Works beside your PSA

Turn ConnectWise incident tickets into structured evidence packs

CasePack sits beside your PSA and helps MSP teams convert ticket-driven incident work into timelines, evidence collections, client-ready reports, audit history, and PDF/ZIP evidence pack exports.

CasePack does not replace ConnectWise

ConnectWise can remain the system your MSP uses for tickets, service work, assignments, and operational tracking. CasePack focuses on the incident evidence layer around that workflow:

  • structured incident record
  • evidence vault
  • response timeline
  • NIS2 milestone tracking where needed
  • report templates
  • audit log
  • evidence pack exports

ConnectWise-style workflow

  1. 1

    Ticket or alert starts in ConnectWise

    A security-related ticket is created from a client request, monitoring alert, EDR/SIEM workflow, or technician action.

  2. 2

    Send key incident details to CasePack

    Use a CasePack webhook to create an incident in the relevant tenant workspace. For ConnectWise payloads, CasePack maps common fields like summary to incident title, board.name to description context, and priority or severity fields to CasePack severity where available.

  3. 3

    Build the evidence record in CasePack

    Add screenshots, logs, IOCs, PDFs, ticket exports, emails, and other artifacts directly to the incident.

  4. 4

    Create the response timeline

    Document containment, eradication, recovery, notes, decisions, and client communication.

  5. 5

    Generate client/auditor-ready outputs

    Use CasePack reports and evidence pack exports to produce a cleaner deliverable than a raw PSA ticket export.

Create a tenant-scoped webhook to receive ConnectWise-style incident payloads.
The incident lands in CasePack ready for evidence, timeline, reports, and export.

What stays in ConnectWise vs CasePack

Workflow areaConnectWiseCasePack
Service ticketPrimary systemReference/source context
Technician assignmentPrimary systemOptional context
Incident evidencePossible attachmentsDedicated incident evidence vault
Response timelineTicket notes/commentsStructured chronological incident timeline
Client-ready reportManual or ticket exportBuilt-in incident report templates
Audit-ready packageManual assemblyPDF/ZIP evidence pack export
NIS2 milestonesManual/customOpt-in milestone tracking per incident

Why MSPs add CasePack to PSA workflows

Ticket systems are excellent for managing work, but security incidents often need a more formal evidence and reporting package. CasePack gives MSPs a repeatable way to answer:

  • What happened?
  • What evidence was collected?
  • What actions were taken?
  • What was communicated?
  • What is ready for the client, insurer, auditor, or compliance review?

Webhook setup summary

  1. 1

    Open CasePack Webhooks in the target tenant

  2. 2

    Create a new webhook

  3. 3

    Select ConnectWise as the provider

  4. 4

    Copy the generated webhook URL

  5. 5

    Configure your PSA or automation workflow to POST incident data to the URL

  6. 6

    Test with a low-severity incident before production use

Security note: Treat the webhook URL as a secret. Rotate by creating a new webhook if exposed.

Keep ConnectWise for tickets. Use CasePack for the evidence package.

Your PSA should manage the work. CasePack helps turn the incident into a professional record with evidence, timeline, reports, audit history, and exports.

Frequently asked questions

No. CasePack is designed to complement PSA workflows by adding structured incident evidence, timelines, reports, audit logs, and exportable evidence packs.

CasePack supports webhook intake. A ConnectWise-style payload can create a new incident in the relevant tenant workspace.

CasePack documentation describes mapping fields such as summary to title, board name to description context, and priority/severity values to CasePack severity where available.

Yes. The PSA can remain the operational ticketing system while CasePack is used for incident evidence packaging and reporting.

No. ConnectWise is a third-party product and trademark of its respective owner. CasePack is not affiliated with or endorsed by ConnectWise.

See what a professional incident evidence pack looks like

Request a sample CasePack evidence pack or book a 20-minute workflow review to see how CasePack fits next to your PSA, SIEM, EDR, or existing incident process.

ConnectWise is a trademark of its respective owner. CasePack is not affiliated with or endorsed by ConnectWise.