Pre-stage
The playbook does everything up to the action, then stops. Staged actions appear on the alert's Response tab and in the notifications of the analysts who opted in. A person confirms or rejects each one. Confirmation executes the action with the confirming analyst's identity.
Auto
Actions execute without confirmation when all of the following hold:
- the playbook is in auto mode;
- the advisory verdict is malicious with confidence at or above the playbook's threshold, and the evidence grade is at or above the deployment's minimum;
- the action is within the organization's automation ceiling.
If any condition fails, the action is staged instead and the run trace says why.
The ceiling
Settings › Organizations › the organization › Automation sets the ceiling: the most consequential action a playbook may take automatically for that organization. Levels run from notify only, through close and escalate, to host isolation and account disablement. A provider can give a cautious customer a low ceiling and a customer who signed for it a high one; playbooks do not need to change.
Reversibility
Every automatic action is recorded with the run that took it and can be reversed from the alert or case: release isolation, unblock an application, re-enable an account where the connector supports it. The reversal is audited too.