AI Playbook
Investigate client security
Collect bounded security evidence for one customer, correlate findings, and recommend remediation without changing systems.
Copy this prompt
Replace the bracketed values, then paste it into an AI client connected to Stackyapper.
Run the "Investigate client security" playbook using Stackyapper.
Inputs
- concern: [Security alert, incident, user, asset, or question to investigate]
- time window: [Optional bounded time window] (optional)
Objective
Collect bounded security evidence for one customer, correlate findings, and recommend remediation without changing systems.
Required evidence
- Security findings
Use when available
- Security assets
- Identity security
- User directory
- Managed devices
- Device alerts
- Service tickets
- Documentation
Procedure
1. Confirm the customer, concern, time window, and affected identity or asset.
2. Collect relevant findings and the associated asset context.
3. Correlate identity alerts and user state when relevant.
4. Check related device evidence, active RMM alerts, tickets, and approved runbooks.
5. Report evidence, uncertainty, severity rationale, containment options, and actions requiring approval.
Return
- Customer scope
- Evidence and freshness
- Missing coverage
- Severity and confidence
- Recommended containment and remediation
Use only evidence available through the Stackyapper Apps and permissions connected to this AI client. If required evidence is unavailable, say what is missing before continuing. Do not guess or make changes in connected systems.Before you paste
Replace every bracketed value in the prompt. Delete an optional input line if it does not apply.
concern: Security alert, incident, user, asset, or question to investigate. (required)time window: Optional bounded time window. (optional)
What Stackyapper will use
The exact tools depend on the Apps connected to your workspace and the current user's permissions.
- Security findings (required)
- Security assets (used when available)
- Identity security (used when available)
- User directory (used when available)
- Managed devices (used when available)
- Device alerts (used when available)
- Service tickets (used when available)
- Documentation (used when available)
What you'll get
- Customer scope
- Evidence and freshness
- Missing coverage
- Severity and confidence
- Recommended containment and remediation
How it works
- Confirm the customer, concern, time window, and affected identity or asset.
- Collect relevant findings and the associated asset context.
- Correlate identity alerts and user state when relevant.
- Check related device evidence, active RMM alerts, tickets, and approved runbooks.
- Report evidence, uncertainty, severity rationale, containment options, and actions requiring approval.