Configure Linivo as a detection source feeding a SOC, with the right routing, retention and access model for that workflow.
Under Detections > Routing, send security-category detections (lateral movement, port scan, rogue device) to your SOC's channel or ticketing queue, and keep general performance alerts on a separate rotation.
Set detection and access-log retention to match your incident-response and audit requirements under Settings > Data > Retention; this is typically longer than the default retention for routine performance metrics.
Give SOC analysts the Auditor role: full visibility into detections, topology and logs, without the ability to change device configuration or alert thresholds.