@CohesitySiem Thank you for reaching out to us, never tested this scenario at my end, but this approach should help the incidents API can be used to Get, Create or Update Sentinel Incidents.
LogicApps have an HTTP action that can be used to GET the incidents using the incidents API, you might need to play around a little to parse (using the parse json action in LogicApps) and de-dup, but once you do, should be able to modify or delete the incidents based on incident IDs.
Reference:
https://learn.microsoft.com/en-us/rest/api/securityinsights/stable/incidents
https://learn.microsoft.com/en-us/azure/logic-apps/logic-apps-create-api-app
Also you can refer to this GitHub repository https://github.com/Azure/Azure-Sentinel/tree/master/Playbooks will guide in developing your approach you are looking for.
Let me know if you have any further questions.