SECOPS
WAF Exception Rule Proposer to Linear
From a batch of confirmed false-positive blocks, the agent drafts concrete Cloudflare skip/exception rule expressions and opens a Linear issue with the proposed rule…
How it runs
The automated pipeline, trigger to output.
- TriggerWebhook delivers confirmed FP batchHTTP webhook
- ActionPull full event + matched rule detailCloudflare
- LogicDraft narrowly scoped skip-rule expression
- LogicValidate expression syntax and scope
- OutputOpen Linear issue with rule + evidenceLinear
What it does
This workflow turns clusters of false-positive WAF blocks into ready-to-review exception rules. Instead of an engineer hand-writing a Cloudflare expression, the agent drafts the precise skip rule, scopes it as narrowly as possible, and files it in Linear with the evidence that justifies it.
When to use it
Use it when you've identified recurring false positives and want a paper trail and approval gate before any WAF rule change ships. It keeps humans in the loop while removing the tedious part of authoring expressions.
How it works
- 1A webhook delivers a batch of confirmed false-positive samples from your triage tooling.
- 2The agent queries Cloudflare for the full event detail and the rules that matched.
- 3It synthesizes a narrowly scoped skip-rule expression that exempts the legitimate pattern without opening a hole, and explains the blast radius.
- 4A logic step verifies the proposed expression is valid syntax and not overly broad.
- 5It opens a Linear issue containing the proposed rule, affected paths, and a rollback note, tagged for security review.
Set it up
What you configure once, before turning it on.
- 1Connect HTTP webhookTrigger any URL on agent actions.
- 2Connect CloudflareWorkers, Pages, R2, KV — the edge stack.
- 3Connect LinearIssues, projects, cycles, triage.
- 4Set each agent's modelWe leave models unset so you pick the tier — fast + cheap, or top-quality.
- 5Tune it to your dataEdit the prompts, filters, and field mappings so it matches how your team works.
- 6Test, then turn it onRun once against a sample, confirm the output, then enable the trigger.
More SecOps workflows
Post-Revocation Verification and Audit Logging
After a key is revoked, it confirms the old credential actually fails, verifies the replacement works.
Page on-call when a WAF rule mass-blocks legitimate traffic
On demand or every few minutes, it detects a single Cloudflare WAF rule suddenly blocking a broad spread of ASNs and paths (a likely false-positive storm).
PII Content Scan on New Dropbox External Share
When a file gets an external Dropbox link, it reads the file content, uses an AI classifier to detect PII or secrets.
Compile a weekly WAF tuning review with trends to Confluence
Every week an agent rolls up Cloudflare WAF block clusters by rule and ASN, compares them to prior weeks for trend direction.
Sensitive Dropbox Link Owner Remediation Loop
When a newly created Dropbox shared link points to a sensitive file, this workflow DMs the file owner, gives them a deadline to justify or revoke it.
GitLab Push Secret Detection to Block and History Purge
On a GitLab push that contains a detected secret, it revokes the exposed credential, opens a tracking issue with git-history purge instructions.
Run it inside a business
This workflow drops into a full company template. Import the org, and this is one of the playbooks its agents run.

Run this workflow in your colony.
14-day trial. No DevOps. No Sales call. Provisioned in under a minute.
