AI Playbook

Investigate client security

Collect bounded security evidence for one customer, correlate findings, and recommend remediation without changing systems.

Copy this prompt

Replace the bracketed values, then paste it into an AI client connected to Stackyapper.

Run the "Investigate client security" playbook using Stackyapper.

Inputs
- concern: [Security alert, incident, user, asset, or question to investigate]
- time window: [Optional bounded time window] (optional)

Objective
Collect bounded security evidence for one customer, correlate findings, and recommend remediation without changing systems.

Required evidence
- Security findings

Use when available
- Security assets
- Identity security
- User directory
- Managed devices
- Device alerts
- Service tickets
- Documentation

Procedure
1. Confirm the customer, concern, time window, and affected identity or asset.
2. Collect relevant findings and the associated asset context.
3. Correlate identity alerts and user state when relevant.
4. Check related device evidence, active RMM alerts, tickets, and approved runbooks.
5. Report evidence, uncertainty, severity rationale, containment options, and actions requiring approval.

Return
- Customer scope
- Evidence and freshness
- Missing coverage
- Severity and confidence
- Recommended containment and remediation

Use only evidence available through the Stackyapper Apps and permissions connected to this AI client. If required evidence is unavailable, say what is missing before continuing. Do not guess or make changes in connected systems.

Before you paste

Replace every bracketed value in the prompt. Delete an optional input line if it does not apply.

  • concern: Security alert, incident, user, asset, or question to investigate. (required)
  • time window: Optional bounded time window. (optional)

What Stackyapper will use

The exact tools depend on the Apps connected to your workspace and the current user's permissions.

  • Security findings (required)
  • Security assets (used when available)
  • Identity security (used when available)
  • User directory (used when available)
  • Managed devices (used when available)
  • Device alerts (used when available)
  • Service tickets (used when available)
  • Documentation (used when available)

What you'll get

  • Customer scope
  • Evidence and freshness
  • Missing coverage
  • Severity and confidence
  • Recommended containment and remediation

How it works

  1. Confirm the customer, concern, time window, and affected identity or asset.
  2. Collect relevant findings and the associated asset context.
  3. Correlate identity alerts and user state when relevant.
  4. Check related device evidence, active RMM alerts, tickets, and approved runbooks.
  5. Report evidence, uncertainty, severity rationale, containment options, and actions requiring approval.