case, click the **Actions** menu.
2. Select **Edit case details**.
3. Switch the **Summarize with AI** toggle.

**Assess case severity and score**

You can review the severity and score assigned to the case, and update them if necessary.

**Review case severity**

The severity value indicates the urgency of a case. Possible values are **Critical**, **High**, **Medium**, and **Low**. Click on the assigned severity to change the value.

**Review the case score**

The assigned case score is displayed in the cases header. This score indicates the urgency and impact of the case.

Click on the case score to see the assigned scoring method. For more information about scoring types and how Cortex AgentiX assigns a score, see [Case scoring](/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/case-concepts/case-scoring.md).

**See a breakdown of the score**

You can see details about the scoring method and the assigned score.

1. On the **Cases** page, click on the menu icon to switch to the detailed view.
2. Click on an assigned score.

If you are not satisfied with the score, you can change the scoring method or overwrite the score by setting the score manually. If you see a discrepancy with the assigned score, consider the following:

* For rule-based scores, revise your scoring rules.

**Change the scoring method or set the score manually**

You can change the default scoring method. In addition, if Cortex AgentiX was unable to assign a score, you can set the score manually.

1. Click on the assigned score.

   If no score was assigned, in the case investigation pane, click the more options icon and select **Manage Score**.
2. Select a different scoring method, or click **Set score manually** and define a new score.

**Update case attributes**

When you start reviewing a case, you can update the case title and description, assign the case, and star a case.

<details>

<summary>Assign a case</summary>

You can assign or reassign a case by clicking on the assigned field.

If the case contains unassigned issues, or the issues are not assigned to the case assignee, a dialog opens with options for assigning the issues.

</details>

<details>

<summary>Update the case title and description</summary>

A case title and description is automatically generated for each case. In addition, AI-generated case summaries are automatically generated when you open a case to provide case context.

You can manually update the saved case description, as required.

1. Select a case and open the **Actions** ![Actions\_icon.png](/files/F3FSSVjsoefaiDWBYhBc) menu.
2. Select **Edit case details**.
3. Update the values in the **Case title** and **Case description** fields.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>The defined values are shown in the <strong>Case Name</strong> and <strong>Case Description</strong> columns in the <strong>Table</strong> view, and saved to the <code>cases</code> dataset. The case title is also shown the list of cases in the <strong>Split</strong> view.</p><p>These values do not replace the AI-generated case title and summary. If the <strong>Summarize with AI</strong> toggle is enabled, AI-generated case summaries are automatically generated when you open a case. For more information about how Cortex AgentiX generates case titles and descriptions, see <a href="#ai-generated-case-summaries">AI-generated case summaries</a>.</p></div>
4. Save your changes.

</details>

<details>

<summary>Star or un-star a case</summary>

You can manually star or un-star a case:

1. Go to Cases & Issues → Cases and select the case that you want to star.
2. Depending on the selected view, take the following action:
   * In the **Split** view, open the **Actions** menu and select **Edit case details**. Switch the toggle to star or un-star the case.
   * In the **Table** view, select one or more cases and right-click. Select whether to star or un-star the cases.

</details>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/establish-case-context.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
