See what a professional incident evidence pack looks like
Request a sample CasePack evidence pack or book a 20-minute workflow review to see how CasePack fits next to your PSA, SIEM, EDR, or existing incident process.
CasePack sits beside your PSA and helps MSP teams convert ticket-driven incident work into timelines, evidence collections, client-ready reports, audit history, and PDF/ZIP evidence pack exports.
ConnectWise can remain the system your MSP uses for tickets, service work, assignments, and operational tracking. CasePack focuses on the incident evidence layer around that workflow:
Ticket or alert starts in ConnectWise
A security-related ticket is created from a client request, monitoring alert, EDR/SIEM workflow, or technician action.
Send key incident details to CasePack
Use a CasePack webhook to create an incident in the relevant tenant workspace. For ConnectWise payloads, CasePack maps common fields like summary to incident title, board.name to description context, and priority or severity fields to CasePack severity where available.
Build the evidence record in CasePack
Add screenshots, logs, IOCs, PDFs, ticket exports, emails, and other artifacts directly to the incident.
Create the response timeline
Document containment, eradication, recovery, notes, decisions, and client communication.
Generate client/auditor-ready outputs
Use CasePack reports and evidence pack exports to produce a cleaner deliverable than a raw PSA ticket export.
| Workflow area | ConnectWise | CasePack |
|---|---|---|
| Service ticket | Primary system | Reference/source context |
| Technician assignment | Primary system | Optional context |
| Incident evidence | Possible attachments | Dedicated incident evidence vault |
| Response timeline | Ticket notes/comments | Structured chronological incident timeline |
| Client-ready report | Manual or ticket export | Built-in incident report templates |
| Audit-ready package | Manual assembly | PDF/ZIP evidence pack export |
| NIS2 milestones | Manual/custom | Opt-in milestone tracking per incident |
Ticket systems are excellent for managing work, but security incidents often need a more formal evidence and reporting package. CasePack gives MSPs a repeatable way to answer:
Open CasePack Webhooks in the target tenant
Create a new webhook
Select ConnectWise as the provider
Copy the generated webhook URL
Configure your PSA or automation workflow to POST incident data to the URL
Test with a low-severity incident before production use
Security note: Treat the webhook URL as a secret. Rotate by creating a new webhook if exposed.
Your PSA should manage the work. CasePack helps turn the incident into a professional record with evidence, timeline, reports, audit history, and exports.
Request a sample CasePack evidence pack or book a 20-minute workflow review to see how CasePack fits next to your PSA, SIEM, EDR, or existing incident process.
ConnectWise is a trademark of its respective owner. CasePack is not affiliated with or endorsed by ConnectWise.