Skip to content

IT and security integrations and automations

Access, incidents, devices, licences and the alerts that matter, automated so each control runs every time and leaves its own evidence.

7 guides  ·  Built with Tray Headless

What this work has in common

The work in this category is mostly controls, and a control that depends on somebody remembering to do it will eventually be missed. The designs in these guides follow the same pattern. Take the decision from an authoritative source such as the HRIS, the CMDB or the identity provider. Act with an expiry by default. Write down what happened as part of doing it.

The failures here are quiet. A licence nobody uses keeps renewing. A device assigned to a leaver is still listed against their name. An alert fires on a server that was decommissioned last quarter. None of these raise an error, so much of the work is reconciling what one system believes against what another one knows.

The usual systems are an ITSM such as ServiceNow or Jira Service Management, an identity provider such as Okta, device management such as Jamf or Intune, monitoring such as Datadog, a compliance platform such as Vanta, and Slack, where most requests and incidents start.

The guides cover access requests and approval, service desk fulfilment, incidents from declaration to postmortem, security alert triage, vulnerabilities into tickets, SaaS licence reclamation and device lifecycle.

Where IT and security automation breaks

Access that never expires

Temporary access granted for a project is still there a year later because nobody set an end date. Grant with an expiry by default and make an extension a new request.

Alert volume as a measure

A triage pipeline that forwards every alert to a channel trains people to ignore the channel. Enrich first, suppress what is known to be benign, and measure what was closed.

Ranking vulnerabilities on CVSS alone

A critical score on a host nobody can reach matters less than a medium one on an internet-facing service. Rank on exploitability and exposure, and group findings by the fix so one ticket closes many.

Evidence assembled before the audit

When the access review is a spreadsheet built the week before an audit, it describes what somebody remembered. When every grant and revocation runs through a workflow, the review is a query.

The systems involved

The applications these guides read from and write to, most used first. Each links to its connector page.

Connections these guides build

Solutions for it and security

The solution pages for this work, with the customer stories behind them.