AI Employee: Sig

Security Playbooks

JIT elevation, incident triage, access reviews, phishing triage, secret rotation, questionnaire response.

26 playbooks in this module.

Anomalous Login
Monitor event · Writes
Approval: User confirms; security on repeated denial
Certificate Expiration Tracking
Cron (daily) · Writes
Approval: Owner ack on manual renew
Cloud IAM Reviews
Cron (quarterly) · Writes
Approval: Owner attests; security reviews privileged
Compliance Training
Cron + HRIS event · Writes
Approval: Manager notified on non-completion
Compromised Credential Response
Monitor event · Writes
Approval: Security decision on account lock for high-risk accounts
Employee Offboarding
HRIS event · Writes
Approval: Security reviews any account it cannot deprovision
Endpoint Compliance Drift
Cron (daily) · Writes
Approval: None for auto-remediate; owner ticket otherwise
GitHub Outside-Collaborator Review
Cron (weekly) · Writes
Approval: Owner attests per repo
Incident Auto-Investigation via Grafana
Monitor event (Grafana alert) · Read-only
Approval: None for read-only enrichment
Incident Response Orchestration
Monitor event + chat · Writes
Approval: IC approval on external comms
IOC Enrichment & Lookup
Chat · Read-only
Just-In-Time (JIT) Access
Chat with approval · Writes
Approval: Manager + security approval; step-up MFA on requester
Phishing & Suspicious Email Triage
Ticket event + email forward · Writes
Approval: Analyst confirmation before mass-remediation
Privacy / Data Deletion
Form (DSAR) · Writes
Approval: Legal review for edge cases
Public Exposure Monitoring
Cron (daily) · Read-only
Restricted-Country Access Control
Monitor event · Writes
Approval: Security approves exceptions
Secret & API Key Rotation
Cron + chat · Writes
Approval: Owner approves for shared secrets
Security Alert Triage & Context
Monitor event · Read-only
Approval: None (read-only enrichment)
Security Exception Handling
Form · Writes
Approval: Security lead + risk owner approval
SOC2 / Vanta Evidence Collection
Cron (per control) · Writes
Approval: Owner attests per control
Terraform PR Request
Form · Writes
Approval: Code owner + security team approval
Tool Migration & Secure Deployment
Form · Writes
Approval: Security + IT lead approval per phase
User Access Reviews (UAR)
Cron (quarterly) · Writes
Approval: Manager attests per user; security reviews escalations
Vendor Security Review
Form · Writes
Approval: Security approval before contract
Vulnerability Assessment & Impact
Chat · Read-only
Vulnerability Remediation Requests
Webhook · Writes
Approval: None (auto-triaged; sev-1 pings on-call)

Every playbook, ready to install.

Meet Sig, the Security AI Employee who runs these playbooks on your team.