A playbook for the known procedure.
Make the order explicit: look up an endpoint, request approval, attempt isolation, then send the configured notification. Route rejection to an end state.
Explore AutomatioImperum gives security engineering teams a platform to connect their tools, build playbooks and agents, and inspect how they run. Bring data into a usable shape, turn a response procedure into reusable steps, and keep the decisions that need a person under your control.
HOST-042This example looks up the endpoint, waits for the configured approval, then attempts isolation and notification on the approved path. Rejection ends this path without isolation. Action policy may require additional review. Real runs require configured connectors, credentials, access and a valid target.
Security engineering starts with the tools already in place. Choose a connector, configure its credentials and supported ingestion endpoints, then map the fields that the next rule or playbook needs. Ingestion and normalization depend on the connector and its configuration.
device.hostnameHOST-042hostnameHOST-042Preview the transformed data before storing it. Check that the endpoint identifier needed for a later action is also available.
Less repeated translation. Analysts and automations can work from fields your team has deliberately mapped.
In Automatio, connect triggers, conditions, connector actions and approval steps on a canvas. Start visually or describe the workflow to generate a draft, then review its logic and field bindings. Test with sample inputs and inspect each node’s output before enabling it.
Make the order explicit: look up an endpoint, request approval, attempt isolation, then send the configured notification. Route rejection to an end state.
Explore AutomatioIn Agent Studio, adapt a template or build a custom agent. Define its instructions, tools and phases, and configure where risk requires approval.
Explore Agent StudioChoose test settings deliberately. Testing is not automatically isolated from your systems. Dry-run settings can simulate side effects while read actions and some AI analysis still execute; simulated approvals do not test a real reviewer’s decision.
An approval step gives your team a checkpoint before a sensitive action. Configure the approver, timeout and branches for that procedure. Then use Execution History to inspect node inputs, outputs and status when a run succeeds, fails or needs attention.
A reviewable handoff to operations. The next analyst can see what was attempted and inspect the result instead of reconstructing the procedure across tools.
Approval is configured, not universal. Timeout behavior can reject, approve or escalate. The example uses rejection on timeout; action policy may require additional review, and an approved request still needs a successful connector action.
With Virtus Optimus licensed, use Watch to review detection-health issues and Broken Pipe to investigate stopped ingestion or parser drift. Available verdict data can add context about noisy rules.
Explore Virtus OptimusDeveloper Studio lets your team define authentication and actions, then review and generate a connector. An OpenAPI description can provide a starting point; configure and verify the resulting connector for your environment.
Explore connector authoringReusable procedures reduce the steps analysts must coordinate by hand. Mapped inputs, explicit review points and per-step results give engineering a concrete place to investigate and improve the work.
Available modules and actions depend on your license, permissions and configured integrations. Validate the workflow in your deployment before relying on it.
Start with supported connectors for your existing tools. Check the particular actions and ingestion endpoints you need, then configure credentials and field mappings. A catalogue entry alone does not mean every capability is ready in your environment.
Yes. Add a Human Approval step and wire its approved and rejected branches. The default approval window is 60 minutes with rejection on timeout; these settings are configurable. This page’s example holds before isolation.
No. Execution settings matter. Dry-run behavior can simulate side effects, while read actions and some AI analysis still run. Simulated approval chooses an example branch without exercising the real approval process. Review your tools and test inputs accordingly.
Compare the same procedure over a defined period: runs completed, hands-on time before and after, approval effort and exception handling. Use execution records to understand what actually ran. Run duration alone is not analyst time saved.
Have any other questions?
Talk to our team
We’ll map its inputs, tools and approval points, then show how it could run in Imperum.