See what a professional incident evidence pack looks like
Request a sample CasePack evidence pack or book a 20-minute workflow review to see how CasePack fits next to your PSA, SIEM, EDR, or existing incident process.
CasePack helps MSPs using Autotask-style PSA workflows document security incidents, collect evidence, build timelines, generate reports, and export client/auditor-ready evidence packs.
Autotask can remain the system for ticket operations, service delivery, assignments, queues, and client work management. CasePack is designed for the incident evidence workflow that ticketing systems often do not handle cleanly:
Ticket is created in Autotask
A security event becomes a ticket through client contact, monitoring, EDR/SIEM escalation, or internal triage.
CasePack receives the incident via webhook
Use CasePack webhook intake to create an incident in the right tenant workspace. For Autotask payloads, CasePack maps common fields like title to incident title, description to incident description, and priority to severity, with common mapping such as 1 = Critical, 2 = High, 3 = Medium, and 4+ = Low.
Evidence is collected in one incident workspace
Upload screenshots, logs, PDFs, email exports, IOCs, ticket exports, and other relevant artifacts.
The response timeline is built as work happens
Document containment, eradication, recovery, decisions, notes, and handover information.
Reports and evidence packs are generated
Create reports and export evidence packs for clients, insurers, auditors, or internal post-incident review.
A ticket export can show work history, but it often does not provide a polished incident package. A strong incident package should include:
CasePack gives MSPs a structured place to create that package without abandoning the PSA.
In CasePack, open the tenant that represents the client/workspace
Create a new webhook
Select Autotask as provider
Copy the generated webhook URL
Configure the Autotask-side automation or integration to send incident payloads
Test with a low-severity incident before production use
Security note: The generated webhook URL contains a secret token. Treat it as sensitive.
Use Autotask for ticket operations and CasePack for the structured incident evidence package your clients, auditors, or internal reviewers need.
Request a sample CasePack evidence pack or book a 20-minute workflow review to see how CasePack fits next to your PSA, SIEM, EDR, or existing incident process.
Autotask and Kaseya are trademarks of their respective owners. CasePack is not affiliated with or endorsed by Autotask or Kaseya.