Responses and playbooks
How to set up the playbook that reacts to attack verdicts, approve or reject proposed actions and review the response history.
A playbook defines the reaction to an attack verdict from the analysis agent: record the action or propose it for approval. The Respostas (Responses) screen gathers the actions waiting for a decision and the history.
Permissions
| Role | What it can do |
|---|---|
| Tenant Admin | View responses (responder.read), approve and run actions (responder.actions.execute) and edit playbooks (responder.playbooks.write). |
| Tenant User | Only view responses (responder.read). |
Refer to Roles and permissions.
When a playbook acts
Playbooks only act on Ataque (Attack) verdicts from an agent profile in active mode, with confidence equal to or above the minimum. A verdict with the Sombra (Shadow) badge does not trigger a playbook. Refer to AI analysis.
Each analysis produces at most one action, only on open incidents.
Actions
| Action | Effect |
|---|---|
| Resolver incidente (Resolve incident) | Closes the incident. |
| Marcar falso positivo (Mark false positive) | Marks the incident as a false positive. The subject can alert again after the cooldown. |
| Arquivar (Archive) | Archives the incident without resolving it. |
| Escalar (Escalate) | Posts a critical in-app notification, Incidente escalado: (Incident escalated:) followed by the rule name, to users who can see incidents. Accepts a Nota (opcional) (Note, optional) of up to 500 characters. |
Before running, Advisor asks for confirmation in a dialog: Resolver o incidente? (Resolve the incident?), Marcar como falso positivo? (Mark as false positive?), Arquivar o incidente? (Archive the incident?) or Escalar o incidente? (Escalate the incident?). When an action is not available, the screen shows Indisponível neste ambiente… (Unavailable in this environment…).
Set up the playbook
The playbook can apply to the whole tenant or to one rule.
- Tenant default: go to Detecção de Picos (Spike Detection) > Respostas > Resposta padrão (Default response) tab.
- Per rule: on the rule's detail page, Resposta automática (Automatic response) tab. Select Criar playbook desta regra (Create playbook for this rule) to give it its own playbook, or Remover playbook desta regra (Remove playbook for this rule) to go back to the default. Without its own playbook, the tab shows Vale o padrão do tenant (Tenant default applies).
Fields
| Field | Default | Use |
|---|---|---|
| Playbook ligado (Playbook on) | Desligado (Off) | Ligado (On) or Desligado (Off). |
| Modo (Mode) | Só registrar (Record only) | Só registrar (Record only) or Propor e aguardar aprovação (Propose and wait for approval). |
| Confiança mínima (%) (Minimum confidence) | 80 | Minimum confidence of the Ataque verdict for the playbook to act. |
| Ação (Action) | Escalar | The action the playbook records or proposes. |
| Nota do aviso (opcional) (Notice note, optional) | — | Text included in the notice. |
The modes:
| Mode | What happens |
|---|---|
| Só registrar | Creates an action with status Simulada (Simulated). Nothing runs. |
| Propor e aguardar aprovação | Creates a proposal in Aguardando decisão (Waiting for decision). It expires after 24 hours or when the incident closes. |
The Respostas screen
Go to Detecção de Picos > Respostas. The screen has three tabs:
- Aguardando decisão: proposals waiting for approval.
- Histórico: every action already decided, run, expired or simulated.
- Resposta padrão: the tenant's default playbook.
Columns include the action's Origem (Source: Manual, Playbook or Agente, Agent), Criada em (Created at) and Expira em (Expires at) for pending actions or Decidida em (Decided at) in the history.
Approve an action
- In the Aguardando decisão tab, select Aprovar (Approve) on the action's row.
- In the Aprovar: X? (Approve: X?) dialog, check the action.
- Select Aprovar e executar (Approve and run). The action runs immediately.
Reject an action
- In the Aguardando decisão tab, select Rejeitar (Reject) on the action's row.
- Fill in Motivo (obrigatório) (Reason, required), up to 500 characters.
- Select Rejeitar ação (Reject action).
Action statuses
| Status | What it means |
|---|---|
| Aguardando decisão (Waiting for decision) | Proposal waiting for approval. |
| Rejeitada (Rejected) | The proposal was rejected. |
| Expirada (Expired) | The proposal passed 24 hours or the incident closed before a decision. |
| Executando (Running) | The action is running. |
| Executada (Done) | The action finished. |
| Falhou (Failed) | The action could not finish. |
| Simulada (Simulated) | Recorded by Só registrar mode, not run. |