My team recently stood up Cisco's Secure Network Analytics (SNA) utilizing it's Adaptive Network Control (ANC) Policy enforcment with ISE via pxGrid but SNA is using the default alarm thresholds which are triggering quarantines within the production environment. I have been attempting to associate/disassociate actions to the various rules but cannot seem to make any edits to them and wanted to know if I am simply going about it wrong? I have the Primary Admin role within SNA. 
In short, I hope to associate the ISE ANC Policy (Alert) action to the Rule instead of (Alarm) so that we will still get flags for the alarms/criteria within SNA that would normal trigger the Quarantine but without actuallying having ISE enforce the policy. If we monitor the triggers and discuss the results with our users we can then determine if raising the thresholds is the appropriate action for our environment or attempt to convince them that the existing thresholds are logical and will remain in place and to adjust their behavior accordingly. 
Please let me know if you know a way of adjusting the actions associated with each rule or if you can propose a better means of capturing the alarm triggers without the ANC policy applying any form of quarantine. Alternatively, if we simply disable the ANC policy how can we still clearly identify who and when is triggering the alarms in a simple to decipher pane. When using the Security Dashboard we have to dig around to gather all the related flows/information when a Alarm trigger is met.