Playbooks

Repeatable procedures for common work across your stack, with the evidence to gather, steps to follow, and answer to produce.

Public catalog

Browse publicly. Limited beta access.

Filters
Work area

23 Playbooks

Browse all

Service desk

Triage service ticket

Investigate a service ticket, identify likely cause and impact, and recommend the next action using current evidence.

Uses Service tickets and Customer records

Security

Investigate client security

Collect and correlate security evidence for one customer, then prioritize remediation.

Uses Security findings and Security assets

Customer success

Prepare client review

Prepare a concise client review from operational, device, identity, documentation, and security evidence.

Uses Customer records and Service tickets

Identity

New-user onboarding readiness

Check the identities, licenses, groups, devices, and documentation needed for a complete new-user onboarding.

Uses User directory and Licensing

Identity

User offboarding audit

Audit an offboarding request and prepare a clear removal and preservation plan.

Uses User directory and Groups and access

Security

Compromised-account investigation

Investigate a suspected identity compromise and prepare evidence-backed containment options.

Uses Identity security and User directory

IT operations

Device health investigation

Assess the current health and operational risk of one managed device.

Uses Managed devices and Device alerts

Service desk

Alert-to-ticket enrichment

Enrich an RMM or security alert with customer, asset, identity, and ticket context.

Uses Device alerts and Managed devices

Service desk

Recurring ticket investigation

Determine whether repeated tickets share an underlying user, device, service, or process cause.

Uses Service tickets and Ticket history

Identity

Microsoft 365 service-impact investigation

Determine the scope and likely cause of a Microsoft 365 service problem.

Uses User directory and Identity security

Resilience

Backup failure investigation

Explain recent backup failures and assess likely recovery risk.

Uses Backup jobs and Asset inventory

Resilience

Patch-compliance review

Review patch posture and prioritize devices requiring technician attention.

Uses Managed devices and Device policies

Security

Security-baseline review

Review a customer security baseline using current identity, endpoint, and vulnerability evidence.

Uses Identity security and Identity configuration

Identity

License-optimization review

Identify likely license waste and entitlement gaps, with evidence for the next review.

Uses Licensing and User directory

IT operations

Warranty and lifecycle review

Assess hardware lifecycle and replacement priorities across a customer estate.

Uses Asset lifecycle and Asset inventory

IT operations

Documentation-gap audit

Compare discovered assets and identities with approved documentation to find missing or stale records.

Uses Documentation and Customer records

Customer success

Client onboarding discovery

Build a bounded discovery and gap report for a newly managed customer.

Uses Customer records and Customer contacts

Customer success

Client offboarding/export readiness

Assess what must be transferred, retained, or verified before a customer relationship ends.

Uses Customer records and Customer contacts

Service desk

Ticket assignment and prioritization

Recommend the queue, priority, and technician profile for a service ticket.

Uses Service tickets and Customer records

Service desk

Ticket response preparation

Prepare an accurate customer-facing ticket update from the latest ticket history and evidence.

Uses Service tickets and Ticket history

Service desk

Resolution verification

Verify that reported remediation addressed the original ticket symptoms before closure.

Uses Service tickets and Ticket history

IT operations

Change preparation

Prepare evidence, dependencies, validation steps, and rollback considerations for a proposed change.

Uses Service tickets and Ticket history

IT operations

Post-change validation

Compare observed post-change state with the approved plan and expected outcomes.

Uses Service tickets and Ticket history

The Playbook plans. Stackyapper still authorizes every call.

Playbooks use only the Apps and permissions available in the workspace. The current beta investigates and prepares results; it does not update connected systems. Missing evidence is called out instead of filled in.