Incidents (Write)
Two-way write routes addressed by the incident Display ID (for example XVA-1234).
Update an incident (status / priority / assignee / comment)
Applies partial updates to a single incident identified by its Display ID (`XVA-<number>`).
Reassign an incident to a user (by email)
Dedicated assignee route for SOAR playbooks. Set `assignee_email: null` to unassign.
Post a comment on an incident
Attaches a free-text comment (max 10,000 chars). **Dedup:** identical text on the same
Bulk update incidents (async job)
Selects incidents by explicit `incident_display_ids` and/or filter fields (`status`,