Every rule ships the playbook for the thing it just caught.

The alert carries its own playbook, ordered, with the reason each step comes when it does.

Detect, guided response

The response steps the rule ships with the alert, in the order it gives them
01Where it goes wrong

The alert fires at 2am and the person on call has never seen this rule before.

02How it works

How it works

Every rule ships a response block: the triage questions to ask, and the criteria for escalating

Where the misconfiguration can be fixed with a script, the rule carries the PowerShell to fix it

Closing an alert captures a classification and a resolution action, leaving a record of what was done

03With Nuvio

Ask the specialist that owns this work.

Ask in your own words. The Response Agent runs as you, and any action it can take ships off until an admin turns it on.

How Nuvio is governed

Response Agent

Containment steps you pick from: revoke sessions, disable sign-in, force MFA re-registration.

  1. You asked: Contain this account until we know more
  2. Nuvio answered: Revoking sessions and forcing MFA re-registration would both fit here, in that order. The buttons are on the alert. Until you switch those actions on, I do not press them.

    Switched off

    Session revoke is switched off for this connection

    Every write-back task ships off. Turn it on in the connector settings and a person runs it from the console.

04Where it fits

The jobs it is bought for.

Catch the chainFive alerts become one incident before anyone is woken
05On your own tenant

See it on your own tenant.

Book a demo

Connect your directory and see your first findings the same day.

The graph behind it