ENGINEERING
CVE Exposure-Based Pager Escalation
On a published CVE for a watched package, this determines whether any internet-facing or production service is exposed.
How it runs
The automated pipeline, trigger to output.
- TriggerCVE webhook for a watched package
- ActionResolve vulnerable repos and map to service exposure metadataGitHub
- LogicBranch on exposure: production/edge = high, internal/dev = low
- ActionOpen a PagerDuty incident for high-exposure matchesPagerDuty
- OutputLog low-exposure matches as a tracked Datadog eventDatadog
What it does
Stops CVE alert fatigue by escalating based on actual exposure rather than mere presence. It checks whether the affected package version runs in any production or internet-facing service, and reserves a page for those cases while quietly logging the rest.
When to use it
Use it when your team gets paged for every advisory regardless of reachability and has started ignoring them. This makes the page mean something again by gating it on real production exposure.
How it works
- 1A CVE webhook for a watched package triggers the run.
- 2The flow queries which GitHub repos pin a vulnerable version and which of those map to production or edge-exposed services via service metadata.
- 3A severity branch evaluates exposure: production or internet-facing match is high; internal-only or dev is low.
- 4High-severity matches trigger a PagerDuty incident with the affected services and fixed version attached.
- 5Low-severity matches are recorded as a Datadog event so they stay tracked without waking anyone.
Set it up
What you configure once, before turning it on.
- 1Connect GitHubRepos, issues, pull requests, actions.
- 2Connect PagerDutyIncidents, on-call, escalations.
- 3Connect DatadogMetrics, traces, log search.
- 4Set each agent's modelWe leave models unset so you pick the tier — fast + cheap, or top-quality.
- 5Tune it to your dataEdit the prompts, filters, and field mappings so it matches how your team works.
- 6Test, then turn it onRun once against a sample, confirm the output, then enable the trigger.
More Engineering workflows
Gate breaking API PRs behind downstream consumer acknowledgement
When a PR introduces a breaking contract change, comments the impact summary back on the PR, applies a blocking label.
Publish a versioned API changelog to Confluence on each release tag
On a new semver release tag, gathers the contract changes since the last release and writes a clean.
Agent reviews model-license fit and suggests compliant swaps on the PR
When a PR adds a Hugging Face model, an agent reads the model card and license, judges fit against your commercial-use policy.
Upgrade Impact Router to Module Code Owners
Maps a dependency-bump PR's affected modules to their CODEOWNERS, then DMs each owner on Slack with only the changelog slice that touches code they own.
Re-Voice IVR Prompts on Phone-Tree Config Merge
When a phone-tree config change merges in GitHub, regenerates the ElevenLabs audio for any prompt whose script changed in the diff and opens a follow-up PR adding the new audio…
Upstream Release to Notion Upgrade Brief
When a watched package publishes a new release, fetches the release notes, maps them to the internal modules that depend on it.
Run it inside a business
This workflow drops into a full company template. Import the org, and this is one of the playbooks its agents run.

Run this workflow in your colony.
14-day trial. No DevOps. No Sales call. Provisioned in under a minute.
