IT and security integrations and automations
Access, incidents, devices, licences and the alerts that matter, automated so each control runs every time and leaves its own evidence.
7 guides · Built with Tray Headless
What this work has in common
The work in this category is mostly controls, and a control that depends on somebody remembering to do it will eventually be missed. The designs in these guides follow the same pattern. Take the decision from an authoritative source such as the HRIS, the CMDB or the identity provider. Act with an expiry by default. Write down what happened as part of doing it.
The failures here are quiet. A licence nobody uses keeps renewing. A device assigned to a leaver is still listed against their name. An alert fires on a server that was decommissioned last quarter. None of these raise an error, so much of the work is reconciling what one system believes against what another one knows.
The usual systems are an ITSM such as ServiceNow or Jira Service Management, an identity provider such as Okta, device management such as Jamf or Intune, monitoring such as Datadog, a compliance platform such as Vanta, and Slack, where most requests and incidents start.
The guides cover access requests and approval, service desk fulfilment, incidents from declaration to postmortem, security alert triage, vulnerabilities into tickets, SaaS licence reclamation and device lifecycle.
Where IT and security automation breaks
Access that never expires
Temporary access granted for a project is still there a year later because nobody set an end date. Grant with an expiry by default and make an extension a new request.
Alert volume as a measure
A triage pipeline that forwards every alert to a channel trains people to ignore the channel. Enrich first, suppress what is known to be benign, and measure what was closed.
Ranking vulnerabilities on CVSS alone
A critical score on a host nobody can reach matters less than a medium one on an internet-facing service. Rank on exploitability and exposure, and group findings by the fix so one ticket closes many.
Evidence assembled before the audit
When the access review is a spreadsheet built the week before an audit, it describes what somebody remembered. When every grant and revocation runs through a workflow, the review is a query.
The it and security guides
Each one is the design, the sequence it runs in, the prompts that build it, and what changes when it runs in production.
How to build access request and approval
Route to the system owner, grant with an expiry by default, provision automatically, and produce the access review as a by-product.
Automation
How to build incident to resolution
Declare fast, assemble the channel and the timeline automatically, keep customers informed on a cadence, and make the postmortem unavoidable.
Automation
How to build security alert triage
Enrich before a human sees it, suppress the known-benign, escalate on asset value, and measure what you closed rather than what fired.
Automation
How to build IT service desk fulfilment
Catalogue the requests worth automating, fulfil the safe ones end to end, and route the rest with everything already gathered.
Automation
How to build SaaS licence reclamation
Find the seats nobody uses, ask before you take, reclaim on a schedule, and put the saving where finance sees it.
Automation
How to build vulnerability to ticket routing
Rank on exploitability and exposure rather than CVSS, group by fix instead of by finding, and route to whoever ships the patch.
Automation
How to build a device lifecycle sync
Reconcile what management sees against what finance owns and what HR says, and make an unassigned device an exception instead of a row.
Integration
The systems involved
The applications these guides read from and write to, most used first. Each links to its connector page.
- Slack (7 guides)
- Jira (6 guides)
- ServiceNow (5 guides)
- Okta (5 guides)
- Snowflake (5 guides)
- Workday REST (3 guides)
- Datadog (3 guides)
- GitHub (2 guides)
- NetSuite (2 guides)
- Zendesk (1 guide)
- Notion (1 guide)
- Microsoft Intune (1 guide)
Connections these guides build
Solutions for it and security
The solution pages for this work, with the customer stories behind them.
- IT service desk with Tray.ai Agents that close tickets.
- Employee lifecycle automation with Tray.ai Onboarding in minutes, not days.
Guides for other teams
- Revenue operations (17)
- Finance (8)
- Customer success (5)
- People operations (6)
- Marketing (3)
- Data operations (5)
- Platform engineering (4)
- AI operations (8)
- Legal and compliance (5)