I agree with @ddelboccio -- If the alert is for a message marked as phishing, then it has already been marked as phishing for that/those users, but if other users also received the same email, or a similar email and have not already marked it as phishing, then taking this action at an administrative level is a good practice. Sometimes it takes some further investigation (i.e. messages with similar subjects, DKIM domains, etc.) to find the additional messages. Spend as much time on it as you feel comfortable!
Here's an article which may help provide some guidance: https://support.google.com/a/answer/11123535