Features 2 min read

Collections

Organize clusters and articles into named collections for investigations, briefings, or ongoing tracking.

Collections let you group related clusters and articles into named sets. Use them to track an ongoing incident, prepare a briefing, or gather research on a specific threat actor or vulnerability.

Creating a Collection

  1. Open the Collections page from the left sidebar.
  2. Click New Collection.
  3. Give it a descriptive name (e.g., "Q2 Ransomware Tracking" or "Board Briefing - April").
  4. Optionally add a short description to help teammates understand the collection's purpose.
  5. Click Create.
Tip: Name collections by purpose rather than date alone. "Salt Typhoon Investigation" is easier to find than "April Research."

Adding Items to a Collection

You can add both clusters and individual articles.

From a Cluster Page

  • Click the Add to Collection button in the cluster header.
  • Select one or more existing collections, or create a new one on the spot.
  • The entire cluster (and its associated articles) is added as a single entry.

From an Article Page

  • Click the bookmark icon or Add to Collection on any article.
  • Choose the target collection.

Managing Collections

Open a collection to see all its items listed chronologically. From here you can:

  • Remove items by clicking the X next to any entry.
  • Edit the name or description using the pencil icon in the collection header.
  • Share the collection with users on the same domain by toggling the Share option. On Business and MSSP tiers, colleagues with verified email addresses on the same domain can view shared collections.
Note: Collection sharing uses domain-based visibility, the same as tag sharing. Free and Researcher tier collections are private.

Deleting a Collection

  1. Open the collection you want to remove.
  2. Click the three-dot menu in the top-right corner.
  3. Select Delete Collection and confirm.

Deleting a collection does not delete the underlying clusters or articles -- it only removes the grouping.

Use Cases

Incident tracking -- Create a collection at the start of an incident and add every relevant cluster and article as they surface. This gives your team a single view of all related intelligence.

Weekly briefings -- Maintain a rolling collection for each briefing cycle. Add noteworthy clusters throughout the week, then walk through the collection during your team meeting.

Research topics -- Track a threat actor, malware family, or vulnerability over time. As new clusters appear, add them to keep your research organized in one place.

Stakeholder reporting -- Build a collection of high-impact items, then share the link with leadership or external partners who need a curated view without sifting through the full feed.