---
title: Responses and playbooks
description: How to set up the playbook that reacts to attack verdicts, approve or reject proposed actions and review the response history.
updated: 2026-09-27
sidebarLabel: Responses and playbooks
---

A playbook defines the reaction to an attack verdict from the analysis agent: record the action or propose it for approval. The **Respostas** (Responses) screen gathers the actions waiting for a decision and the history.

:::note
Actions are internal Advisor governance: closing, archiving or escalating the incident. No setting in the customer's Cloudflare account changes.
:::

## Permissions

| Role | What it can do |
|---|---|
| Tenant Admin | View responses (`responder.read`), approve and run actions (`responder.actions.execute`) and edit playbooks (`responder.playbooks.write`). |
| Tenant User | Only view responses (`responder.read`). |

Refer to [Roles and permissions](/en/advisor/referencia/papeis-e-permissoes/).

## When a playbook acts

Playbooks only act on **Ataque** (Attack) verdicts from an agent profile in active mode, with confidence equal to or above the minimum. A verdict with the **Sombra** (Shadow) badge does not trigger a playbook. Refer to [AI analysis](/en/advisor/deteccao-de-picos/analise-por-ia/).

Each analysis produces at most one action, only on open incidents.

## Actions

| Action | Effect |
|---|---|
| Resolver incidente (Resolve incident) | Closes the incident. |
| Marcar falso positivo (Mark false positive) | Marks the incident as a false positive. The subject can alert again after the cooldown. |
| Arquivar (Archive) | Archives the incident without resolving it. |
| Escalar (Escalate) | Posts a critical in-app notification, **Incidente escalado:** (Incident escalated:) followed by the rule name, to users who can see incidents. Accepts a **Nota (opcional)** (Note, optional) of up to 500 characters. |

Before running, Advisor asks for confirmation in a dialog: **Resolver o incidente?** (Resolve the incident?), **Marcar como falso positivo?** (Mark as false positive?), **Arquivar o incidente?** (Archive the incident?) or **Escalar o incidente?** (Escalate the incident?). When an action is not available, the screen shows **Indisponível neste ambiente…** (Unavailable in this environment…).

## Set up the playbook

The playbook can apply to the whole tenant or to one rule.

- **Tenant default**: go to **Detecção de Picos** (Spike Detection) > **Respostas** > **Resposta padrão** (Default response) tab.
- **Per rule**: on the rule's detail page, **Resposta automática** (Automatic response) tab. Select **Criar playbook desta regra** (Create playbook for this rule) to give it its own playbook, or **Remover playbook desta regra** (Remove playbook for this rule) to go back to the default. Without its own playbook, the tab shows **Vale o padrão do tenant** (Tenant default applies).

### Fields

| Field | Default | Use |
|---|---|---|
| Playbook ligado (Playbook on) | **Desligado** (Off) | **Ligado** (On) or **Desligado** (Off). |
| Modo (Mode) | **Só registrar** (Record only) | **Só registrar** (Record only) or **Propor e aguardar aprovação** (Propose and wait for approval). |
| Confiança mínima (%) (Minimum confidence) | 80 | Minimum confidence of the **Ataque** verdict for the playbook to act. |
| Ação (Action) | Escalar | The action the playbook records or proposes. |
| Nota do aviso (opcional) (Notice note, optional) | — | Text included in the notice. |

The modes:

| Mode | What happens |
|---|---|
| Só registrar | Creates an action with status **Simulada** (Simulated). Nothing runs. |
| Propor e aguardar aprovação | Creates a proposal in **Aguardando decisão** (Waiting for decision). It expires after 24 hours or when the incident closes. |

:::tip
Start with **Só registrar**. **Histórico** (History) shows what the playbook would do before proposals enter the approval queue.
:::

## The Respostas screen

Go to **Detecção de Picos** > **Respostas**. The screen has three tabs:

- **Aguardando decisão**: proposals waiting for approval.
- **Histórico**: every action already decided, run, expired or simulated.
- **Resposta padrão**: the tenant's default playbook.

Columns include the action's **Origem** (Source: **Manual**, **Playbook** or **Agente**, Agent), **Criada em** (Created at) and **Expira em** (Expires at) for pending actions or **Decidida em** (Decided at) in the history.

### Approve an action

1. In the **Aguardando decisão** tab, select **Aprovar** (Approve) on the action's row.
2. In the **Aprovar: X?** (Approve: X?) dialog, check the action.
3. Select **Aprovar e executar** (Approve and run). The action runs immediately.

### Reject an action

1. In the **Aguardando decisão** tab, select **Rejeitar** (Reject) on the action's row.
2. Fill in **Motivo (obrigatório)** (Reason, required), up to 500 characters.
3. Select **Rejeitar ação** (Reject action).

:::caution
A proposal with no decision expires after 24 hours, or earlier if the incident closes.
:::

### Action statuses

| Status | What it means |
|---|---|
| Aguardando decisão (Waiting for decision) | Proposal waiting for approval. |
| Rejeitada (Rejected) | The proposal was rejected. |
| Expirada (Expired) | The proposal passed 24 hours or the incident closed before a decision. |
| Executando (Running) | The action is running. |
| Executada (Done) | The action finished. |
| Falhou (Failed) | The action could not finish. |
| Simulada (Simulated) | Recorded by **Só registrar** mode, not run. |

---

> Guardnet Docs · https://docs.guardnet.com.br/en/advisor/deteccao-de-picos/respostas-e-playbooks/
> Documentation index: https://docs.guardnet.com.br/en/llms.txt
