Withdrawing a case is for when triage turns out to have been wrong — a false positive discovered mid-drafting, a component that turns out not to be used the way the SBOM implied, or an alert that should never have opened a case. It's the one clean way out of a case that's running down a clock that no longer applies.
Before you start
- Withdrawal is reachable from any state except the two terminal ones:
closedand already-withdrawn. If a case has already reachedclosed, there's nothing to withdraw. - You need
cases.writepermission.
Steps
- Open the case.
- Find Withdraw this case, below the case's main actions.
- Enter a reason. You'll be asked for one — the case won't let you withdraw with an empty field.
- Confirm. This is a one-way move: a withdrawn case leaves the live list and cannot be reopened.
What you should see
The case moves to withdrawn and drops off the live list on Cases, appearing
in the closed list instead, labeled Withdrawn rather than Reported and
closed — those are different endings and the product keeps them visibly
different. Nothing about the case is deleted: your reason, and everything that
happened before withdrawal, stays in the evidence pack.
Withdrawal isn't the same as being wrong to have triaged carefully
Opening a case and then withdrawing it isn't a mistake to avoid — it's what careful triage sometimes produces once more information is available. The reason you give is what makes that visible later, to you or to an auditor, rather than leaving an unexplained gap in the case history.