Automations let you define rules that act on detections automatically, changing a detection's status, applying a tag, or adding a note, without requiring an analyst to review and triage each one manually. You review and activate everything yourself: nothing runs until you turn an automation on.
This article describes how to access Automations, how the automation list is organized, how to create, edit, pause, and delete an automation, and how priority order and permissions work.
About Automations
Every automation follows a WHEN / IF / THEN structure. WHEN defines the trigger, such as the detection status an automation starts from. IF defines the conditions, or parameters, that must match. THEN defines the action or actions taken when those conditions are met.
Automations currently apply to the Ticket and Credential detection types. Support for the EASM Exposure detection type is coming soon.
Accessing Automations
To access Automations, perform the following:
In the top navigation bar, click the settings gear icon.
In the Settings menu, click Automations.
Note: If you do not see the option to create, edit, pause, or delete automations, your user profile only has view access. Contact a user with the Manager profile to make changes.
The Automations List Page
The Automations list page shows every automation configured for the selected account in priority order. Each row shows the automation's name and detection type, how many threats it auto-triaged in the last 30 days, the status it runs on, and the actions it performs.
List columns
Column | Description |
Order | The automation's priority position in the list. Automations are evaluated top to bottom; drag a row using the handle to change its position. |
Automations | The automation's name and its detection type (Ticket, Credential, or EASM (Soon)). |
Threats auto-triaged (30 days) | The number of detections this automation acted on in the last 30 days. |
Runs when | The detection status (or statuses) this automation triggers from. |
Actions | The action(s) the automation performs when its conditions are met. |
Status | Active or Paused. |
Filtering and searching automations
"Search items" is a free-text field that searches automations by name. Use the Filter menu to narrow the list by:
Automation type: Ticket, Credential, or EASM (Soon).
Status: Active or Paused.
Reordering automation priority
If a detection matches the conditions of more than one automation, only the highest-priority matching automation runs for it. Because of this, the order of automations in the list determines which rule wins when more than one could apply.
To change the order, drag a row by its handle (the dotted icon on the left of each row) to a new position in the list. You can also set the exact position from the Automation priority order field while creating or editing an automation.
Creating an Automation
To create an automation, perform the following:
On the Automations list page, click + New automation.
Choose how you want to start: Start from a template to prefill the builder with a proven pattern for your product, or Build manually to compose the trigger, conditions, and actions yourself.
Starting from a template
The template gallery groups templates by category: Brand Protection, Online Piracy, Data Leakage, Deep & Dark Web, VIPs, and EASM (Soon). Selecting a template prefills the builder with its trigger, conditions, and actions, which you can then adjust to fit your needs before saving.
Building an automation manually
Whether you start from a template or from scratch, an automation is configured in the same four sections.
Step 1: Name and Priority
Enter or select the following:
Automation name: a descriptive name for the automation.
Automation priority order: the position of this automation relative to your other automations. You choose this position yourself; if a detection matches more than one automation, only the one with the highest priority runs for it. You can change this position later from the Automations list page.
Detection type: Ticket, Credential, or EASM (Soon).
Description (optional): a short note describing what the automation does, shown on the automation's detail page.
Step 2: Condition (WHEN)
Define the trigger for the automation, such as the detection status it starts from (for example, Open) and, optionally, the asset(s) or ticket type(s) it applies to.
Important: If you don't select an asset or a ticket type, the automation applies to all assets and all ticket types.
Step 3: Parameters (IF)
Add one or more conditions using the detection's attributes (for example, Impersonation is High, Logo similarity is greater than 70%, or the Domain contains a keyword). Combine multiple conditions using the "Add parameter" option.
Step 4: Action (THEN)
Choose one or more actions to run when the conditions in Step 3 are met. You can add more than one action to the same automation; all of them run together when the conditions are met. The following actions are currently available:
Action | Description |
Change status | Changes the detection's status (for example, to Incident or Treatment). Some status options, such as Takedown, depend on the corresponding product being contracted and having available credits. If the entitlement or credit check fails, the action does not run, and the failure is recorded in the automation's audit log with the reason. |
Add tag | Applies one or more tags to the detection. |
Add note | Adds a note to the detection, useful for recording the reason a detection was triaged automatically. |
Assign to (Soon) | Will assign the detection to a specific user. |
Click + Add action to add another action to the same automation.
Previewing impact before activating
Before saving, click Preview and save to open the Preview impact panel. This dry-run shows, over the last 30 days:
The number of matched detections and automated actions the rule would have produced.
A plain-language rule summary (WHEN / IF / THEN) so you can double-check the logic.
A sample of matched detections, so you can confirm the rule is catching the right threats.
The automation's resulting priority position and a reminder that only the first matching rule runs per detection.
No action is taken during preview. Click Active automation to save and activate the automation.
Important: Once active, a new automation applies retroactively to all existing detections that match its conditions, in addition to all new detections going forward.
Editing an Automation
To edit an automation, perform the following:
On the Automations list page, click the automation you want to edit, or click the ⋯ menu on its row and select Edit.
Click Edit automation.
Update the name, condition, parameters, or actions as needed.
Click Preview and save, review the impact, and click Active automation to save your changes.
Note: Changes to an existing automation are not applied retroactively, unlike a newly created automation. The updated rule only affects detections going forward. To apply a rule retroactively, create a new automation.
Pausing an Automation
Pausing an automation stops it from running without removing it from the list. A paused automation remains visible with a "Paused" status, and you can reactivate it at any time.
To pause an automation, perform the following:
On the Automations list page, click the ⋯ menu on the automation's row.
Click Pause.
To reactivate a paused automation, open it and click Active automation, or use the ⋯ menu and select Active again.
Deleting an Automation
Deleting an automation permanently removes it from the Automations list. This action cannot be undone. To delete an automation, perform the following:
On the Automations list page, click the ⋯ menu on the automation's row.
Click Delete.
Automation Permissions
Only users with the Manager profile can create, edit, pause, or delete automations. Users with other profiles can access the Automations list and view each automation's configuration and audit log, but all write actions are disabled for them.
Reviewing Automation Details and the Audit Log
Click an automation in the list to open its detail page. This page shows the automation's Description, its Threats auto-triaged (30 days) count, and its WHEN / IF / THEN configuration.
At the bottom of the detail page, the Audit log has two tabs:
Timeline: a chronological record of every change to the automation (created, edited, paused, reactivated) and every execution outcome, including failures (for example, a blocked action due to a missing entitlement or insufficient credits), each with the acting user and timestamp.
Runs: the individual detections the automation has acted on.
Are you still using the previous version of Automations? Refer to the [Automations — Legacy Experience] article for the corresponding instructions.
If you have any questions, feel free to reach out at [email protected] 😊
