A shift bounds automatic pickup; it does not enable it. An agent investigates on its own only when its own configuration says to process incidents automatically for the incident’s severity, and a shift then decides when that happens. See Configuring Security Delivery Agents for the automatic-processing configuration itself.
Who is this for? Workspace Owners create and manage shifts. Everyone using Agent Center benefits from the visibility: each agent shows whether it is on shift right now, so an untouched incident reads as “off shift by design” rather than “something is broken”.
Creating a shift
1
Open the investigation policies
In Workspace Manager, open the workspace and select the Agents tab, or open the agent in Agent Center and select its Policies tab.
2
Add a shift
Click Add policy, then choose Add a shift. The shift editor opens with the most common schedule already painted: Monday to Friday, 9:00 to 17:00.
3
Paint the working hours
Click an hour to toggle it, or click and drag to paint a range. The Weekdays 9:00 to 17:00 button restores the standard week, and Clear empties the grid.
4
Pick the timezone
The schedule keeps these wall-clock hours year round in the timezone you choose, which defaults to your own. Daylight saving changes never shift the working hours.
5
Name it and save
The live preview reads the schedule back in plain words, for example “Investigates on its own between 09:00 and 17:00 on weekdays (Berlin time).” Save, and the shift appears as a row in the policy list.
A shift with no hours painted means the agent never investigates on its own; your team triggers every investigation manually. A shift covering every hour of the week cannot be saved, because it would not limit anything.
How shifts behave
- Outside the shift, new incidents wait for people. An automatically triggered investigation outside the painted hours is skipped, the incident stays in your queue, and the skip is recorded in the workspace audit trail. Nothing re-runs it automatically when the shift resumes; off-shift work belongs to your team.
- Manual triggering always works. A person can start an investigation at any hour, on or off shift. Shifts schedule the agent’s autonomy, never your team’s access to it.
- Shifts are policy rows. Each shift appears in the investigation policy list with a Shift badge and its schedule sentence, and can be reordered, turned off, or deleted like any policy. See Workspace Policies for how ordering works.
Editing and converting a shift
Editing a shift always reopens the schedule grid with the stored hours painted exactly as saved. If a schedule stops being enough, convert the shift into a general policy: open the shift and choose Edit as a general policy. Conversion keeps what the policy does but swaps the grid for the condition builder, where you can add incident conditions alongside the schedule. Conversion is one way; a converted policy cannot become a shift again, which the confirmation states before anything changes.On-shift and off-shift in Agent Center
Agent Center shows each agent’s current state wherever the agent appears:- The agents table shows a subtle On shift or Off shift chip next to the agent’s status. Hover it for the full sentence, including when the state next changes, for example “Off shift. New incidents wait for people until Monday 09:00 (Berlin time); anyone can still start an investigation.”
- The agent’s overview shows the same chip beside the deployment status, plus a Shift row with the full sentence.
- Agents without shifts show nothing. No badge, no noise. Most agents run around the clock, and the absence of a chip means exactly that.
- Only operational agents show a state. A paused or undeployed agent is not working regardless of the clock, so its shift state is not shown.
- The state is read at page load. It refreshes when you reload or revisit the page; there is no live ticker.
Roles and permissions
Frequently asked questions
What happens to incidents that arrive off shift?
What happens to incidents that arrive off shift?
They stay in your incident queue like any other incident, and the skipped automatic investigation is recorded in the workspace audit trail. When the shift resumes, the agent picks up newly arriving incidents; it does not go back through the queue on its own.
Can I trigger an investigation while the agent is off shift?
Can I trigger an investigation while the agent is off shift?
Yes, always. Manual triggering is never blocked by a shift. That is the point of a shift: it schedules autonomy, not access.
Does creating a shift make my agent start picking up incidents automatically?
Does creating a shift make my agent start picking up incidents automatically?
No. Automatic pickup comes from the agent’s own configuration, which says which incident severities it processes automatically. A shift bounds when an agent configured that way works on its own; for an agent without automatic processing, a shift changes nothing.
Can one agent have multiple shifts?
Can one agent have multiple shifts?
Yes. Each shift is its own policy row, and the agent investigates on its own only in hours every shift allows. Most workspaces need exactly one.
How do daylight saving changes affect a shift?
How do daylight saving changes affect a shift?
They do not change the working hours. A 9:00 to 17:00 shift stays 9:00 to 17:00 on the wall clock of its timezone all year.
Why does an agent show no shift chip?
Why does an agent show no shift chip?
Either its workspace has no shifts, in which case the agent runs around the clock and no state is shown by design, or the agent is currently paused or not deployed.
Can I turn a general policy into a shift?
Can I turn a general policy into a shift?
No. Conversion is one way, from shift to general policy. To schedule with the grid again, create a new shift.
Related guides
Workspace Policies
The ordered allow and block rules that shifts are part of.
Configuring Security Delivery Agents
Set up and configure agents using the three-phase adoption model.
Agent Execution History
Monitor and audit agent activity with a complete execution trail.
Deploying Agent Center
Deploy the Azure AI Foundry infrastructure required for agents.
Questions about Agent Shifts? Contact us at support@contraforce.com.